Terra Quantum and Apex.AI Bring Post-Quantum Security to Cloud-Connected Machines
The transition to post-quantum cryptography (PQC) is an urgent issue within the quantum industry without a simple solution. While the US National Institute of Standards and Technology (NIST) has released its initial PQC…
Cierra Lunde · · 3 min read

The transition to post-quantum cryptography (PQC) is an urgent issue within the quantum industry without a simple solution. While the US National Institute of Standards and Technology (NIST) has released its initial PQC standards, there is a notable (and concerning) disconnect between establishing those standards and origanizations implementing them. PQC migration will also need to reach vehicles, robots, industrial equipment, and defense systems that increasingly depend on continuous communication between edge devices and the cloud.
Post-quantum cryptography consists of classical cryptographic algorithms designed to resist attacks from both conventional and quantum computers. Its immediate advantage is that it can be deployed through existing computing and networking infrastructure, making it one of the most accessible paths toward quantum-safe security.
Terra Quantum and Apex.AI have demonstrated how that transition could take place without a need to redesign the applications and software architectures already supporting these systems. Anything to reduce the technical and operational barriers to migration is important in order to promote adoption and ensure that as many systems as possible are protected.
The recently announced joint implementation uses PQC standardized by NIST to secure communication between a robotic software environment built on Apex.OS and a cloud-based control system. The companies describe the project as a practical blueprint for introducing quantum-resistant security into connected, software-defined systems while preserving their existing communication patterns and application logic.
Replacing cryptographic infrastructure can become an expensive undertaking when it requires organizations to modify application internal development processes. Terra Quantum and Apex.AI were able to replace vulnerable cryptographic components while maintaining the broader architecture surrounding them.
This could allow organizations to migrate incrementally and strengthen their security layer without abandoning their existing software investments.
The demonstration is especially relevant to systems with long operational lives. Vehicles, industrial machines, aerospace platforms, and defense assets introduced today may remain active for decades. During that time, sufficiently capable quantum computers could threaten widely used public-key cryptographic methods that currently protect authentication, data exchange, and remote access.
At the same time, these systems are becoming more dependent on cloud connectivity. Monitoring, diagnostics, fleet coordination, remote operation, and software updates all require information to travel securely between distributed machines and centralized services. Cryptographic migration must therefore protect not just data at rest but the communication infrastructure connecting physical assets to the systems that manage them.
“Organizations cannot afford to wait until that moment arrives,” said Markus Pflitsch, CEO, founder and chairman of Terra Quantum. He said the implementation demonstrates that standardized post-quantum cryptography can protect cloud-connected systems using technology available today and without disrupting their underlying software architectures.
Apex.OS provided the software-defined foundation for the implementation. The platform is designed for software-defined vehicles and intelligent machines operating across distributed environments. Terra Quantum contributed the post-quantum cryptographic capabilities used to secure communication between the Apex.AI-based edge environment and the cloud.
The project also highlights the broader systems challenge. Connected machines rarely operate in isolation. Autonomous vehicles, robots, sensors, cloud platforms, and command systems increasingly function as interconnected systems-of-systems. A weakness in one communication layer can affect the resilience of the wider operational network.
It’s important to note that a successful implementation is not the same as proving readiness for every production environment. Organizations will still need to evaluate performance, integration requirements, hardware constraints, certificate and key management, and interoperability across their systems. Migration will also require an inventory of where vulnerable cryptography is currently embedded, which is a challenge for complex products assembled from multiple software and hardware components.
However, the collaboration addresses one of the largest practical barriers to post-quantum adoption that migration must wait for entirely new systems or require wholesale architectural redesign.
For manufacturers and operators of long-lived connected assets, post-quantum security is increasingly becoming a product-lifecycle decision. But, oganizations can begin that transition within the architectures they already use and, most importantly, before quantum risk becomes an emergency.