Harvest-Proof Index · 26 September 2026 · 3,642 server names tested · 2,885 measured · 51 companies

Harvest-Proof Index

Qtonic Quantum Corp ranks first of 51. 5 of its 8 public HTTPS servers are harvest-proof: they accept post-quantum key exchange and refuse the classical sessions an adversary can record today and decrypt once a large enough quantum computer exists. The other three are its public web pages; they offer post-quantum first and also accept classical sessions, two of them since 23:36 UTC that day so that search engines and older browsers can reach the company site. Of the 2,877 servers measured at the 50 largest IT-security companies, none is harvest-proof.

62.5%of Qtonic Quantum Corp servers are harvest-proof (5 of 8; the other 3 are public web pages that also accept classical clients)
0%for each of the 10 largest IT-security companies by market value
0harvest-proof servers among the 50 companies, out of 2,877 measured
99.1%of servers gave the same result when re-measured with separately written code (2,858 of 2,883)

Against the biggest

Qtonic Quantum Corp against the ten largest IT-security companies by market value.

CompanyHarvest-proof serversOffer post-quantum
Qtonic Quantum Corppublisherrank 1 of 5162.5%100.0%
Palo Alto Networks#1 by market value · 109 servers0.0%31.2%
CrowdStrike#2 by market value · 103 servers0.0%73.8%
Fortinet#3 by market value · 92 servers0.0%25.0%
Cloudflare#4 by market value · 119 servers0.0%99.2%
Okta#5 by market value · 154 servers0.0%31.8%
Zscaler#6 by market value · 97 servers0.0%40.2%
F5#7 by market value · 75 servers0.0%18.7%
Rubrik#8 by market value · 44 servers0.0%31.8%
Akamai#9 by market value · 131 servers0.0%88.5%
Leidos#10 by market value · 54 servers0.0%31.5%

Against the best

Qtonic Quantum Corp against the five companies with the highest post-quantum coverage on the common industry measure. Four offer the hybrid group on all of their servers and Cloudflare on 99.2%; every one of those servers still accepts a classical session.

CompanyHarvest-proof serversOffer post-quantum
Qtonic Quantum Corppublisherrank 1 of 5162.5%100.0%
Alarum Technologies#50 by market value · 99 servers0.0%100.0%
Kudelski#39 by market value · 20 servers0.0%100.0%
Castellum#45 by market value · 8 servers0.0%100.0%
Mobilicom#44 by market value · 5 servers0.0%100.0%
Cloudflare#4 by market value · 119 servers0.0%99.2%

All 51 companies

Ranked by the share of servers that refuse all three classical handshakes tested, then by the share that offer the post-quantum hybrid group, then by name. Select a company to inspect each of its servers.

#CompanyMeasured servers Harvest-proofOffer post-quantumServers
1Qtonic Quantum Corppublisherqtonicquantum.com62.5%5/8100.0%8/8
2Alarum Technologiesalarum.io · ALAR · #50 by value0.0%0/99100.0%99/99
3Castellumcastellum.ai · CTM · #45 by value0.0%0/8100.0%8/8
4Kudelskikudelskisecurity.com · KUD.SW · #39 by value0.0%0/20100.0%20/20
5Mobilicommobilicom.com · MOB · #44 by value0.0%0/5100.0%5/5
6Cloudflarecloudflare.com · NET · #4 by value0.0%0/11999.2%118/119
7Akamaiakamai.com · AKAM · #9 by value0.0%0/13188.5%116/131
8Fastlyfastly.com · FSLY · #23 by value0.0%0/4283.3%35/42
9secunetsecunet.com · YSN.F · #27 by value0.0%0/5282.7%43/52
10OneSpanonespan.com · OSPN · #31 by value0.0%0/3878.9%30/38
11Allotallot.com · ALLT · #32 by value0.0%0/3778.4%29/37
12SentinelOnesentinelone.com · S · #16 by value0.0%0/4877.1%37/48
13Tenabletenable.com · TENB · #24 by value0.0%0/6475.0%48/64
14Check Point Softwarecheckpoint.com · CHKP · #11 by value0.0%0/8674.4%64/86
15CrowdStrikecrowdstrike.com · CRWD · #2 by value0.0%0/10373.8%76/103
16SailPointsailpoint.com · SAIL · #13 by value0.0%0/4669.6%32/46
17WALLIX Groupwallix.com · ALLIX.PA · #38 by value0.0%0/2466.7%16/24
18Varonis Systemsvaronis.com · VRNS · #21 by value0.0%0/8758.6%51/87
19Corero Network Securitycorero.com · CNS.L · #41 by value0.0%0/1353.8%7/13
20NCC Groupnccgroup.com · NCC.L · #37 by value0.0%0/4652.2%24/46
21Gen Digitalgendigital.com · GEN · #12 by value0.0%0/4551.1%23/45
22A10 Networksa10networks.com · ATEN · #26 by value0.0%0/2450.0%12/24
23Identividentiv.com · INVE · #46 by value0.0%0/2050.0%10/20
24Verimatrixverimatrix.com · VMX.PA · #49 by value0.0%0/3650.0%18/36
25Rapid7rapid7.com · RPD · #30 by value0.0%0/6245.2%28/62
26Commvaultcommvault.com · CVLT · #19 by value0.0%0/7444.6%33/74
27Intercede Groupintercede.com · IGP.L · #40 by value0.0%0/1844.4%8/18
28Zscalerzscaler.com · ZS · #6 by value0.0%0/9740.2%39/97
29NETSCOUTnetscout.com · NTCT · #25 by value0.0%0/4938.8%19/49
30Netskopenetskope.com · NTSK · #17 by value0.0%0/4238.1%16/42
31cyancyansecurity.com · CYR.DE · #48 by value0.0%0/3336.4%12/33
32WISeKeywisekey.com · WKEY · #43 by value0.0%0/2236.4%8/22
33WithSecurewithsecure.com · WITH.HE · #35 by value0.0%0/5532.7%18/55
34PagerDutypagerduty.com · PD · #28 by value0.0%0/16331.9%52/163
35Oktaokta.com · OKTA · #5 by value0.0%0/15431.8%49/154
36Rubrikrubrik.com · RBRK · #8 by value0.0%0/4431.8%14/44
37Softcatsoftcat.com · SCT.L · #22 by value0.0%0/6631.8%21/66
38Leidosleidos.com · LDOS · #10 by value0.0%0/5431.5%17/54
39Qualysqualys.com · QLYS · #18 by value0.0%0/5131.4%16/51
40Palo Alto Networkspaloaltonetworks.com · PANW · #1 by value0.0%0/10931.2%34/109
41F-Securef-secure.com · FSECURE.HE · #34 by value0.0%0/2630.8%8/26
42Yubicoyubico.com · YUBICO.ST · #29 by value0.0%0/4930.6%15/49
43Digital Arts Inc.daj.jp · 2326.T · #33 by value0.0%0/728.6%2/7
44Fortinetfortinet.com · FTNT · #3 by value0.0%0/9225.0%23/92
45Trend Microtrendmicro.com · 4704.T · #20 by value0.0%0/10824.1%26/108
46Cyberoocyberoo.com · CYB.MI · #47 by value0.0%0/2420.8%5/24
47Sangfor Technologiessangfor.com · 300454.SZ · #15 by value0.0%0/5520.0%11/55
48Telostelos.com · TLS · #36 by value0.0%0/1618.8%3/16
49F5f5.com · FFIV · #7 by value0.0%0/7518.7%14/75
50Quick Healquickheal.com · QUICKHEAL.NS · #42 by value0.0%0/219.5%2/21
51360 Security Technology360.cn · 601360.SS · #14 by value0.0%0/1180.8%1/118

Server explorer

ServerKindAddressHybrid onlyX25519 onlyP-256 onlyTLS 1.2Result
Loading server records…

Two ways to read the table

Hybrid column: can a modern client get post-quantum protection?

This is the common industry measure. Cloudflare, Akamai and Fastly, and companies whose servers sit on those networks, score high on this column. Several of the largest companies offer the hybrid group on a minority of their servers: F5 18.7%, Fortinet 25.0%, Palo Alto Networks 31.2%.

Harvest-proof column: can anyone still get a classical session?

A recorded classical handshake can be decrypted once a large quantum computer exists. In this index, a server closes that path only if it refuses all three classical handshakes tested: TLS 1.3 with X25519, TLS 1.3 with P-256, and TLS 1.2. None of the 2,877 servers measured at the 50 companies does. Qtonic Quantum Corp refuses all three on 5 of its 8 servers.

Policy change on 26 September 2026, 23:36 UTC. Qtonic Quantum Corp opened its two public web servers (qtonicquantum.com and www) to classical clients so that search engines, answer engines, link previews and older browsers can reach the company site; they still offer the post-quantum hybrid group first (deploy transcript). Its five machine-facing servers (api, lab, mx, qstrike, stream) remain harvest-proof. The eighth, demo.qtonicquantum.com, is served from a content network and accepted classical sessions in every re-measurement, before and after the change. Measurements earlier that day (below) show 7 of 8; the ranking on this page uses the measurement taken after the change.

Refusing classical has a cost: clients without the hybrid group cannot connect. curl built on OpenSSL 3.0.13 (the Ubuntu 24.04 default) fails against api.qtonicquantum.com (transcript). Qtonic Quantum Corp's harvest-proof servers accept only X25519MLKEM768, so a client that offers only another post-quantum group, such as pure ML-KEM-1024, cannot connect either. Companies that serve the general public accept classical sessions so older clients keep working. Qtonic Quantum Corp made the same choice for its own website on 26 September 2026 and kept its five machine-facing servers harvest-proof. A 0% harvest-proof score can reflect that choice; this index measures handshakes, not the reasons behind them.

How each server was tested

Four handshakes per server

TLS 1.3 · X25519MLKEM768 only
TLS 1.3 · X25519 only
TLS 1.3 · P-256 only
TLS 1.2 · default suites

Every server is tested on HTTPS (port 443). A handshake counts as completed even if the certificate name does not match.

Which servers

Each company's apex and www, the names from the first 2,400 labels of the SecLists subdomains-top1million-5000 list that resolve, and names from certificate-transparency logs, all on the company's own registered domain. The same method applies to every company, including Qtonic Quantum Corp.

A server that completes none of the four handshakes is left out of every percentage and shown as unmeasured in the explorer. Mail servers are not included: the measurement host cannot reach port 25, so this edition covers HTTPS only. A name such as mx.qtonicquantum.com is counted for its HTTPS service on port 443.

The four handshakes are a practical test, not every classical option. Two WISeKey VPN servers refuse X25519 and P-256 but accept P-384 and X448; they count as not harvest-proof because they also accept TLS 1.2. Qtonic Quantum Corp's 5 harvest-proof servers were also tested against 19 more classical variants (other key groups, TLS 1.0 to 1.2, a missing or false server name) and 5 other post-quantum groups, and refused every one.

Six measurements, one result

The original measurement, by the publisher's own probe, was made earlier on 26 September. To check it, a separately written probe re-tested every server three times: at 15:52–15:59 UTC, at 17:28–17:35 UTC and, after the policy change, at 23:44–23:52 UTC. All six measurements were made from AWS us-west-2, on two different hosts; servers behind content networks may answer differently in other regions. The ranking on this page uses the current measurement, 23:44–23:52 UTC.

What matched

2,858 of 2,883 servers measured in both the original and the current measurement (23:44–23:52 UTC) got the same result (99.1%). Both headline results held: no harvest-proof server among the 50 companies' measured servers, and Qtonic Quantum Corp as the only one of the 51 companies with harvest-proof servers.

What differed, and why

20 of the 25 differences sit on one content-network address range (150.171.110.x); 3 are Qtonic Quantum Corp's own servers: qtonicquantum.com and www.qtonicquantum.com, which reflect its policy change on 26 September 2026, 23:36 UTC (above), and demo.qtonicquantum.com, which is served from a content network and accepted classical sessions in every re-measurement. Re-tested three times, some of those servers switched between hybrid and classical between attempts. The replication also added qstrike.qtonicquantum.com, a name in Qtonic Quantum Corp's certificate logs that the first run missed. It is harvest-proof. It also removed qryptonic.org, a separate Qtonic Quantum Corp domain that the first run had counted under qtonicquantum.com. No other company had a second domain counted, so it was taken out.

A second full re-measurement at 17:28–17:35 UTC confirmed the result: 99.1% of servers gave the same answer, Qtonic Quantum Corp was again 7 of 8 (measured before the policy change of 23:36 UTC), and no server at any of the 50 companies was harvest-proof. Post-quantum shares held within 2 points for every company except Commvault, NCC Group and Varonis Systems, whose servers sit on a content network that switches between classical and hybrid (up to 15.2 points).

MeasurementTLS implementationVantage pointWhenQtonic Quantum Corp harvest-proofHarvest-proof servers at the 50 companies
Original measurement (as published)Go crypto/tls (publisher probe)AWS us-west-2 (publisher host)26 Sep 2026, as published7 of 8 (before the policy change)0 of 1,612
Replication 1Go crypto/tls (independent code)AWS us-west-2 (worker host)15:52–15:59 UTC7 of 8 (before the policy change)0 of 2,878
Replication 2Go crypto/tls (independent code)AWS us-west-217:28–17:35 UTC7 of 8 (before the policy change)0 of 2,879
OpenSSL cross-checkOpenSSL 3.5.7 s_clientAWS us-west-226 Sep 2026, 18:17–18:29 UTC7 of 8 (before the policy change)0 of 2,875
Adversarial reviewGo crypto/tls (reviewer's own code)AWS us-west-218:54–18:59 UTC7 of 8 (before the policy change)0 of 2,880
Current measurement (after the policy change)Go crypto/tls (independent code)AWS us-west-2 (worker host)23:44–23:52 UTC5 of 80 of 2,877

The first five rows were measured before the policy change of 23:36 UTC; the last row after it. The first row is the publisher's own published summary: its raw files are published under proof/original/, but the exact server subset behind that summary cannot be identified from them, so it is shown as published rather than recomputed.

Try to disprove it

The headline is falsifiable. To disprove it, find one server on the published list, at any of the 50 companies, that completes a hybrid-only handshake and refuses all three classical ones. Or show that one of the five Qtonic Quantum Corp servers marked harvest-proof (api, lab, mx, qstrike, stream) accepts a classical session. Any server can be checked with OpenSSL 3.5 or later:

HOST=api.qtonicquantum.com
# 1. Post-quantum hybrid only — a harvest-proof server completes this
openssl s_client -connect $HOST:443 -servername $HOST -brief -tls1_3 -groups X25519MLKEM768 </dev/null
# 2-4. Classical only — a harvest-proof server refuses all three
openssl s_client -connect $HOST:443 -servername $HOST -brief -tls1_3 -groups X25519 </dev/null
openssl s_client -connect $HOST:443 -servername $HOST -brief -tls1_3 -groups P-256 </dev/null
openssl s_client -connect $HOST:443 -servername $HOST -brief -tls1_2 </dev/null

The data files have not changed since they were timestamped by two independent timestamp authorities on Sep 27 00:20:08 2026 GMT. To verify, download SHA256SUMS, the files it lists and a timestamp token, then run:

sha256sum -c SHA256SUMS
openssl ts -verify -data SHA256SUMS -in SHA256SUMS.freetsa.tsr -CAfile freetsa-cacert.pem -untrusted freetsa-tsa.crt
openssl ts -reply -in SHA256SUMS.freetsa.tsr -text | grep "Time stamp"

A hostile reader could look for a showcase server we missed. We searched public certificate logs for post-quantum-named hosts (pq, pqc, quantum, kyber, mlkem and similar) at 48 of the 50 companies, after checking that the same search finds pq.cloudflareresearch.com. It found 11. None is harvest-proof: 9 do not resolve, 1 did not answer, and 1 accepts classical sessions. The public log database timed out for SailPoint and Zscaler, so those two were not searched this way. The result is in hunt-report.json.

Submit a reproducible challenge and read the public log with the hostname, resolved address, UTC time, vantage and four handshake outcomes. Qtonic Quantum Corp is the publisher and a measured company; accepted corrections will be recorded in a new dated snapshot while this proof remains available.

Questions and answers

Why did Qtonic Quantum Corp's score change on 26 September?

At 26 September 2026, 23:36 UTC Qtonic Quantum Corp opened its two public web servers (qtonicquantum.com and www) to classical clients so that search engines, answer engines and older browsers can reach the company site. They still offer the post-quantum hybrid group first. The five machine-facing servers remain harvest-proof, so the count went from 7 of 8 to 5 of 8. The eighth server, demo.qtonicquantum.com, sits on a content network and accepted classical sessions before and after the change. Earlier measurements that day are kept on the page.

Which company is the most post-quantum ready on public HTTPS in this index?

Qtonic Quantum Corp ranks first of 51. 62.5% of its public HTTPS servers (5 of 8) offer the post-quantum hybrid group X25519MLKEM768 and refuse all three classical handshakes tested. None of the 2,877 servers measured at the 50 largest IT-security companies does both.

How do the largest IT-security companies compare?

Each of the ten largest IT-security companies by market value has 0% harvest-proof servers. Their share of servers offering post-quantum key exchange ranges from 18.7% (F5) to 99.2% (Cloudflare). Qtonic Quantum Corp offers it on all 8 of its servers (100%).

What does harvest-proof mean?

A harvest-proof server accepts the post-quantum hybrid group X25519MLKEM768 and refuses the three classical handshakes tested: TLS 1.3 with X25519, TLS 1.3 with P-256, and TLS 1.2. In these tests, the only handshake it completed was the post-quantum one. That removes the classical-only sessions that harvest-now, decrypt-later attacks record today to decrypt later.

How was this measured and checked?

On 2026-09-26, 3,642 public HTTPS server names found on each company's own domain (51 companies) were tested with four TLS handshakes; the 2,885 that completed at least one are counted. Separately written probes re-measured every server three times and OpenSSL and an adversarial reviewer checked it again; the current measurement agreed with the original on 99.1% of the servers both runs measured, and six measurements in total gave the same headline result: no harvest-proof server at any of the 50 companies.

Read this before citing the ranking

Conflict of interest. Qtonic Quantum Corp publishes this page, designed the harvest-proof measure and ranks first on it. The hybrid column is included so the result can also be read on the common industry measure, where several companies tie Qtonic Quantum Corp at 100%.

Different estate sizes. Qtonic Quantum Corp has 8 measured servers. The 50 companies have between 5 and 163 measured servers. Counted by address instead of by name, Qtonic Quantum Corp is 0 of 2: its 5 harvest-proof names share the address that also serves qtonicquantum.com and www, which accept classical sessions since the policy change, and its second address serves demo, which accepts them too; each of the 50 companies is also 0 by address. A small estate is easier to keep uniform, so the percentages compare rates, not effort.

One day, public servers only. This is a snapshot of internet-facing TLS on 26 September 2026. It says nothing about internal systems, the products these companies sell, or their customers' deployments. Companies are the top 50 of the companiesmarketcap.com IT-security list as read that day.