LatticeScan

Index

Are the quantum companies quantum-safe?

The companies below are building the machines that will one day break today’s encryption. So we scanned their own public connections for the defense against exactly that: post-quantum key exchange. The result is its own kind of answer. Of the 14 we checked, not one has fully protected its public endpoints. Every one has at least one connection a future quantum computer could open.

GradeCompanyPost-quantum endpoints
B
Xanadu
xanadu.ai
11/12
report
B
IonQ
ionq.com
10/11
report
B
PsiQuantum
psiquantum.com
7/10
report
B
QuEra
quera.com
6/9
report
B
Atom Computing
atom-computing.com
4/6
report
B
Quantinuum
quantinuum.com
6/12
report
B
Quantum Computing Inc
quantumcomputinginc.com
6/12
report
C
Infleqtion
infleqtion.com
4/10
report
C
Oxford Quantum Circuits
oxfordquantumcircuits.com
2/5
report
C
IQM
meetiqm.com
3/10
report
C
D-Wave
dwavesys.com
3/12
report
C
Alice & Bob
alice-bob.com
2/11
report
C
Rigetti
rigetti.com
1/12
report
C
Pasqal
pasqal.com
0/12
report

The grade reflects how many of a domain’s reachable public endpoints negotiate hybrid ML-KEM key exchange, the part of a connection exposed to harvest now, decrypt later. A means every endpoint; B means most; C means modern TLS but classical key exchange on some or all. Often the one classical endpoint is a third-party marketing or ads host rather than core infrastructure, which is exactly the kind of gap an external scan surfaces.

This is a snapshot from July 2026. Each report above is live and reproducible, so a company that turns on post-quantum key exchange will show it the next time it is scanned. Method: how these grades are produced.

Want the same read on your own domain, or your vendors? Type one in and get a grade with the reasoning behind it.

Run a scan