American Binary has received an independent attestation validating the formal security model underlying its MaxKyber network protocol, a milestone the cybersecurity startup says demonstrates that its post-quantum virtual private network architecture satisfies all security requirements defined by the U.S. National Security Agency’s Commercial National Security Algorithm Suite 2.0, or CNSA 2.0.
The announcement comes as governments, critical infrastructure operators and large enterprises accelerate preparations for a future in which quantum computers could eventually undermine widely used public-key encryption. Although cryptographically relevant quantum computers have not yet been built, organizations are increasingly planning for “harvest now, decrypt later” attacks, in which encrypted data stolen today could be stored and decrypted years from now once sufficiently capable quantum computers become available.
Cybersecurity companies have largely focused on replacing vulnerable cryptographic algorithms with new post-quantum standards approved by the National Institute of Standards and Technology. American Binary is attempting to differentiate itself by emphasizing not only the algorithms it uses but also mathematical proof that its protocol behaves as intended.
The company said independent reviewers Dr. Joe Kiniry and Dr. Tom Shrimpton evaluated the symbolic proofs and engineering documentation supporting MaxKyber, concluding that the protocol satisfies 120 security properties spanning authentication, secrecy, forward secrecy, identity protection, replay resistance, denial-of-service resilience and other security characteristics.
According to the reviewers, they are unaware of another VPN protocol that has undergone formal verification of comparable scope. That assessment reflects their review and has not been independently validated across the broader VPN industry.
Beyond Cryptography
For many organizations, migrating to post-quantum cryptography has focused primarily on replacing existing encryption algorithms with newly standardized alternatives. American Binary reports that approach addresses only part of the challenge.
Instead, the company has invested several years in developing a protocol whose overall design can be mathematically analyzed using formal verification tools including Tamarin and ProVerif. Those tools allow researchers to model the behavior of security protocols and prove, under defined assumptions, that specified security properties always hold.
Formal verification differs from conventional penetration testing or software auditing by attempting to demonstrate mathematically that entire classes of security failures cannot occur rather than simply showing that known vulnerabilities have not been found.
The technique has been used for decades in high-assurance applications including aerospace, defense and hardware verification but remains relatively uncommon in commercial networking products because creating complete mathematical models requires substantial engineering effort and specialized expertise.
If widely adopted, proponents argue, formally verified protocols could reduce the uncertainty surrounding increasingly complex cryptographic software while providing customers with greater confidence that implementations behave as intended.
A Different Approach to Post-Quantum Migration
One of the more notable aspects of American Binary’s design is its decision to rely entirely on post-quantum cryptography for key establishment rather than using a hybrid approach.
Many organizations transitioning toward post-quantum security currently deploy hybrid key exchange schemes that combine classical algorithms with post-quantum algorithms. Supporters of hybrid designs argue they provide defense in depth during the industry’s transition period by maintaining compatibility with existing infrastructure while reducing dependence on any single cryptographic assumption.
According to the release, American Binary has taken a different path with MaxKyber replacing the traditional Diffie-Hellman key exchange with ML-KEM-1024, the highest security parameter set defined in NIST’s FIPS 203 standard, while pairing it with AES-256-GCM and SHA-512/256, all of which are included in the NSA’s CNSA 2.0 guidance for protecting classified and national security systems.
The company suggests that eliminating classical key exchange removes future dependence on cryptographic algorithms that quantum computers could eventually compromise, providing protection against long-term “harvest now, decrypt later” attacks.
Whether enterprises broadly embrace pure post-quantum architectures remains an open question. Many security vendors continue to favor hybrid deployments during the migration period because they minimize operational disruption while organizations gain experience with newly standardized algorithms.
Performance as Well as Security
Post-quantum cryptography has often been associated with larger keys, larger messages and increased computational overhead, creating concerns that stronger security could come at the expense of performance.
American Binary says MaxKyber attempts to address that tradeoff through protocol design rather than relying solely on faster hardware.
The company said its authenticated key exchange completes mutual authentication in a single network round trip while reducing handshake overhead by approximately 4,600 bytes compared with alternative approaches. According to American Binary, the smaller protocol footprint is intended to improve reliability on mobile devices and other networks where bandwidth is limited or packet loss is common.
The company also said one integration partner measured download performance approximately 70% faster than a comparable enterprise VPN, although it did not identify the comparison product or disclose the benchmark methodology.
For data center and AI workloads, American Binary said the protocol supports technologies including Vector Packet Processing and the Data Plane Development Kit to reduce networking overhead in high-throughput environments.
Compliance Could Become a Selling Point
Beyond performance, American Binary reports that formal verification may shorten the increasingly complex security review processes faced by organizations deploying new cryptographic technologies.
Critical infrastructure operators, government agencies and regulated industries frequently require extensive technical evaluations before approving new security products. By providing detailed mathematical models and independently reviewed documentation, the company believes customers and integration partners may be able to reduce portions of those diligence efforts.
Whether formal verification becomes a competitive advantage across the broader cybersecurity market remains to be seen. Enterprise buyers typically weigh multiple factors—including interoperability, operational maturity, vendor support and deployment experience—alongside cryptographic assurance when selecting networking products.
American Binary also announced that Whitfield Diffie has joined the company as an adviser. Diffie shared the 2015 ACM Turing Award for his pioneering work in public-key cryptography and co-developed the Diffie-Hellman key exchange, one of the foundational technologies underpinning secure communications on the modern internet.
He joins an advisory group that already includes cryptographers Bruce Schneier and Brian LaMacchia.
The addition of three widely recognized figures in applied cryptography strengthens the company’s technical credentials as it seeks to compete in an increasingly crowded market for post-quantum cybersecurity products.



