QNyx 4.2.0ENGINEERED IN CANADA / DEPLOYED AT THE EDGE

Post-quantum.
Full throttle.

Protect the traffic.
Keep the performance.

Post-quantum key exchange. Authenticated identity. Multi-gigabit encrypted transport. All in a 1 MB Rust binary.

LinuxAndroid100% userspace
ENCRYPTED TRANSPORTQNyx 4.2.0
ENDPOINTLinux / Android
QNyxENCRYPTED
REMOTELinux
ENCRYPTED
DATA PLANE
>1.5 Gbps
ML-KEM-1024ML-DSA-87AES-256-GCM
Logical tunnel view · physical-link test result
>1.5 Gbps

Encrypted throughput

<1 ms

Added latency

1 MB

Standalone binary

100%

Rust · Userspace

02SYSTEM ARCHITECTURE

Your applications.
A stronger transport.

QNyx carries ordinary IP traffic through the host’s standard virtual network interface. Encryption and tunnel processing live entirely in userspace.

THE QNYX DATA PATHLOGICAL VIEW
ApplicationsOrdinary IP traffic
Host networkingIP stack + TUN / VPN interface
100% USERSPACE

QNyx 4.2.0

Authenticate peers
Encrypt / decrypt traffic
Rekey / recover sessions
RUST · 1 MB STANDALONE CORE
TCP / KEY EXCHANGEEstablish trust

ML-KEM-1024 + ML-DSA-87

UDP / DATA PLANEMove encrypted traffic

AES-256-GCM

QNyx uses the existing operating system network stack. No custom kernel module. No patched networking stack.
01 / INTEGRATE

Keep your applications

Route IP traffic into the tunnel through familiar host networking interfaces.

02 / AUTHENTICATE

Identity is a keypair

ML-DSA-87 identifies peers and binds tunnel addressing to cryptographic identity.

03 / TRANSPORT

Separate the channels

TCP establishes the session. UDP carries encrypted data on a port selected for the session.

03CRYPTOGRAPHY

Post-quantum
from the first handshake.

QNyx 4.2.0 combines post-quantum key establishment and signatures with AES-256-GCM authenticated encryption and SHA-512 key derivation.

KEY ESTABLISHMENT

ML-KEM-1024

Establish shared session material with post-quantum key encapsulation.

IDENTITY & AUTHENTICATION

ML-DSA-87

Authenticate both peers using post-quantum digital signatures.

AUTHENTICATED ENCRYPTION

AES-256-GCM

Protect handshake messages and data-plane traffic with separate keys.

KEY DERIVATION

SHA-512

Derive handshake and data keys from the shared secret and context.

FROM SHARED SECRET TO SECURE TRAFFICHANDSHAKE OVERVIEW
CLIENTSERVER
  1. 01
    Establish a shared secret

    ML-KEM-1024 key encapsulation over the TCP channel.

  2. 02
    Derive separate session keys

    SHA-512-based derivation with context produces a handshake key and a data key.

    HANDSHAKE KEYDATA KEY
  3. 03
    Authenticate the client

    Client signs the data key with ML-DSA-87. AES-256-GCM protects the handshake message.

  4. 04
    Authenticate the server

    Server verifies, signs the same data key, and returns an encrypted response. Client verifies.

  5. 05
    Open the encrypted data plane

    Successful authentication enables AES-256-GCM-protected UDP traffic.

Conceptual protocol sequence. Session establishment and data transport use separate derived keys.

The QNyx header travels inside the encryption.

The UDP payload does not expose a plaintext QNyx protocol header. Outer IP/UDP addressing, packet sizes, and timing remain visible to the network.

04RESILIENCE

Links break.
QNyx reconnects.

A dropped connection starts a recovery process. QNyx reconnects, re-establishes keys, verifies the peer, and restores the tunnel when connectivity returns.

900 s
Automatic session rekeying
Fresh session material every 15 minutes
RECOVERY IS PART OF THE PROTOCOL
Tunnel activeAuthenticated, encrypted traffic
Link lostDetect the disconnected peer
Reconnect & re-authenticateFresh key exchange · verify identity
Traffic resumesIdentity-bound addressing retained

Recovery time depends on link availability and configuration.

Identity-bound addressingPublic-key enrolmentAutomatic recovery

05DEPLOYMENT

Small footprint.
Serious reach.

From Linux servers and edge computers to Android devices. One transport design, compiled for the platform you deploy.

STANDALONE BINARY1 MB

100% Rust.
100% userspace.

Compact enough for the edge.
Fast enough for multi-gigabit links.

Linux x64

Servers, virtual machines, routers, and conventional edge hardware. Standard TUN integration.

SERVER / EDGE

Linux ARM64

Compact boards and ARM infrastructure, using the same protocol and cryptographic suite.

EMBEDDED / ARM

Android

The Rust transport integrated with Android’s VPN interface for mobile endpoints.

MOBILE

Target-specific builds. Shared protocol. Shared identity model.

06OPERATOR DOCUMENTATION

Built to be operated.

Installation, key enrolment, network requirements, and troubleshooting. Request the QNyx 4.2.0 operator documentation for your deployment.

Request the manual

07TECHNICAL FAQ

A closer look.

What is QNyx?

QNyx is a post-quantum native VPN and secure transport from Xaoc Industries. It carries ordinary IP traffic over an authenticated, encrypted tunnel, with post-quantum key establishment and peer identity built into the protocol.

What does >1.5 Gbps encrypted throughput mean?

Xaoc has measured QNyx at more than 1.5 Gbps of encrypted tunnel throughput on physical hardware. Results depend on hardware, packet sizes, configuration, and network conditions.

Where does QNyx run?

Linux on x64 and ARM64, plus Android. Linux deployments use a standalone binary compiled for the target architecture; Android integrates the Rust transport with the platform VPN interface. The protocol and identity model are shared across platforms.

Does 100% userspace mean the kernel is bypassed?

The QNyx transport and cryptographic processing run in userspace. Linux provides the IP stack, standard TUN interface, sockets, and network drivers. QNyx does not require a custom kernel module or a patched network stack.

How are peers identified and admitted?

ML-DSA-87 keypairs identify peers. Approved public keys control admission, and tunnel addressing is bound to cryptographic identity within the selected server context. Reconnecting to the same server preserves that identity-based addressing.

What happens when connectivity is lost?

QNyx automatically attempts to re-establish the connection, performs a fresh post-quantum handshake, authenticates the peer, and resumes the data channel when the underlying network is available. Session material also rotates automatically on a 15-minute cadence.

XAOC INDUSTRIES / ONTARIO, CANADA

Put QNyx
on your network.

Start with a real link. Measure throughput, interoperability, and recovery in your environment.

Let’s build your pilot
entColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-key-round" aria-hidden="true">Public-key enrolmentAutomatic recovery

05DEPLOYMENT

Small footprint.
Serious reach.

From Linux servers and edge computers to Android devices. One transport design, compiled for the platform you deploy.

STANDALONE BINARY1 MB

100% Rust.
100% userspace.

Compact enough for the edge.
Fast enough for multi-gigabit links.

Linux x64

Servers, virtual machines, routers, and conventional edge hardware. Standard TUN integration.

SERVER / EDGE

Linux ARM64

Compact boards and ARM infrastructure, using the same protocol and cryptographic suite.

EMBEDDED / ARM
QNyx 4.2.0 · MADE IN CANADA