Eon Path Quantum-safe encryption for apps you already run. Ride the wave before it catch you.
Close the "harvest now, decrypt later" gap before attackers exploit it. No code changes required.
Who this is for
CISOs and engineering teams at organizations running critical infrastructure who:
- Want to protect their most sensitive, long-lived data before it's exposed.
- Want the fastest, lowest-risk path to quantum resilience.
- Want the peace of mind of having it handled now, without waiting years for a full migration.
How it works
- Eon Path deploys as a transparent proxy between your app and the network. It intercepts standard TLS, swaps in quantum-safe cryptography, and passes the traffic on.
- Zero developer effort. No application rewrites or re-architecture.
- Zero downtime. Deployed in hours without business disruption.
Under the hood
- ML-KEM-768 (Kyber) hybrid with X25519.
- ML-DSA for public-key auth.
- Runs on Windows, macOS, Linux.
- Central, API-driven key management.
- Failover and crypto-agility modes.
- NIST-approved algorithms, also recommended by BSI and ANSSI.
Setup
- 1. Install the server component, a lightweight daemon with a minimal resource footprint.
- 2. Deploy client apps with a simple installer, for every major platform.
- 3. Activate protection.
Quantum-safe crypto. Apps you already run. No code change.
Bad guy grab your data now. Decrypt later when quantum come. Call it "harvest now, decrypt later." Threat real — maybe this decade. Eon Path stop it. Today.
How it work
Eon Path sit as transparent proxy between app and network. It catch normal TLS, swap in quantum-safe crypto, pass traffic on. App never know. Dev never touch code.
Why good
- Deploy in hours, not months.
- Zero developer work.
- No app downtime.
- Compliance ready — now.
Under hood
- ML-KEM-768 (Kyber) hybrid with X25519.
- ML-DSA for public key auth.
- Runs on Windows, macOS, Linux.
- Central API-driven key management.
- Failover + crypto-agility modes.
Set up
- 1. Install server piece.
- 2. Deploy client apps.
- 3. Turn protection on.
Eon Path — NIST-standardized hybrid post-quantum key exchange and signatures. Drop-in; no application code changes.
Cryptography
Architecture
Two tunnelling methods:
- Proxy — HTTP CONNECT proxy fronting an SSH server; hybrid PQC key exchange,
ML-DSAhost keys, per-userauthorized_keys. - Routing (VPN) — WireGuard with IPv4-over-IPv6 (464XLAT / SIIT) translation; key exchange ML-KEM-1024 + ML-DSA-87, PQC-derived pre-shared key.
- API-driven public-key lookup (PQKS); TOFU host-key verification; failover + crypto-agility modes.
Defaults
127.0.0.1:9999127.0.0.1:2022truemlkemDeploy
- 1. Install the server component.
- 2. Deploy client apps.
- 3. Enable protection.
Documentation
Full reference at docs.eoncore.eu/eon-path/. Every page there is also Markdown: append index.md to its URL. All products in one file: docs.eoncore.eu/llms-full.txt.