Expert Advisors
Guided by the world’s leading minds in cryptography and security.
Our advisors bring deep technical expertise and real-world experience to help shape a more secure future.

Advisor
Whitefield Diffie

Cryptographer, ACM Turing Award winner and co-inventor of the Diffie-Hellman key exchange.

Advisor
Brian LaMacchia

Microsoft Crypto Board Founder, Leader for 20+ years, .NET co-creator, IACR Board member

Advisor
Bruce Schneier

Author, “Applied Cryptography”EFF Board member, Harvard
What People are Saying
Proven in the real world.
Security that performs where it matters, from enterprise and government to the people building our most critical systems.
The easiest, least painful security product install. It just worked.
— Anastasia M. CEO
No known VPN — post-quantam or classical, deployed or research — has been subjected to specification and formal erification of comparable depth.
— Dr. Joe Kiniery, PhD
Dr. Tom Shrimpton, PhD
Part of the minority, not selling snake oil.
— Exec, top CSP
Traditional network security is obsolete.
Full CSNA 2.0 compliance is mandatory to survive.
Ambit Client: the only VPN third-party-verified to fully comply with CSNA 2.0.
100% CNSA 2.0
Compliant
Verified by peer-reviewed symbolic proof. Unmatched protection against Harvest Now, Decrypt Later attacks and conventional threats
Fully
Crypto-Agile
Never replace your VPN again. Upgrades automatically, including to future cryptographic standards or requirements

+70% faster
+958% Max Throughput
Compared to leading competitors.
The best possible post-quantum data throughput and latency
The best possible post-quantum data throughput and latency
Would you feel safe with less?
*Ambit Client is the only enterprise VPN using exclusively CNSA 2.0 standard algorithms that we are aware of. CNSA 2.0 is the highest publicly disclosed set of requirements for National Security Systems
**70% faster download speeds measured by Oracle vs. leading enterprise VPN
***958% max throughput measured by Ambit Client validated @ 230Gbps vs. leading enterprise Zero Trust solution's publicly available data @ 24Gbps
**70% faster download speeds measured by Oracle vs. leading enterprise VPN
***958% max throughput measured by Ambit Client validated @ 230Gbps vs. leading enterprise Zero Trust solution's publicly available data @ 24Gbps
Why American Binary?
Your business is under cyber-attack.
It’s called “Harvest Now, Decrypt Later,” or HNDL. Nation-state actors are collecting your data and storing it to decrypt with a quantum computer. American Binary’s VPN is the only one that credibly defeats this and all other known current threats.
Quantum computers will defeat your existing cybersecurity.
Only post-quantum cryptography (PQC) that meets the US Government’s highest standards for National Security Systems (CNSA 2.0) can protect your data. American Binary solutions are third-party formally verified as compliant with CNSA 2.0 via symbolic proof.
Other solutions using any non-CNSA 2.0 and/or hybrid cryptography are considered transitionary at best and will require a major overhaul. With American Binary, simply do it once and do it right.
Other solutions using any non-CNSA 2.0 and/or hybrid cryptography are considered transitionary at best and will require a major overhaul. With American Binary, simply do it once and do it right.
Your success is at stake.
You've earned it.
Now make sure you keep it.
Now make sure you keep it.

PQC that meets CNSA 2.0 standards typically comes at significant cost of data speeds.
American Binary makes PQC usable via advanced networking technologies that maximize throughput and minimize latency. Testing by third parties shows that American Binary beats a top enterprise VPN's download speeds by 70%.
built different
Ambit Client is the only solution that can secure your company’s success.
Because its the only VPN using exclusively
CNSA 2.0 (NIST Level 5) algorithms for all 4 key components.

The Best and Last VPN you will ever need
The Best and Last VPN you will ever need
Uniquely Quantum-Secure
Verified by peer-reviewed symbolic proof. unmatched protection against Harvest Now, Decrypt Later attacks and conventional threats.
Simple for Users
Verified by peer-reviewed symbolic proof. unmatched protection against Harvest Now, Decrypt Later attacks and conventional threats.
Easy for Admins
Verified by peer-reviewed symbolic proof. unmatched protection against Harvest Now, Decrypt Later attacks and conventional threats.
*Ambit Client is the only enterprise VPN using exclusively CNSA 2.0 standard algorithms that we are aware of. CNSA 2.0 is the highest bar for National Security Systems.
Features
Post-Quantum Features
Ambit Client protects against HNDL and quantum attacks by exclusively using algorithms that comply with CNSA 2.0 (e.g., the Module-Lattice Key Encapsulation Module (ML-KEM 1024)) across all four key components without any hybrid cryptography:
- Authentication
- Key Exchange
- Bulk Encryption (AEAD)
- Hashing
Ambit Client also features modern, hyper-efficient networking technology that enhances performance and user experience; this is in contrast to the typical VPN and PQC experience that significantly degrade network performance. Testing by third parties shows that Ambit Client beats a top VPN's download speeds by 70%.
Additional VPN Features
- Protection against traditional cyber-attacks such as Man-in-the-Middle (MITM), remote hacking, Distributed Denial-of-Service (DDoS) attacks and session hijacking
- FireFalconTM Posture Check enforces endpoint compliance by validating OS updates, firewall status, device integrity, and approved geolocation before allowing VPN access.
- Data protection
- Online tracking mitigation
- Protection when using public network access points
- Multi-factor authentication, including hardware keys
- IPv4 and IPv6 compatibility
- Detailed logging (visible only to you)
Deployment Configurations
SaaS for Enterprise
For customers who want to minimize management
It features three software components:
It features three software components:
- Ambit Client Controller, cloud-hosted by American Binary
- Ambit Client Tunnel, cloud-hosted by American Binary
- Ambit Client VPN, installed on your users’ devices
On-Premises for Enterprise
For customers who want maximum control
Supporting 20+ architectures and featuring three software components:
Supporting 20+ architectures and featuring three software components:
- Ambit Client Controller, hosted in your environment
- Ambit Client Tunnel, hosted in your environment
- Ambit Client VPN, installed on your users’ devices

SaaS for Enterprise
For customers who want to minimize management
It features three software components:
- Ambit Client Controller, cloud-hosted by American Binary
- Ambit Client Tunnel, cloud-hosted by American Binary
- Ambit Client VPN, installed on your users’ devices

On-Premise for Enterprise
For customers who want maximum control
Supporting 20+ architectures and featuring three software components:
- Ambit Client Controller, cloud-hosted by American Binary
- Ambit Client Tunnel, cloud-hosted by American Binary
- Ambit Client VPN, installed on your users’ devices
HOw Can We Help
Frequently Asked Questions
What sets Ambit Client apart?

Ambit Client is an enterprise VPN that combines post-quantum cryptography (PQC) with networking improvements to mitigate both the cryptographic security impacts of quantum computing and the operational friction commonly induced by cryptographic security products. Unlike competing VPNs, it does not use any hybrid cryptography, which is regarded by NIST as "transitionary" technology at best. Ambit Client skips the transitionary state and is the final solution for defending against a quantum computer. With Ambit Client, businesses can do it once, do it right, and get back to their missions.
Ambit Client defeats Harvest-Now-Decrypt-Later (HNDL) attacks through the use of only PQC that is compliant with the Federal Information Processing Standard (FIPS) 140-3 and Commercial National Security Algorithm Suite (CNSA) 2.0 standards - the requirements set for National Security Systems in the US. When using Ambit Client, all information leaving an endpoint (e.g., workstation, laptop, mobile device) is fully encrypted with PQC. While bad actors may be able to capture information, they will not be able to decrypt, use, or derive value from it. As a result, Ambit Client creates future-proofing for a post-quantum world.
Underlying these capabilities is an innovative cryptographic protocol, MaxKyber®, that enables rapid, modular replacement of classical cryptographic primitives anticipated to be vulnerable to quantum computers with secure PQC algorithms within a framework extensible to currently ubiquitous network protocols (e.g., Transport Layer Security (TLS), IPSec IKEv2) as well as the generation of a product suite supporting all aspects of connected business operations.
All security claims have been formally specified and verified via peer-reviewed symbolic proof, an industry leading practice.
Ambit Client defeats Harvest-Now-Decrypt-Later (HNDL) attacks through the use of only PQC that is compliant with the Federal Information Processing Standard (FIPS) 140-3 and Commercial National Security Algorithm Suite (CNSA) 2.0 standards - the requirements set for National Security Systems in the US. When using Ambit Client, all information leaving an endpoint (e.g., workstation, laptop, mobile device) is fully encrypted with PQC. While bad actors may be able to capture information, they will not be able to decrypt, use, or derive value from it. As a result, Ambit Client creates future-proofing for a post-quantum world.
Underlying these capabilities is an innovative cryptographic protocol, MaxKyber®, that enables rapid, modular replacement of classical cryptographic primitives anticipated to be vulnerable to quantum computers with secure PQC algorithms within a framework extensible to currently ubiquitous network protocols (e.g., Transport Layer Security (TLS), IPSec IKEv2) as well as the generation of a product suite supporting all aspects of connected business operations.
All security claims have been formally specified and verified via peer-reviewed symbolic proof, an industry leading practice.
Which architectures can Ambit Client support?

Ambit Client can function as a post-quantum secure tunnel for the following architectures. Details available upon request.
Point to Point (P2P)
1. Basic P2P
2. Redundant P2P
Hub and Spoke
3. Single Hub
4. Active/Standby
5. Active/Active
6. Hierarchical
Mesh
7. Full Mesh
8. Partial Mesh
Access
9. Remote Access
10. DMZ Gateway
11. Extranet/B2B
Cloud
12. Site-to-Cloud
13. Multi-Cloud
14. Hybrid Cloud
Datacenter
15. Datacenter Interconnect
16. Geo-redundant
17. HA Cluster
Segmentation
18. Semgmentation
19. Multi-tenant
20. IoT/OT
Point to Point (P2P)
1. Basic P2P
2. Redundant P2P
Hub and Spoke
3. Single Hub
4. Active/Standby
5. Active/Active
6. Hierarchical
Mesh
7. Full Mesh
8. Partial Mesh
Access
9. Remote Access
10. DMZ Gateway
11. Extranet/B2B
Cloud
12. Site-to-Cloud
13. Multi-Cloud
14. Hybrid Cloud
Datacenter
15. Datacenter Interconnect
16. Geo-redundant
17. HA Cluster
Segmentation
18. Semgmentation
19. Multi-tenant
20. IoT/OT
What is MaxKyber®?

Think of Ambit Client as an armored car to transport your data. It needs quantum-resistant armor and a powerful engine to move large payloads of data safely and quickly. The MaxKyber® protocol plays the roles of the armor and the engine. MaxKyber® was designed to meet a number of technical challenges impacting PQC implementation, including:
1. Making the new PQC algorithms functionally useful by packaging them in a modular manner such that they could be readily integrated into any product requiring the secure exchange of information across a potentially insecure channel. Think of it like putting the engine and armor into a different type of car. This includes VPNs, such as Ambit Client VPN, and also networking and connectivity tools like software defined networks (SDN), browsers, and cloud services.
2. Ensuring that common features such as in-session key rotation were provided in a manner consistent with PQC cryptographic standards and CNSA 2.0. For example, the ML-KEM standard is silent on the issue of key rotation, which is a standard part of legacy cryptographic protocols like Internet Key Exchange, v.2 (IKEv2).
3. Ensuring the provision of a robust, post-quantum analog to the key establishment capabilities provided by classical cryptographic protocols such as the elliptical curve Diffie-Hellman key agreement protocol (ECDH) that was faithful to PQC standards and the requirements specified in CNSA 2.0.
4. Ensuring compatibility with existing networking standards and implementations. For example, PQC algorithms often run into issues with Maximum Transmission Unit (MTU) limitations. This constraint becomes of singular importance when mobile and Internet-of-Things (IoT) networks are considered.
5. Solving the key distribution problem between peers in a manner consistent with CNSA 2.0 without exposing a shared secret (e.g., a cryptographic key) to the risks of transit across an insecure channel.
The MaxKyber® protocol is implemented as a modular package that is portable to TLS and IPSec IKEv2, thus offering a short path to rapid, prolific PQC adoption.
1. Making the new PQC algorithms functionally useful by packaging them in a modular manner such that they could be readily integrated into any product requiring the secure exchange of information across a potentially insecure channel. Think of it like putting the engine and armor into a different type of car. This includes VPNs, such as Ambit Client VPN, and also networking and connectivity tools like software defined networks (SDN), browsers, and cloud services.
2. Ensuring that common features such as in-session key rotation were provided in a manner consistent with PQC cryptographic standards and CNSA 2.0. For example, the ML-KEM standard is silent on the issue of key rotation, which is a standard part of legacy cryptographic protocols like Internet Key Exchange, v.2 (IKEv2).
3. Ensuring the provision of a robust, post-quantum analog to the key establishment capabilities provided by classical cryptographic protocols such as the elliptical curve Diffie-Hellman key agreement protocol (ECDH) that was faithful to PQC standards and the requirements specified in CNSA 2.0.
4. Ensuring compatibility with existing networking standards and implementations. For example, PQC algorithms often run into issues with Maximum Transmission Unit (MTU) limitations. This constraint becomes of singular importance when mobile and Internet-of-Things (IoT) networks are considered.
5. Solving the key distribution problem between peers in a manner consistent with CNSA 2.0 without exposing a shared secret (e.g., a cryptographic key) to the risks of transit across an insecure channel.
The MaxKyber® protocol is implemented as a modular package that is portable to TLS and IPSec IKEv2, thus offering a short path to rapid, prolific PQC adoption.
How can you tell if a VPN is really quantum-resistant?

According to the highest global standard, CNSA 2.0, using one, two, or even three CNSA 2.0 or NIST-compliant algorithms is not enough for a VPN to be considered quantum-resistant. In order to do so, four key cryptographic components must use algorithms defined by CNSA 2.0:
1. Authentication
2. Key Exchange
3. Bulk Encryption (AEAD)
4. Hashing
If just one of those components is not compliant with CNSA 2.0, the entire product cannot be considered quantum resistant by virtue of the CNSA 2.0 standard.
Businesses can ask their VPN providers if they use the Diffie-Hellman Key Exchange, hybrid cryptography, or elliptic-curve cryptography. If the vendor answers “yes” to any of those questions, then according to CNSA 2.0 their VPN is not quantum-resistant and any data transiting through the VPN does not meet the highest standard for protection against HNDL.
Ambit Client, however, completely uses exclusively CNSA 2.0 algorithms (NIST Level 5) across all four key components, and truly meets the highest bar for quantum-resistance.
1. Authentication
2. Key Exchange
3. Bulk Encryption (AEAD)
4. Hashing
If just one of those components is not compliant with CNSA 2.0, the entire product cannot be considered quantum resistant by virtue of the CNSA 2.0 standard.
Businesses can ask their VPN providers if they use the Diffie-Hellman Key Exchange, hybrid cryptography, or elliptic-curve cryptography. If the vendor answers “yes” to any of those questions, then according to CNSA 2.0 their VPN is not quantum-resistant and any data transiting through the VPN does not meet the highest standard for protection against HNDL.
Ambit Client, however, completely uses exclusively CNSA 2.0 algorithms (NIST Level 5) across all four key components, and truly meets the highest bar for quantum-resistance.
What impact is quantum computing expected to have on cryptography? When will we feel it? What is HNDL?

Despite the emergence of stable, viable quantum computing platforms not being expected until close to the end of the decade (near to 2030), quantum computing is already having an indirect impact on asymmetric cryptography. Governments and malicious actors around the world are currently engaging in what is known as Harvest-Now-Decrypt-Later (HNDL) attacks. HNDL attacks are premised on a combination of the following ideas:
1. Information transiting the internet is routinely protected with asymmetric cryptographic algorithms that cannot be broken with classical computers today
2. Quantum computing will be able to break these asymmetric algorithms
3. While much of the information that transits the internet loses value quickly over time, a large, significant part of the information retains value over long periods
4. Seemingly innocuous information transiting the internet from many sources can be mosaicked to create valuable sensitive information
As a result, global actors are currently copying and storing everything that transits the internet and are doing so today.
1. Information transiting the internet is routinely protected with asymmetric cryptographic algorithms that cannot be broken with classical computers today
2. Quantum computing will be able to break these asymmetric algorithms
3. While much of the information that transits the internet loses value quickly over time, a large, significant part of the information retains value over long periods
4. Seemingly innocuous information transiting the internet from many sources can be mosaicked to create valuable sensitive information
As a result, global actors are currently copying and storing everything that transits the internet and are doing so today.
Why bother with VPN if TLS will get there eventually?

What we’re really getting at is “how do you PQ the world?”
The answer is to break it down into small pieces and start where there is immediate need. PQ TLS is an absolute necessity but seems a long way away and in its absence, PQ VPN is an easy and relatively affordable step you can take now to start mitigating HNDL attack surface and the current compounding leakage of sensitive information from remote workers and more.
Once TLS is ready, TLS and VPN don't interfere with each other and should be used in parallel. Until then, adopting X25519MLKEM768 for TLS as a starting point is better than not doing it, but there is a lot of work left to be done to ensure all of the standards that a web browser interacts with work will take time.
Adoption of a fully CNSA 2.0 compliant VPN should be done immediately to stop current data leakage.
The answer is to break it down into small pieces and start where there is immediate need. PQ TLS is an absolute necessity but seems a long way away and in its absence, PQ VPN is an easy and relatively affordable step you can take now to start mitigating HNDL attack surface and the current compounding leakage of sensitive information from remote workers and more.
Once TLS is ready, TLS and VPN don't interfere with each other and should be used in parallel. Until then, adopting X25519MLKEM768 for TLS as a starting point is better than not doing it, but there is a lot of work left to be done to ensure all of the standards that a web browser interacts with work will take time.
Adoption of a fully CNSA 2.0 compliant VPN should be done immediately to stop current data leakage.
How easy is it to install and operate Ambit Client?

The SaaS version of Ambit Client enables account setup and installation on endpoint devices in minutes. If an on-premises configuration is selected, server installation, configuration, and subsequent device installation are typically completed in half a day or less. Endpoint installation follows standard platform patterns. Windows, Mac, iOS, and Android are supported.
Ambit Client is designed for a low/no burden adoption experience. Operation requires minimal expertise or training, and the application itself is initialized with a single click. Ambit Client can be configured to automatically activate on startup, and maintains protection even after network interruptions.
Ambit Client is designed for a low/no burden adoption experience. Operation requires minimal expertise or training, and the application itself is initialized with a single click. Ambit Client can be configured to automatically activate on startup, and maintains protection even after network interruptions.
Where can I find your whitepaper and other documentation?

Where can I download the VPN?

Only customers can use the VPN. If you are a customer, please see the Welcome Email we sent you for download links.
If you would like to become a customer, please contact sales.
If you would like to become a customer, please contact sales.
Media and Recognition
Contact Sales
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
To report any security or vulnerability issues, please send an email to disclosure@ambit.com

















