ADD EXHB 5 ea030589201ex99-3.htm DEEP DIVE - NAORIS QUANTUM PROTOCOL

Exhibit 99.3

 

Naoris Quantum Protocol is building the verification layer the post-quantum internet will require.

 

Hackers, NSA codebreakers, even architects of the internet have all joined forces to prepare your banks and favorite businesses for the threat of “Q-Day” — the Day when quantum computing could crack the internet’s encryption.

 

But here’s the really scary thing…

 

Q-Day doesn’t just break tomorrow’s encryption...

 

It makes everything already recorded untrustworthy — because every log, transaction and audit trail signed with today’s cryptography can be forged after the fact.

 

Naoris is designed to address the whole timeline: a post-quantum distributed mesh that continuously validates every device, system, server, service and application, so the data and infrastructure of the past stay provable.

 

It makes the systems of today stay resilient. And it ensures the quantum hardware of the future is trustworthy for the first time, with no single point that even a quantum computer can break.

 

The tech has been tested across over 1 million connected endpoint nodes”… and the company has signed its first commercial agreements.

 

“The internet was built to move information. It was never built to prove it.”
— David Carvalho, Founder and CEO

 

 

Insert Offering Summary

 

 

 

In the BIG IDEA section, you learned how for 50 years, the internet has been built layer by layer.

 

First: a way for computers to connect.

 

Then: a way to find one another.

 

Then: a way to encrypt what they send.

 

And finally: a way to decide who gets access.

 

You were also introduced to the players and key stakeholders which were vital to each evolution.

 

Now, the Q-Day threat has created the need for the next layer — where a device or server must continually prove they are who they say they are.

 

This trust is incredibly important as billions of new devices come online… and as AI begins to act on our behalf.

 

Naoris is looking to take its post-quantum trust protocol, and turn it into the default security layer running underneath everyday infrastructure.

 

 

 

Most systems today — banks, power grids, hospitals, governments, AI labs — assume trust rather than continuously proving it. That’s a problem.

 

 

 

 

 

SIDEBAR:

 

Quantum Computing is on the doorstep

 

The countdown to Q-Day is already running.

 

Google has targeted 2029 to complete its own post-quantum migration.1

 

 

1Ars Technica, “Google bumps up Q-Day estimate to 2029” (Mar 2026): https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-previously-thought/ ; Google, “The quantum era is coming—are we ready to secure it?”: https://blog.google/innovation-and-ai/technology/safety-security/the-quantum-era-is-coming-are-we-ready-to-secure-it/

 

2

 

 

The U.S. government has now put several federal post-quantum deadlines on the calendar for 2030 and 2031.2

 

National Security Systems are already moving under NSA transition requirements.3

 

And security agencies are warning about a problem that starts before Q-Day: Harvest now. Decrypt later.4 A tactic where hackers can steal encrypted data today, store it…then, simply, wait until the right quantum computer exists that can open it.

 

Naoris is building ahead of the scramble that will happen in the next 3-5 years.

 

The transition has already started.

 

 

The Big Problem We All Face

 

Most modern security systems on the market today have the same blind spot.

 

They all ask the machine to report on itself.

 

Your laptop runs an antivirus software. You likely have one right now loaded. The antivirus asks your laptop, “Are you okay?”

 

Your computer checks its processes… applications, files, connections, security tools… and then replies back, “I’m okay.”

 

A hacker’s first goal is to attempt to hide malicious activity, disable defenses and make everything appear normal.

 

Much like a scene in a movie where the hacker changes the security cameras to appear as if no one is there when a robber actually is…

 

The alarm never goes off and nothing is wrong until it’s too late. In fact, the breach can sit there for months.

 

That’s where the current standard is flawed.

 

Right now, you either take a device at its word…

 

Or you have to trust a central security company (or firewall) to be the sole authority on what’s ‘okay’ – a potential single source of failure.

 

Naoris approaches this problem differently.

 

Naoris is designed so a device does not get to unilaterally declare, “I’m ok and trustworthy”. It creates a “trust mesh” where participating devices on the network help validate its state.

 

This concept of distributed trust is what the team behind Naoris has been working on for the past 8 years — a team that consists of the very people who helped build the internet’s original trust layer

 

 

2Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” 22 June 2026 (Fed. Reg. Doc. 2026-12909): https://public-inspection.federalregister.gov/2026-12909.pdf
3NSA, CNSA 2.0 FAQ v2.1 (Dec 2024): new National Security Systems compliant from 1 January 2027; exclusively CNSA 2.0 by 2033. https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
4CISA, NSA & NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography” (2023): https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography

 

3

 

 

The Naoris Quantum Protocol Team

 

David Carvalho - Founder and CEO

 

 

Carvalho spent more than twenty years as an ethical hacker and security chief in the exact regulated, critical environments Naoris now wants to sell into.

 

His career included security engineering and operations at AT&T…

 

Serving as the Chief Information Security Officer of London City Airport where he protected critical national infrastructure from outsider hackers…

 

And he was the Chief Information Security Officer (CISO) of OCS Group, a role where he oversaw government and critical-infrastructure environments.

 

Carvalho spent two decades watching the same pieces fail — i.e. you can add another firewall, another password, another layer, but sooner or later something inside the system has to be trusted, and that’s the thing that gets exploited.

 

4

 

 

Youssef El Maddarsi - Co-Founder & Chief Business Officer

 

 

A Co-Founder and also the Chief Business Officer, Maddarsi is an entrepreneur with more than ten years of strategic-development and international-business.

 

His experience spans cybersecurity, AI and digital infrastructure and includes work with governments, enterprises and strategic partners globally.

 

Sumit Chauhan - Chief Technology Officer

 

 

Chauhan has spent 25+ years building enterprise-grade systems, with expertise spanning product engineering, technical consulting, solution architecture, and co-founding an IT company.

 

5

 

 

His experience also includes work with AI, machine learning, big data, blockchain, cloud technologies, product engineering and solution architecture.

 

He built Naoris with the team, testing over 1 million connected endpoint nodes.

 

David Holtzman - Executive Chairman

 

 

David Holtzman helped build the actual infrastructure of the internet…

 

He designed the global Domain Name System registration architecture that ICANN still uses — the ’second layer’ of the internet when instead of using numbers to find a website, you could now type in a name.

 

He was also CTO of Network Solutions in the late 1990s, when it ran the internet’s master root server.

 

That means he literally helped lay plumbing the modern internet runs on today.

 

Before that, he served as the Chief Scientist, Internet Information Group, at IBM. He built Minerva, a distributed system used by Wall Street and NATO.

 

On top of all that, he served as a military codebreaker with the US Naval Security Group and later the NSA.

 

Holtzman is a true cybersecurity expert who’s been in the trenches since the internet took off…

 

And he believes Naoris is the next layer of the internet — to be built on top of what he helped build.

 

6

 

 

Magnus Fyhr — Chief Financial Officer

 

Fyhr was a former investment banker and senior equity-research analyst on Wall Street with experience in financial leadership, fundraising, investor relations, business development and due diligence for growth-stage companies.

 

 

Also influential to the development of Naoris is the late Lt. Gen. Kjell Grandhagen, former Chief of the Norwegian Intelligence Service (2010–2016) and Chairman of the NATO Military Intelligence Committee (2015–2016).

 

Grandhagen identified the centralized cybersecurity model as fundamentally flawed, helping inspire the project from its earliest testing phase.

 

His diagnosis was that the centralized model of trust — one authority vouching for everything from a single point — is fundamentally flawed. His words to Carvalho, which Naoris was built on: “We need to play a different game.”

 

How Naoris Quantum Protocol works:

 

Naoris isn’t a new hardware solution you have to find space for in your office.

 

There is no “rip and replace”.

 

It’s installed on your device through software or firmware. It is designed to run as a background program.

 

7

 

 

You likely have many running on your phone and computer right now.

 

Naoris sits underneath the apps you actually touch, down at the operating-system level of the device.

 

  Imagine a night-shift guard living in the basement with cameras watching everything above making sure everything's normal.
   
  That’s the system watching the machine's condition, cryptographically signing a statement of what it sees, and passing it around to other devices in the network to check that statement against what they'd expect.
   
  The company calls the resulting web of cross-checks its Trust Mesh.
   
  Where it sits is key: below security tools, below cloud infrastructure, above hardware — a single validation layer that gives everything stacked on top of it the one thing none of them can produce on their own: proof.
   
  And it could work on nearly any device…
   
  No matter if it's a legacy laptop or a brand-new data center server for an AI company.
   
  ● It’s a lightweight background process (Naoris claims it will not slow down a machine or server’s normal running processes).
  ● The user/employee/company never sees it as it works in silence beneath the surface (as long as it's downloaded on the network, it is up and running).
  ● There's no need to build new infrastructure or upgrade technology. Naoris is designed to be added to infrastructure a company already has, and not to replace it.

 

You keep your hardware. You stay on the same network you’re already on. All you’re changing is how the machines on the network all trust each other.

 

This ease of integration is what makes it commercially realistic. It’s unlikely that any company or government is would be willing to rip out their entire system for a security upgrade.

 

8

 

 

How Naoris actually watches all the devices without disruption and without looking
at what you’re doing on your computer all day

 

Importantly, at all times the system watches the machine’s condition… not the user’s content.

 

It isn’t reading your emails. It isn’t capturing your passwords. Instead, it’s watching the machine itself.

 

Specifically:

 

The processes and services running

 

Installed applications and software changes
  
Network connections
  
File changes
  
Hardware state
  
The device’s overall security posture, measured against a known baseline

 

The system is designed to sit underneath, checking its ’state’ 24/7.

 

From this, it is designed to produce one thing: a signed proof of the machine’s current state that other Trust Mesh devices check and validate.

 

And it could work from Day 1.

 

How the Validation Actually Works

 

At a high level, the verification process can be thought of in five steps.

 

STEP 1 — Observe

 

Naoris monitors relevant aspects of the device’s security state.

 

STEP 2 — Attest

 

Naoris’ node creates a cryptographically signed attestation…essentially evidence describing the state it observed.

 

STEP 3 — Validate

 

Other participating nodes evaluate that evidence according to defined policies and expected conditions.

 

STEP 4 — Reach a Distributed Verdict

 

Naoris uses a consensus architecture it calls dPoSec — Distributed Proof of Security

 

9

 

 

The protocol is designed so that the device being evaluated cannot simply declare itself trustworthy and end the discussion.

 

Other validators participate.

 

STEP 5 — Act

 

If a machine fails the relevant checks, the system can flag the device and, depending on the deployment and policy configuration, potentially trigger additional action.

 

Observe → Prove → Validate → Agree → Act

 

According to Management: “Two details matter for anyone who has seen security tools gamed. The set of validators rotates on every evaluation, so a machine never gets to pick its own judges. And trust decays unless it is re-earned — a device that was fine yesterday has to prove it again today.”

 

 

For fifty years the law of security was: every device you add makes you weaker — one more door.

 

On Naoris, every device you add is one more defender — a proof node validating everything around it.

 

And it works at machine speed, which is what the AI era needs.

 

Here’s a hypothetical example of the same thing happening with two AI agents instead of two servers...

 

A treasury agent asks another agent to make a payment. Before the money moves, the trust layer runs the full check in-line:

 

1.Is the device it runs on intact?

 

2.Is the identity attested?

 

3.Do the surrounding nodes agree? Then seals the verdict with a post-quantum signature.

 

4.Verdict: proceed. Elapsed time: milliseconds.

 

An unknown agent tries the same request from a tampered machine. Verdict: halt, quarantined. Also milliseconds.

 

10

 

 

There’s no “log” to read the next morning telling your cybersecurity there’s a problem. The verdict hits before any action is allowed, preventing it from happening in the first place. And the signed trail proves what every agent did — and why it did it.

 

 

Why Naoris Quantum Protocol is Quantum-Proof

 

The current signatures protecting most of today’s systems rely on public-key math — RSA and elliptic-curve — which a large enough quantum computer is expected to break.

 

Naoris signs its proofs with ML-DSA-87 instead.

 

You don’t need to understand what that means except ML-DSA is one of the post-quantum signature standards finalized by the National Institute of Standards and Technology (NIST).

 

ML-DSA-87 is the highest NIST security-category parameter within their standard.

 

NSA guidance for National Security Systems also specifies ML-DSA-87 for relevant digital-signature uses.

 

11

 

 

NIST is instructing all firms to adapt new signatures from this same encryption family. Those deadlines are on the table already:

 

Google is pushing to be migrated by 2029.

 

U.S. federal key establishment = do it by 2030.
   
U.S. federal digital signatures = done by 2031.
   
Full National Security System migration = complete system overhaul nationwide by 2035.

 

In fact, the threat of quantum attacks is so urgent, the White House pulled forward the federal deadline four years:

 

On 22 June 2026, Executive Order 14412 pulled the federal deadline forward by four to five years from the old 2035 target for high value assets and high impact systems— and the digital-signature standard the 2031 deadline points at is ML-DSA / FIPS 204, the exact standard Naoris signs every validation with. Two days later the White House budget office gave every agency 120 days to file its migration plan.

 

Meanwhile, a May 2025 survey of 1,042 senior security executives found that 69% know quantum computing is a risk to their encryption… but only 5% have implemented quantum-safe encryption.5

 

Nineteen out of twenty haven’t started.

 

The rules now say they have to. And that’s an opportunity for Naoris.

 

[VISUAL — 69% aware vs. 5% deployed — two-bar or donut. Source: https://www.globenewswire.com/news-release/2025/05/08/3077339/0/en/Quantum-Readiness-Gap-DigiCert-Study-Finds-Just-5-of-Enterprises-Have-Quantum-Safe-Encryption-in-Place.html]

 

Can any major company just copy Naoris’ code and put it in their own systems?

 

Naoris traces its origin to 2018, when founder David Carvalho became convinced that the way the world hands trust to machines was fundamentally broken…and (with incredible foresight) our devices wouldn’t survive what was coming next in computing.

 

 

5Quantum Readiness Gap: A DigiCert Study On Quantum-Safe Encryption

 

12

 

 

If this works, what stops a giant like Microsoft or Crowdstrike from cloning it next quarter?

 

The company’s moat rests on three things:

 

First (and most overlooked) is the architecture itself. A distributed trust network becomes more valuable as more devices join it. That’s a network effect: the first mover who actually wins adoption is the hardest to take down, because the value lives in the size of the mesh, not just the code.
  
Second, patents. Naoris holds a portfolio of provisional patent applications covering its approach. The Naoris Protocol, the Trust Mesh and all related software, algorithms and trade secrets are owned by the company.
  
And third, the head start. Years of research are not something a competitor spins up over a weekend. It’s taken almost a decade for Naoris to publish 4 research papers and test over 1 million connected endpoint nodes.

 

From research to real-world tests

 

According to management, a recently completed test program onboarded over 1 million connected endpoint nodes (non-paying), with the large majority joining through a lightweight PQ Daemon Node — or for most people, simply an extension in their Chrome browser.

 

The test didn’t just demonstrate the architecture could operate across a very large distributed population of participating devices, it...

 

Verified over 100 million post-quantum cryptographic validations
  
over 600 million integrity enforcement events were processed
  
Secured over 3 million post-quantum digital identities

 

This appears to support several things:

 

1.Their Naoris “Protocol” could operate across a large distributed participant base

 

2.Post-quantum signed validations can be processed at substantial volume

 

3.Users/companies could download Naoris without slowing down their systems, etc.

 

NOTE: This was a controlled test for viability and is not actively going on anymore. However, the live operation to join their “Trust Mesh” kicked off April 1, 2026, meaning the commercial, real-world phase is still early-stage relative to the testnet volume cited above

 

After the success of this controlled test…  

 

13

 

 

What markets could benefit from the Naoris solution?

 

Banking and Finance:

 

Security spending in banking, financial services and insurance alone is projected to reach roughly $146 billion by 2030.

 

And the major players in that market are already moving…

 

In December 2025 the Bank for International Settlements, with the Bank of Italy, the Bank of France, the Deutsche Bundesbank and Swift, ran post-quantum signatures on real liquidity transfers in the euro area’s main payment system.

 

Europol has also issued a call to action to the whole financial sector.

 

And in January 2026 the G7’s Cyber Expert Group, chaired by the U.S. Treasury and the Bank of England, published a coordinated post-quantum roadmap.

 

The central banks have started. Main Street’s banks will have to follow.

 

Government and Defense:

 

For governments and national-security organizations, the challenge is bigger than cybersecurity alone: sensitive data, legacy infrastructure, strict sovereignty requirements, and an accelerating shift toward post-quantum cryptography all collide in the same environment.

 

That makes post-quantum machine trust a natural fit for Naoris — with governments, systemically important institutions, defense organizations, and national-security agencies all potential target customers.

 

These are environments where critical systems must remain under sovereign control. Cryptographic keys cannot simply be handed to outside parties. And every action needs a verifiable audit trail owned by the organization itself.

 

Naoris calls this digital sovereignty at scale.

 

Energy and Critical Infrastructure:

 

Power, utilities, industrial controls, transport, factories… all these are full of equipment that stays in the field for years.

 

Naoris can sit alongside old infrastructure instead of ripping it out. And that matters most here.

 

14

 

 

Telecom:

 

Telecom companies run enormous interconnected networks where integrity and uptime are constant concerns. Again, Naoris can sit alongside old infrastructure and help flag issues before they become problems.

 

Enterprise Technology:

 

Cloud, endpoints, data centers, AI infrastructure. Past a certain size, every big company hits the same wall: too many machines for any human to personally know which ones still deserve trust. Naoris Trust Mesh solves this.

 

AI:

 

The next customer is a machine. Autonomous agents already negotiate, transact and control physical processes — and neither side can prove what the other is.

 

Naoris describes its answer as Post-Quantum-Attested AI Identity and has filed for the “Naoris Decentralized Swarm AI” mark. The EU AI Act’s Article 50 transparency rules for AI-generated content have applied since 2 August 2026, with penalties up to €15 million or 3% of worldwide turnover.

 

Naoris’ current product line:

 

Naoris has a family of products to build into companies’ infrastructure:

 

1.The core Naoris Protocol (which continuously validates systems, identities, devices and data)

 

2.PQVPN by Naoris (a distributed post-quantum VPN and secure-routing layer)

 

3.PetalVault (a post-quantum evidence layer for Bitcoin ownership and audit workflows: prove you hold the coins without moving them) and…
   
4.The Naoris Community Intelligence Layer (post-quantum-attested AI identity and creator authenticity).

 

No matter the product, the same idea applies…

 

Every machine, device, server is monitored for its normal state. Any changes detected by others connected to them through the Trust Mesh are flagged.

 

15

 

 

Notable Market Traction

 

Management claims to have a robust pipeline of opportunities and two recent agreements indicate early market interest:

 

1)Electra AI. In May 2026, Naoris announced a partnership with Electra AI to bring post-quantum cybersecurity to AI battery intelligence, the fast-growing layer where always-connected battery systems meet the AI models that monitor, optimize, and control them.

The two companies are pairing Electra’s AI Brain for Batteries™ platform with Naoris Quantum Protocol’s post-quantum, decentralized trust layer to advance a cybersecurity framework designed specifically for AI battery intelligence.

Electra AI is a leading AI-driven cleantech and B2B software company, accelerating the world’s transition to electrification by unlocking the full potential of battery technology. The partnership arrives alongside a tightening regulatory landscape. Frameworks including the EU Battery Passport, the NIS2 Directive, and UNECE R155 are raising expectations for traceability, cybersecurity, and resilience across battery-powered infrastructure.

2)xCure (South Korea). In March 2026, Naoris also signed a joint venture with the Korean company xCure, a  Korean cybersecurity company, to commercialize its post-quantum cryptography and decentralized cybersecurity products in the Korean market. Naoris granted the JV exclusive distribution rights, commercialization rights, and a limited IP license for our products within Korea for an initial one-year exclusivity period. 

 

Use of Funds

 

Naoris intends to use the capital raise to further:

 

Sales and operations expansion
  
Product engineering and continuing research
  
Cloud, equipment and node infrastructure
  
Customer integration and platform work
  
Marketing and demand generation
  
General working capital

 

16

 

 

Management estimates a $24 million raise would fund at least about 15 months of operations. Their goal is to reach cash-flow positive by the end of 2027 with future growth funded from generated cash (please keep in mind this is a goal and not a guarantee).

 

   $15,000,000   $20,000,000   $24,000,000 
Gross proceeds  $15,000,000   $20,000,000   $24,000,000 
Selling agent commissions1  $900,000   $1,200,000   $1,440,000 
Other offering expenses  $1,072,300   $1,072,300   $1,072,300 
Net proceeds  $13,027,700   $17,727,700   $21,487,700 
                
Cloud Infrastructure  $4,095,172   $5,561,141   $5,590,400 
Equipment & Node Infrastructure  $997,820   $1,396,216   $3,827,284 
Expanding the Operation Team  $1,255,763   $1,705,331   $1,714,305 
R&D/Product Engineering  $3,409,411   $4,630,493   $4,654,857 
Expanding Finance Team  $1,490,388   $2,023,948   $2,034,597 
Marketing and Demand Generation  $878,257   $1,192,819   $2,398,189 
Expanding Marketing Team  $559,600   $760,003   $764,002 
Working Capital/Other  $341,289   $457,749   $504,066 
Total use of net proceeds  $13,027,700   $17,727,700   $21,487,700 

 

5 Catalysts for Naoris right now:

 

Q-Day is coming and the theft could potentially have already begun. Quantum computers are expected to break today’s public-key encryption. Under harvest now, decrypt later, data is being stolen today to be unlocked later. Google just moved its Q-Day migration deadline up to 2029.

 

The encryption fix is now mandated and almost nobody’s ready. Government deadlines run 2027–2035. Yet 69% of security leaders know the risk and only 5% have acted. That gap is the demand.

 

Provisional patents filed, four peer-reviewed papers, and a 1M+ node test network support the technology.

 

The first agreements are signed. A joint venture with xCure and a multi-year deal with Electra AI.

 

One platform – but a family of products. Naoris has multiple products that can attract different types of businesses and serve multiple markets

 

Risks to consider:

 

1.Naoris could fail.

 

This is an early-stage technology investment, and there are several very real ways the thesis you just read could go wrong.

 

2.The technology could work and customers still might not buy it.

 

This may be the biggest risk. Large banks, governments and infrastructure operators don’t adopt new security architecture casually. Naoris could have genuinely useful technology and still find that selling it takes longer and costs more than management expects. The early agreements are encouraging; they are not proof of broad adoption.

 

17

 

 

3.Big competitors won’t sit on their hands.

 

Cybersecurity is one of the most competitive markets on Earth. Some of the world’s largest technology and security companies already have deep relationships with the exact customers Naoris wants. Those companies have a brand, massive amounts of capital and the ability to build, acquire or bundle competing technology. Naoris’s patents and architecture may help it stand apart, but they don’t guarantee it owns the market or even a piece of it.

 

4.The quantum transition could take longer than expected.

 

Nobody knows exactly when a cryptographically relevant quantum computer arrives. It could be sooner, or much later. Government schedules create reasons to prepare now, but organizations can still move slowly, budgets can slip, and standards and deadlines can change. If customers don’t feel enough urgency, the opportunity may develop more slowly than Naoris hopes.

 

5.Naoris still has to finance the journey.

  

The company is entering commercialization from an early financial base. Their audited statements showed no commercial revenue during the audited period. There is no guarantee that $24 million will bring it to profitability.

 

6.Capital and dilution risk.

 

More capital may be required which could create dilution for your position.

 

7.And, as always, investment comes with significant risk and there’s no guarantee of return.

 

Frequently Asked Questions:

 

Are there plans to IPO eventually?

 

This offering is the listing. It is structured to close only if at least $15 million is raised and the shares are approved for listing on Nasdaq Capital Market — so if it closes, Naoris’ Class A shares will be publicly listed. There is no guarantee the listing approval is obtained; if it isn’t, the offering doesn’t close and funds are returned. Beyond that, management has said it will look at a broader public offering in the future as the company grows.

 

Is Naoris a cryptocurrency or related to Bitcoin?

 

No. It uses distributed-ledger technology, the same “many independent machines agreeing without a central referee” idea that makes Bitcoin’s ledger so hard to fake, but it applies that to the integrity of machines, not to a cryptocurrency or any financial number. Investors are buying shares of a company here, not a crypto token.

 

What about the Naoris Token?

 

This is not part of the investment or their technology today.

 

18

 

 

Does Naoris have customers?

 

The company has signed its first commercial agreements but has not yet generated revenue.

 

How much are shares today?

 

Class A common shares at $4.00 each, through a Regulation A offering, with a minimum investment of 200 shares ($800).

 

Do customers have to hand over their data to Naoris?

 

No and that’s deliberate. The whole benefit of Naoris is to stop trusting one central authority, so it would make no sense if Naoris became that central authority.

 

Customers run their own nodes, and the Trust Mesh can run private, on-premise, sovereign-cloud, hybrid, or fully air-gapped.

 

Naoris is not looking through emails and using/selling that data.

 

Has anyone actually paid for Naoris yet?

 

The first commercial agreements are signed: a South Korean joint venture with xCure and a multi-year enterprise agreement with Electra AI.

 

Is the technology proven?

 

Four peer-reviewed papers, a test network across over 1 million connected endpoint nodes, and controlled reconstructions support the technology; no product has been adopted by any customer or received certification.

 

Ready to Invest? Click Here

 

Please read the BIG IDEA section to learn more about why Naoris is important in this time of quantum computing advancements.

 

Please read the MARKET COMPS to learn about other tech companies working on similar projects and how they compare to Naoris.

 

Important Disclosures & Investor Notice

 

DISCLOSURE: All information contained in this communication should not be considered investment advice nor an offer to buy or sell securities, but for educational and informational purposes only. Investing in private or early-stage offerings (such as Reg A, Reg S, Reg D, or Reg CF) involves a high degree of risk. Securities sold through these offerings are not (most of the time) publicly traded and therefore illiquid. Additionally, investors will receive restricted stock that is subject to holding period requirements. Companies seeking capital through these offerings tend to be in earlier stages of development and have not yet been fully tested in the public marketplace. Investing in private or early-stage offerings requires a tolerance for high risk, low liquidity, and a long-term commitment. Investors must be able to afford to lose their entire investment. Such investment products are not FDIC insured, may lose value, and have no bank guarantee.

 

19

 

 

Naoris Quantum Protocol Inc. (the “Company”) has filed an Offering Circular relating to the Company’s securities, initially filed with the Securities and Exchange Commission (the “SEC”) on August 5, 2026 and forming part of the offering statement on Form 1-A qualified by the SEC on [●], 2026 (the “Offering Circular”). An investment in the Company’s securities involves significant risks. Please see the summary of certain risk factors set forth at the end of this communication and the more detailed discussion under “Risk Factors” in the Offering Circular before making an investment decision.

 

:Ars Technica, “Google bumps up Q-Day estimate to 2029” (Mar 2026): https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-previously-thought/ ; Google, “The quantum era is coming—are we ready to secure it?”: https://blog.google/innovation-and-ai/technology/safety-security/the-quantum-era-is-coming-are-we-ready-to-secure-it/

 

:Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” 22 June 2026 (Fed. Reg. Doc. 2026-12909): https://public-inspection.federalregister.gov/2026-12909.pdf

 

:NSA, CNSA 2.0 FAQ v2.1 (Dec 2024): new National Security Systems compliant from 1 January 2027; exclusively CNSA 2.0 by 2033. https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF

 

:CISA, NSA & NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography” (2023): https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography

 

:Kjell Grandhagen — Chief of the Norwegian Intelligence Service (2009–2016); Chairman of NATO’s Military Intelligence Committee; joined the Naoris advisory board June 2018. https://businesscloud.co.uk/news/ex-nato-intelligence-lead-joins-cybersecurity-firm/

 

:NIST, FIPS 204 (Module-Lattice-Based Digital Signature Standard / ML-DSA), Aug 2024: https://csrc.nist.gov/pubs/fips/204/final

 

:NSA, CNSA 2.0 FAQ: ML-DSA-87 is the parameter set specified for National Security Systems. https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF

 

:U.S. migration timeline: NSM-10 / NIST IR 8547 (https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf); U.K. NCSC PQC migration timelines (https://www.ncsc.gov.uk/guidance/pqc-migration-timelines).

 

:Naoris Protocol published network figures: over 100 million post-quantum cryptographic validations; over 1 million connected endpoint nodes; over 3 million registered digital identities; over 600 million integrity enforcement events; public test launched 31 Jan 2025; live network 1 Apr 2026. https://www.naorisprotocol.com/blog/naoris-protocol-testnet-complete-whats-next ; coverage https://thequantuminsider.com/2026/04/01/naoris-protocol-launches-mainnet-introducing-post-quantum-layer-1-blockchain/ . Test-program figures; not paying customers or protected devices.

 

:Nathaniel Popper, The New York Times, “Knight Capital Says Trading Glitch Cost It $440 Million,” 2 Aug 2012.

 

:https://www.grandviewresearch.com/press-release/global-bfsi-security-market

 

:Preliminary Regulation A offering circular (Form 1-A). Final terms — including the minimum raise and the Nasdaq Capital Market listing condition — are controlled by the qualified offering circular: https://www.sec.gov/Archives/edgar/data/2145466/000121390026099378/ea0302771-1aa1_naoris.htm

 

:https://www.digicert.com/news/quantum-readiness-gap-a-digicert-study-on-quantum-safe-encryption

 

20

 

 

Appendix A — From the Artifact Deck: items to port into the Big Idea, and three deck corrections

 

Use in the Big Idea (text): the Carvalho line “The internet was built to move information. It was never built to prove it.” (cover); “zero systems on Earth can prove it today” (slide 02); Zero Trust asks who are you? — the trust layer asks should this proceed, now? (slide 03); “Every prior inflection got a new layer. This one is ours.” and “adoption, not replacement — IAM · EDR · SIEM · Zero Trust become inputs” (slide 04); the Colonial Pipeline case as a fourth documented event (slide 05); “growth grows the sensor surface, not the attack surface — every neighbour is a witness” (slide 08); the mesh as a live PQ-readiness sensor (slide 12); Grandhagen’s “We need to play a different game.” (slide 15); the closing couplet (slide 20).

 

Use in the Big Idea (visuals): slide 02 (the zero), 04 (missing layer), 05 (four events), 06 (the inversion curve — drop the 2ⁿ/3ⁿ labels), 07 (centralised vs distributed), 09 (M2M trace), 12 (two clocks), 13/14 (mandates — after adding EO 14412), 17 (live tiles), 18 (proof tiles).

 

Deck corrections before reuse: (1) threats mitigated reads 603M+ on the cover and slide 17; the published figure is 586,170,360 — align, or update the source page first; (2) slides 13–14 pre-date the 22 June 2026 executive orders — add EO 14412 (keys 2030, signatures 2031, contractors 2030) and retire the “NSM-10 + EO 14144 — 2035” framing; (3) the 8/8 vs 0–2/8 self-scorecard on slide 10 and “only Naoris supplies it at scale” on slide 19 are self-assessments — keep the six properties, soften the scoring.

 

:Naoris Quantum Protocol, Distributed Quantum-Trusted Infrastructure — Artifact Deck 2026-071 (20 slides), company materials.

 

:Naoris Protocol published network figures: over 100 million post-quantum cryptographic validations; over 1 million connected endpoint nodes; over 3 million registered digital identities; over 600 million integrity enforcement events; public test 31 Jan 2025; live network 1 Apr 2026. https://www.naorisprotocol.com/blog/naoris-protocol-testnet-complete-whats-next ; https://www.naorisprotocol.com/

 

:Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” 22 June 2026, Sec. 4(b)(ii)–(iii), Sec. 6(c). https://public-inspection.federalregister.gov/2026-12909.pdf

 

:OMB Memorandum M-26-15, 24 June 2026. https://www.whitehouse.gov/wp-content/uploads/2026/06/M-26-15-Execution-of-the-Migration-to-Post-Quantum-Cryptography.pdf

 

:DigiCert / Propeller Insights survey, 8 May 2025 (n = 1,042). https://www.globenewswire.com/news-release/2025/05/08/3077339/0/en/Quantum-Readiness-Gap-DigiCert-Study-Finds-Just-5-of-Enterprises-Have-Quantum-Safe-Encryption-in-Place.html

 

:Form 1-A, Summary — “Our Company” (IP ownership). https://www.sec.gov/Archives/edgar/data/0002145466/000121390026085345/ea0300508-1a_naoris.htm

 

:Ramos-Cruz, Andreu-Perez & Martínez, Neurocomputing Vol. 581 (2024), open access — 337 articles identified; Naoris described as “a first effort.” https://www.sciencedirect.com/science/article/pii/S092523122400198X

 

:Form 1-A, Summary — “Our Company”, “Key Benefits” (Time-Proof Security Architecture; deployment models; digital sovereignty), “Our Market Opportunity” (eight converging markets), “Our Products and Services”; Risk Factors (target customers). https://www.sec.gov/Archives/edgar/data/0002145466/000121390026085345/ea0300508-1a_naoris.htm

 

:Form 1-A, Risk Factors — Market and Competition (category statements for PetalVault, PQVPN, Community Intelligence Layer).

 

:BIS Innovation Hub, Project Leap Phase 2 (Dec 2025): https://www.bis.org/publ/othp107.pdf ; Europol Quantum Safe Financial Forum (Feb 2025): https://www.europol.europa.eu/publications-events/publications/quantum-safe-financial-forum-call-to-action ; G7 Cyber Expert Group roadmap (Jan 2026): https://home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf

 

:European Commission, Article 50 AI Act FAQ; Regulation (EU) 2024/1689. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act

 

:Gartner 2Q26 forecast (25 June 2026, G00855892): $248.9B (2026) → $372.6B (2030). https://www.gartner.com/en/documents/6998666

 

:MarketsandMarkets, 1 Oct 2025. https://www.marketsandmarkets.com/PressReleases/post-quantum-cryptography.asp

 

:Precedence Research: https://www.precedenceresearch.com/digital-trust-market ; Grand View Research: https://www.grandviewresearch.com/industry-analysis/digital-trust-market-report

 

:Roots Analysis. https://www.rootsanalysis.com/zero-trust-security-market

 

:NSA CNSA 2.0 FAQ v2.1 (Dec 2024). https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF

 

:UK NCSC PQC migration timelines (Mar 2025). https://www.ncsc.gov.uk/guidance/pqc-migration-timelines

 

:NIS2 quantum-resistant roadmap requirement, as summarised in BIS Project Leap Phase 2. https://www.bis.org/publ/othp107.pdf

 

:Form 1-A, Risk Factors — Market and Competition: primary competitive reference set and adjacent vendors. https://www.sec.gov/Archives/edgar/data/0002145466/000121390026085345/ea0300508-1a_naoris.htm

 

21

 

 

Summary of Risk Factors

 

The following risk factors, among others described more fully in the Offering Circular, should be considered carefully before investing:

 

Risks Related to the Company’s Business and Operations

 

The Company is an early-stage company with a limited operating history, which makes it difficult to evaluate its prospects and increases the risk of your investment.

 

The Company may not achieve profitability, which could cause the value of your investment to decline.

 

The Company’s success depends on market acceptance of post-quantum security solutions, which is an emerging market that may develop more slowly than the Company anticipates.

 

The Company faces long and unpredictable sales cycles, particularly with government and enterprise customers, which may cause its operating results to fluctuate significantly.

 

The Company depends on the continued service of key personnel, including its founder and senior technical leadership, and the loss of any key personnel could adversely affect its business.

 

The Company depends on third-party technology, cloud providers, and infrastructure partners, and any disruption in these relationships or services could adversely affect its platform and business.

 

The Company’s product expansion strategy includes products that the Company currently considers sufficiently developed for customer or partner deployment discussions, including PetalVault, PQVPN by Naoris, and the Naoris Community Intelligence Layer; however, these products may not achieve market adoption, may require additional capital, personnel, customer-specific integrations, certifications, security reviews, independent audits, or regulatory approvals, and may divert resources from the Company’s core platform.

 

The Company holds a 49% minority interest in a Korean joint venture (the “Naoris Korea JV” or the “JV”) that it does not control, and the JV’s failure to commercialize the Company’s products, disputes with its JV partner, or adverse developments in the Korean market could result in impairment of its investment and harm its business and financial results.

 

Risks Related to the Company’s Technology and Products

 

Post-quantum cryptographic standards are still evolving, and changes to these standards could require the Company to make significant modifications to its platform.

 

The Company’s products are complex, and defects, errors, or vulnerabilities could harm its reputation and adversely affect its business.

 

22

 

 

The Company’s Distributed Proof of Security consensus mechanism and Trust Mesh architecture may face scalability, reliability, and interoperability challenges.

 

The Company’s platform may be the target of cyberattacks, and any security breach could severely damage its reputation and business.

 

PetalVault, PQVPN by Naoris, and the Naoris Community Intelligence Layer are complex product initiatives built on Naoris infrastructure, and failures in security, scalability, usability, data integrity, AI output quality, or integration may adversely affect the Company’s business.

 

PetalVault depends on third-party blockchain infrastructure, cryptographic standards, Bitcoin transaction policies, and Bitcoin-related legal and market developments that the Company does not control.

 

PQVPN by Naoris involves secure routing, node attestation, and data-in-transit services, and may expose the Company to performance, privacy, availability, lawful access, and cross-jurisdictional routing risks.

 

The Naoris Community Intelligence Layer involves permissioned AI identities, community interaction data, digital identity, creator and brand rights, consent-based analytics, cross-platform communications, and monetization workflows, and may create risks involving privacy, publicity rights, intellectual property, consumer protection, AI governance, data protection, transparency, and platform governance.

 

Risks Related to the Company’s Market and Competition

 

The market for cybersecurity solutions is intensely competitive, and the Company competes with well-capitalized incumbents that have significantly greater resources than it does.

 

Larger competitors and technology companies may develop competing post-quantum security solutions that could reduce demand for the Company’s platform.

 

The post-quantum cryptography market may develop more slowly than anticipated, and the timing of the Company’s market opportunity is uncertain.

 

The Company may face customer concentration risks, with a limited number of customers accounting for a significant portion of its revenue.

 

Risks Related to Government Regulation and Compliance

 

The Company operates in a complex and evolving regulatory landscape, and compliance with multiple regulatory frameworks across jurisdictions is costly and challenging.

 

Changes in post-quantum cryptography mandates across jurisdictions could adversely affect the Company’s business.

 

The Company’s products may be subject to export control and sanctions regulations that could restrict its ability to sell internationally.

 

The Company’s platform’s use of blockchain and digital asset-related technology may subject it to evolving and uncertain regulatory requirements.

 

The Company’s application-layer products may be subject to evolving regulation relating to digital assets, AI, privacy, biometrics and voice data, consumer protection, communications services, encryption, export controls, sanctions, and data localization.

 

23

 

 

Risks Related to Intellectual Property

 

The Company’s ability to protect its proprietary technology, including its Distributed Proof of Security consensus mechanism and Trust Mesh architecture, is critical to its competitive position.

 

The Company’s reliance on NIST-standardized cryptographic algorithms that are publicly available may limit its ability to differentiate its platform from competitors.

 

The Company may be subject to intellectual property infringement claims by third parties, which could be costly and disruptive to its business.

 

The Company’s ability to obtain, maintain, and enforce rights in product names, software modules, AI models and prompts, data workflows, brands, and digital persona licenses may be limited.

 

Risks Related to Financial Condition and Capital Requirements

 

The Company will need to raise additional capital to fund its operations and growth, and such capital may not be available on favorable terms or at all.

 

The Company is dependent on the proceeds from this offering, and a shortfall in proceeds could adversely affect its ability to execute its business plan.

 

Risks Related to This Offering and the Company’s Securities

 

This is a Regulation A offering, and the Company will have limited reporting obligations compared to companies that conduct registered offerings under the Securities Act.

 

The Company’s founder and Chief Executive Officer will control approximately 91% of the total voting power of its capital stock following this Offering, and will therefore be able to control all matters submitted to stockholders for approval.
   
There is no public market for the Company’s securities, and investors may not be able to sell their securities when they want or at a price that is acceptable to them.

 

Investors will experience immediate and substantial dilution as a result of this offering.

 

The Company may conduct future capital raises that could result in additional dilution to investors in this offering.

 

The Company will have broad discretion over the use of proceeds from this offering, and investors may not agree with how the Company spends the proceeds.

 

Listing the Company’s securities on the Nasdaq Capital Market will increase its regulatory burden.

 

The Nasdaq Capital Market may delist the Company’s securities, which could limit investors’ ability to engage in transactions in the Company’s shares and subject it to additional trading restrictions.

 

24

 

 

The Company will incur increased costs as a result of operating as a public company and will be required to devote substantial time to new compliance initiatives.

 

The Company may issue additional securities or other equity securities without shareholder approval, which would dilute the ownership interests of existing shareholders in the Company and may depress the market price of its shares.

 

The Company’s ability to meet expectations and projections in any research or reports published by securities or industry analysts, or a lack of coverage by securities or industry analysts, could result in a depressed market price and limited liquidity for its securities.

 

The Company may be required to take write-downs or write-offs, restructuring and impairment or other charges that could have a significant negative effect on its financial condition, results of operations and share price, which could cause investors to lose some or all of their investment.

 

The Company does not intend to pay dividends for the foreseeable future.

 

This Offering is being conducted on a “best efforts” basis and the Company may not be able to execute its growth strategy if the maximum offering amount is not sold.

 

This is a fixed price offering and the fixed offering price may not accurately represent the current value of the Company or its assets at any particular time. Therefore, the purchase price paid for the Company’s shares may not be supported by the value of its assets at the time of purchase.

 

As the Company’s initial public offering price is substantially higher than its net tangible book value per share, investors will experience immediate and substantial dilution.

 

The Company recently effected a reverse stock split of both classes of its common stock, which may not achieve its intended effect.

 

Using a credit card to purchase shares may impact the return on an investor’s investment as well as subject the investor to other risks inherent in this form of payment.

 

Forward-looking statements in this Offering Circular may not accurately predict the Company’s future performance, and actual results may differ materially from the Company’s projections.

 

25