ADD EXHB 6 ea030589201ex99-4.htm BIG IDEA - NAORIS QUANTUM PROTOCOL

Exhibit 99.4

 

“Sufficiently powerful quantum computers could expose all our personal information,

financial transactions, and business and government secrets.”
National Institute of Standards and Technology

 

Quantum “D-Day” Is Coming.1

 

And It Could Not Only Break the Trust the Internet Is Built On...
But Re-Write Every Transaction That’s Already Been Recorded.

 

Google warns that quantum computers could bypass today’s digital locks...2

 

The White House has warned that large-scale quantum computers could threaten widely used cryptographic systems...3

 

And NATO — the world’s most powerful military alliance — is already preparing for the quantum era, warning of far-reaching implications for our economies, security and defense.4

 

The threat is no longer theoretical. Experts believe it’s inevitable.

 

Q-Day doesn’t just break tomorrow’s encryption...

 

It makes everything already recorded untrustworthy — because every log, transaction and audit trail signed with today’s cryptography can be forged after the fact.

  

 

1Ars Technica, “Google bumps up Q-Day estimate to 2029, far sooner than previously thought,” March 2026.https://arstechnica.com/security/2026/03/google-bumps-up-q-day-estimate-to-2029-far-sooner-than-previously-thought/

 

2Google, “The quantum era is coming. Are we ready to secure it?“https://blog.google/innovation-and-ai/technology/safety-security/the-quantum-era-is-coming-are-we-ready-to-secure-it/

 

3NSA, “President Biden Signs Memo to Combat Quantum Computing Threat.“https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3020175/president-biden-signs-memo-to-combat-quantum-computing-threat

 

4NATO, “NATO releases first-ever quantum strategy,” 17 January 2024.https://www.nato.int/en/news-and-events/articles/news/2024/01/17/nato-releases-first-ever-quantum-strategy

 

 

And for curious investors looking to explore the next wave of Deep Tech, read on to learn how Naoris Quantum Protocol

 

Spent the last 8 years building post-quantum digital trust infrastructure — a distributed “Trust Mesh” designed to continuously prove that every device and piece of data inside a network is legitimate.

 

Conceived the dCSMA in 2018 following discussions with the late Lt. Gen. Kjell Grandhagen, former Chief of the Norwegian Intelligence Service and Chairman of the NATO Military Intelligence Committee, to help advance its post-quantum technology.

 

Has multiple provisional patents in process.

 

And its post-quantum testnet ran from January 31 to November 12, 2025. It recorded over 100 million post-quantum cryptographic validations across over 1 million connected endpoint nodes, with over 3 million registered digital identities and over 600 million integrity enforcement events.5

 

Plus, you’ll see how this company is built for the things governments, central banks and the biggest companies on Earth are now being ordered to buy — by law, with dates attached: post-quantum security, cyber resilience, digital sovereignty, and provable compliance — for their machines and for their AI.6

 

Introducing: Naoris Quantum Protocol

 

When sufficiently powerful quantum computers arrive, the encryption protecting banks, governments, critical infrastructure and the broader digital economy could face a threat unlike anything the internet has encountered before.7

 

“Naoris’ mission is to make trust between every device, system, server, service and AI agent continuously provable. That means 24/7 validation that is cryptographically signed and post-quantum by default. This way our digital economy runs on PROOF instead of blind trust.”

 

 

5Offering Circular, Business — public testnet operated 31 January to 12 November 2025; over 100 million post-quantum validations, over 1 million connected endpoint nodes, over 3 million registered digital identities and over 600 million integrity enforcement events.

 

6White House, “Securing the Nation Against Advanced Cryptographic Attacks,” June 2026. https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/ ; European Commission, “Regulatory framework on AI.” https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

 

7NIST, “Quantum Computers May Put Internet Traffic at Risk. NIST Is Safeguarding Computers With New Codes.“https://www.nist.gov/blogs/taking-measure/quantum-computers-may-put-internet-traffic-risk-nist-safeguarding-computers-new

 

2

 

— David Carvalho, Founder and CEO

 

That’s why Naoris believes the answer is not simply another firewall or another layer of traditional cybersecurity…

 

It’s to ensure trust between every device, system, server and service is continuously provable — so that no single machine — and not even Naoris itself — gets to be the ultimate source of truth.

 

Naoris does this through a post-quantum distributed “Trust Mesh”, so no machine has to be trusted on its own word.

 

This means the architecture distributes validation across the network.

 

That’s important because…

 

The Internet was Never Built to Know Who You Could Trust

 

We’ve built the entire internet on one quiet assumption — that the servers and devices on the other end are telling the truth.

 

When you order something from Amazon…

 

Or post a family picture on Facebook…

 

You assume these companies are watching out for you… protecting your private logins, data, etc.

 

It’s a ‘handshake in the dark.’

 

You have no way of verifying if those devices or servers are compromised or not.

 

You’re vulnerable every time you log in or swipe your card at the store.

 

But it’s not a surprise. Because it’s how the internet was built… for now.

 

Each decade or two, there’s an innovation to the internet’s infrastructure… a new layer solving a problem the last generation never saw coming.

 

Go back to the earliest days of computer networking, and the first challenge is child’s play today…

 

Task #1 — get 2 computers to talk to each other.

 

In the 1960s and 70s, even getting two networks to exchange information was difficult and expensive.

 

That’s when a common set of rules called” TCP/IP” solved it.

 

Suddenly computers no longer only communicated with you. They could now connect – and communicate – with others.

 

3

 

 

TCP/IP (developed 1970s) established common rules letting interconnected networks exchange data. Source: standard computing history.

 

At the time, websites were identified by a string of numbers.

 

If you wanted to find specific information, you identified a website by numbers alone.

 

Imagine needing a phonebook to use the internet where you’d have to type in 10 digits to reach your favorite site.

 

Nobody wants to memorize a string of numbers to reach their bank.

 

So as more computers came online, a more convenient system for accessing them was needed.

 

That’s when the Domain Name System, DNS, gave the internet an address book: type a name, it finds the number attached to that name.

 

(Keep this in mind: Naoris’ Executive Chairman, David Holtzman, later ran the master root server of that very system as CTO of Network Solutions. More on him below.)

 

But then another problem came up…

 

Now that machines could find each other…

 

People began sending things worth stealing: passwords, debit/credit card numbers, medical records, bank details.

 

Putting that sensitive information into a website would be like reading out your credit card number every time you check out at the store.

 

So how do you stop someone stealing it in transit?

 

Enter Encryption. First, there was SSL (now it’s TLS). This encryption keeps your data safe when you put your card details in on Amazon.

 

4

 

There’s a little padlock in your browser right now… go take a look. That’s TLS encryption. That one breakthrough made online commerce, buying stocks on your computer, etc. possible.

 

 

This TLS lock protects your data on a site.

 

Then, as the networks filled with people…

 

You needed “gates” to ensure only certain people in a business or group could access information.

 

Who won the SSL/TLS race?

 

 

SSL/TLS (mid-1990s) encrypts data in transit — the browser ‘padlock.’ Source: standard computing history; Ojha et al., Sensors & Transducers 268(1), Apr 2025, §1.3.

 

That led to authentication — codes to your phone, long-character passwords, identity systems.

 

And now…

 

We have “Zero Trust”.

 

Formalized in 2020… “Zero Trust” simply states: do not trust someone just because they are already on your network… make them prove themselves.

 

 

Every one of those advances was revolutionary at the time.

 

And together, they built the internet we use and enjoy today.

 

5

 

Who won the Zero Trust race?

 

Companies dominating the cybersecurity space right now

 

 

All these companies ended up in the 11-figure club.

 

But underneath all of them…

 

One question was never answered and it’s grown more dangerous every year (especially now that we use devices everywhere we go, and now that AI is starting to act on our behalf):

 

What if the machine itself is wrong or compromised?

 

The Internet was Built in Layers… Naoris Believes it’s Building the NEXT Layer

 

70s–80s — TCP/IP: can these devices talk to each other?

 

80s–90s — DNS: where can I find my friend to talk to?

 

90s — SSL/TLS (the padlock): is it okay to share some personal details with my friend?

 

Early 2000s–2020 — Identity & Zero Trust: who is allowed into the area where I talk to my friend?

 

???? — Can I prove the device, system, server or service I’m talking to is still what it claims to be — right now?

 

Every question has its own layer. The last one never did. Naoris calls its answer the post-quantum trust layer.

 

Think about the distinction.

 

6

 

A machine can have:

 

The right address

 

A valid certificate

 

Encrypted traffic

 

A user with the right password, who passes multi-factor, and holds every permission

 

And the machine itself can still be hacked or compromised.

 

That is the gap the internet never closed.

 

We built systems for connection, location, privacy, and identity. But continuously proving the integrity of every device has proven to be a tall order.

 

So for decades, we’ve lived with it.

 

Said another way:

 

“You have an IT worker at your job tinkering with the network, fixing the ‘bugs’ as they come up manually. But…

 

 

Who’s monitoring the I.T. guy each day?”

 

It’s a band-aid because…

 

That world is disappearing.

 

7

 

The Countdown to Quantum Computing

 

Where all current encryption potentially becomes obsolete

 

…Google engineers just moved the timeline up…

 

Two things happened in the last 18 months that changed the math:

 

1.Google’s “Willow” chip showed, in the journal Nature, that quantum error correction finally works the way theory said it should.8

 

2.And a Google researcher cut the estimate of how big a quantum computer needs to be to break today’s internet encryption from 20 million qubits to under one million — a twenty-fold drop in one paper.9

 

[VISUAL — simple “the goalposts moved” graphic: 20,000,000 qubits (2019 estimate) → under 1,000,000 (2025 estimate). Source: https://arxiv.org/abs/2505.15917]

 

 

There’s a reason governments are suddenly thinking hard about cryptography.

 

It’s called quantum computing.

 

For simplicity’s sake, you only need to know one thing…

 

Today’s computers process information one way.

 

Quantum computers use fundamentally different physics that could eventually let powerful-enough machines solve certain math problems that would take today’s computers an impractical amount of time.

 

 

8Google Quantum AI, “Quantum error correction below the surface code threshold,” Nature 638, 920–926 (Feb 2025). https://www.nature.com/articles/s41586-024-08449-y

 

9Craig Gidney (Google Quantum AI), “How to factor 2048 bit RSA integers with less than a million noisy qubits,” arXiv:2505.15917, May 2025. https://arxiv.org/abs/2505.15917

 

8

 

 

And some of those math problems sit directly underneath the encryption the modern world runs on.

 

Yes, your bank, government communications, your company’s corporate systems, digital signatures, secure websites, sensitive data.

 

A sufficiently capable quantum computer could threaten the widely used public-key cryptography (RSA and elliptic-curve).

 

In layman’s terms… these public keys help secure everything from digital signatures and communications to banking and government systems.

 

This quantum computer doesn’t exist at the required scale today, and nobody knows exactly when it will.

 

For decades, the world was smaller.

 

Computers weren’t everywhere. Your fridge wasn’t online. Your car wasn’t talking to the cloud. No AI was operating software on your behalf.

 

And the mathematical locks guarding the most sensitive information on Earth were still far too hard for any ordinary computer to pick.

 

There’s a name for the day quantum computing arrives and can pick the locks.

 

The experts call it Q-Day — the point when a quantum computer becomes powerful enough to break the public-key cryptography much of the digital world relies on — the digital certificates and signatures that prove things are what they claim to be.

 

And here’s the part that matters for everything you just read.

 

You might assume Q-Day means the internet goes dark. But it’s worse. Much worse….

 

According to cybersecurity giant Palo Alto Networks, most systems would keep running. The bigger problem would be trust.

 

Digital signatures. Certificates. Identities. Software authenticity. Secure connections. The mechanisms computers use to prove that something (or someone) is who they claim to be.

 

If they were secured with cryptography that later becomes breakable, the proof behind them may no longer be enough to guarantee authenticity — because they could be forged after the fact.

 

9

 

Palo Alto puts it in three words: “the largest issue would be verification.”10

 

A machine with the right address, the valid certificate, the correct password… that still can’t prove it hasn’t been tampered with.

 

Quantum doesn’t create that trust gap. It threatens to blow it wide open.

 

Q-Day isn’t a blackout. It’s a crisis of digital trust.

 

And here’s what makes a “someday” threat frightening today: some of the secrets a quantum computer could expose years from now may already be sitting on somebody else’s server.

 

Security agencies have warned for years about a strategy with a chillingly simple name — harvest now, decrypt later.

 

You don’t crack the encryption today. You steal it anyway…

 

Copy it. Store it.

 

…Wait.

 

A military file, a trade secret, a set of financial records… all still valuable years from now. The attacker doesn’t need today’s key. He needs tomorrow’s computer.

 

The theft doesn’t wait for Q-Day. Only the unlocking does.

 

GOOGLE IS ALREADY SOUNDING ALARMS

 

2026 — Google sets an aggressive goal to complete its own post-quantum migration by 202911

 

Naoris began building in 2018 — before the standards were finalized, before Google put 2029 on its migration clock, before most investors knew what Q-Day meant.

 

Any nefarious hacker or country… only needs 1 device to potentially compromise all of the devices on a network.

 

It’s getting harder for tech and the government to keep up.

 

New devices – and threats – are coming online every single day

 

Every new device is an open window for hackers

 

Look around your own house…

 

 

10Palo Alto Networks, “What Is Q-Day?“https://www.paloaltonetworks.com/cyberpedia/what-is-q-day

 

11Google, “Cryptography migration timeline.“https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/

 

10

 

Twenty-five years ago you might have had one computer online… a dial-up connection that took (sometimes) minutes to load one webpage.

 

Today your TV is connected, you control your thermostat from your phone, your doorbell alerts you with a video of who’s knocking…

 

Your car connects… your watch connects… heck, you can hook up your refrigerator to the internet now.

 

 

Multiply that number of devices across the whole economy.

 

Factories run thousands of connected sensors…

 

Hospitals connect monitors and imaging machines…

 

Power grids run remote controllers…

 

Airports connect baggage and security systems…

 

Your bank connects to millions of servers and devices… how else would an ATM work?

 

And now, in the mid-2020s… companies are embedding autonomous AI agents into all of it — agents that buy, sell, approve and control things, increasingly without a human in the loop.

 

A Million Machines Became 50 billion

 

In 1992, roughly 1,000,000 computers were connected to the internet.12

 

 

12Computer History Museum, “Internet History 1990s.“https://www.computerhistory.org/internethistory/1990s/

 

11

 

In 2013, Cisco estimated that by 2020, roughly 50,000,000,000 would be connected to the internet.13

 

And Palo Alto Networks estimated about 98% of IoT traffic moving between them is unencrypted… meaning… it’s readable by anyone who looks.14

 

Every one of those devices is another “handshake in the dark.”

 

Cross your fingers and hope your doorbell is behaving in the correct way and not stealing information from you.

 

It’s no surprise cybersecurity grew into one of the largest industries on Earth:

 

You have firewalls at your office, antivirus software on your computer, aggressive spam filters on your email to detect phishing…

 

And yet the complexity itself became part of the problem.

 

A large company might run security products from dozens of vendors: CrowdStrike, Cloudflare, Palo Alto Networks…

 

Each runs its own software, has its own updates and quirks…

 

All of it built to hopefully stop outside intruders from getting in.

 

But what if the intruders are already inside?

 

The world’s third-largest “economy”

 

Cybersecurity Ventures projects cybercrime will cost the world about $10.5 trillion a year.15

 

For perspective, that would make cybercrime the world’s third largest economy — larger than the entire economic output of Japan or Germany.

 

And the industry was (hastily) built, in barely a decade, to act as guardians to keep intruders out.

 

 

13Cisco, “Cisco Connections Counter.“https://blogs.cisco.com/news/cisco-connections-counter

 

14Palo Alto Networks Unit 42, “2020 Unit 42 IoT Threat Report.“https://unit42.paloaltonetworks.com/iot-threat-report-2020/

 

15Cybersecurity Ventures, Official Cybercrime Report 2025. https://cybersecurityventures.com/official-cybercrime-report-2025/

 

12

 

 

Chaos happens when ONE central authority is in charge of protecting every device

 

In July 2024, the cybersecurity company CrowdStrike ($CRWD) pushed a faulty update to its Falcon software sitting on millions of Windows machines.16

 

No red flags until it was too late…

 

Microsoft estimated about 8.5 million devices were hit.17

 

Airlines grounded flights worldwide. Banks, hospitals, small businesses all saw major disruptions.

 

The software causing the damage was the software meant to protect the machines… it wasn’t a hacker slipping past a firewall.

 

Customers give a ‘handshake in the dark’ to dozens of companies each day that they are safe and protected.

 

 

16Cybersecurity Dive, CrowdStrike mismatch Falcon sensor outage. https://www.cybersecuritydive.com/news/crowdstrike-mismatch-falcon-sensor-outage/723569/

 

17TechTarget, “Microsoft: Faulty CrowdStrike update affected 8.5M devices.” https://www.techtarget.com/cybersecurity/news/366596532/Microsoft-Faulty-CrowdStrike-update-affected-85M-devices

 

13

 

 

These cyberattacks happen… and all systems seem normal until the data is stolen.

 

How $440 million disappeared in 45 minutes because no one knew their own devices went rogue18

 

Knight Capital didn’t have an AI problem…

 

There were no hackers or stolen passwords. Nobody broke through a secure firewall.

 

In 2012, Knight was one of the biggest trading firms in America. Daily, their computers bought and sold enormous volumes of stock.

 

On August 1… a normal day… Knight updated the software on 8 servers.

 

Well, 7 updated correctly…

 

One did not.

 

A technician had missed it.

 

Normally, this isn’t an issue in any business.

 

But hidden on that 8th server was some old code. And when the stock market opened at 9:30am, that one server began firing incorrect orders into the market.

 

Firing off orders is what their computers did. So this “was normal.”

 

However…

 

In about 45 minutes, Knight had run up roughly $440 million in losses.

 

 

18Henrico Dolfing, “Case Study 4: The $440 Million Software Error at Knight Capital.” https://www.henricodolfing.ch/en/case-study-4-the-440-million-software-error-at-knight-capital/ ; SEC Press Release 2013-222. https://www.sec.gov/newsroom/press-releases/2013-222

 

14

  

 

 

Per the New York Times

 

Nearly half a billion gone and one of the biggest firms nearly collapsed in 1 hour.

 

All because one machine out of eight was behaving differently from the others.

 

Nothing was wrong with its permissions. It was authorized to make those trades.

 

By the time actual humans caught on, the $440 million was long gone.

 

No firewall would’ve stopped this. The threat was on the inside.

 

What if a Company You Trust Sends You a Virus Today?19

 

In 2020, SolarWinds made network-management software used by thousands of organizations including major corporations and government agencies.

 

Their whole job was to help companies watch their own infrastructure.

 

SolarWinds was the central watchman for a company.

 

what happens when the central point fails…

 

Hackers managed to slip malicious code into SolarWinds’ own legitimate software updates.

 

Those updates went out through the normal, trusted channel.

 

Customers — their own clients who gave them money to protect them — had no reason to doubt the update… so many downloaded it.

 

In a clever “Trojan Horse” maneuver, hackers managed to get their code into as many as 18,000 organizations.

 

The cybersecurity breach of SolarWinds’ software is one of the most widespread and sophisticated hacking campaigns ever conducted against the federal government… — The U.S. Government Accountability Office, 2021

 

No passwords were stolen to get the update onto computers…

 

Customers simply downloaded the software… and their computers did not resist downloading it either.

 

 

19Zscaler, “What Is the SolarWinds Cyberattack?” https://www.zscaler.com/resources/security-terms-glossary/what-is-the-solarwinds-cyberattack

 

15

 

Who watches the watchmen?

 

Your antivirus software watches your computer…

 

Your monitoring tools watch your network…

 

Your identity system decides who gets in…

 

And soon, your AI agents will be watching all of it for you.

 

But what watches them?

 

The government? Who watches the government? Eventually something has to be trusted without anyone able to prove it.

 

That is the gap Naoris is filling.

 

The “P-Word”: The Next Layer of the Internet

 

And the one thing quantum computing can break in seconds (unless a company can stop it)

 

Proof.

 

For fifty years, there was no way to get it.

 

There was no way to keep checking, continuously, whether a machine was still telling the truth to every other device on the network.

 

So the whole world shook hands in the dark, and hoped.

 

The one thing all three failures had in common

 

Knight wasn’t ‘hacked’

 

CrowdStrike wasn’t even attacked, it was just faulty code…

 

SolarWinds was simply the Trojan Horse into as many as 18,000 organizations

 

In every one, permission was valid and trust was assumed.

 

Not one was a failure of who was allowed in… every one was a failure of whether the device (even the company) already trusted could still be trusted.

 

The answer isn’t “more security”… it’s PROOF.

 

That all changed…

 

…quietly…

 

In 2018.

 

One man, who spent two decades watching these problems grow from the inside… including running security for an airport, national infrastructure and government systems… set out to solve it once and for all.

 

16

 

The Man Who Wanted to Take Trust Out of Cybersecurity’s Hands

 

Back in 2018, when cybersecurity meant stronger passwords, better firewalls, and keeping hackers at bay…

 

Naoris CEO David Carvalho was thinking about a much different problem. One that grew out of his 20-year cyber security career which included…

 

Security engineering and operations at AT&T.

 

Chief Information Security Officer of London City Airport — protecting critical national infrastructure.

 

And Group Chief Information Security Officer (CISO) of OCS Group UK, across critical-infrastructure and government environments.

 

And at each role, he kept hitting the same wall:

 

You can always build another security wall…

 

Require another (stronger) password…

 

Add more CAPTCHA…

 

But sooner or later, something inside the system has to be trusted.

 

Meaning — the buck stops with a central authority.

 

A device sends out a status report that says: “I’m okay” and the system (and the reader) decides whether to believe it.

 

Then came the conversation that changed everything...

 

In 2018, Carvalho sat down with the late Lt. Gen. Kjell Grandhagen — Chief of the Norwegian Intelligence Service from 2010 to 2016 and Chairman of NATO’s Military Intelligence Committee. A man who had spent his career on the receiving end of nation-state attacks (and who joined Naoris’ advisory board that same year).20

 

Grandhagen’s conclusion was blunt: the centralized model of trust — one authority vouching for everything from a single point — is fundamentally flawed. It gives the adversary exactly one target.

 

 

20Form 1-A, Summary — “Our Company”: conceived in 2018 following discussions with the late Lt. Gen. Kjell Grandhagen, former Chief of the Norwegian Intelligence Service and Chairman of the NATO Military Intelligence Committee (2015–2016). Independent record: https://www.infosecurity-magazine.com/profile/kjell-grandhagen/ ; https://en.wikipedia.org/wiki/Kjell_Grandhagen. Advisory-board appointment, June 2018: https://businesscloud.co.uk/news/ex-nato-intelligence-lead-joins-cybersecurity-firm/

 

17

 

So Carvalho asked the question almost nobody in the industry was asking: what if nothing got to vouch for itself?

 

Meaning — prove yourself 24/7 that you are who you say you are.

 

Blind trust… the “handshakes in the dark”… are gone.

 

Flip the lights on and see everyone.

 

Right when a device, server… any machine starts acting “differently” than it normally does… it’s flagged.

 

And it does it immediately. Compare that to waiting until an hour later and $440 million is gone.

 

That was the idea David began building in 2018, which later became Naoris Quantum Protocol.

 

And he did not build it alone. The dCSMA architecture emerged from discussions with the late Lt. Gen. Kjell Grandhagen, former Chief of the Norwegian Intelligence Service and Chairman of the NATO Military Intelligence Committee, who identified the centralized cybersecurity model as fundamentally flawed.The Brains Building the Future of Internet Trust

 

David Carvalho — Founder and CEO. Over 20 years as an ethical hacker and Global Chief Information Security Officer across regulated and critical sectors: CISO of London City Airport, Group CISO of the 100,000-person OCS Group, and government systems under the NATO umbrella. Certified CISSP.21

 

David Holtzman — Executive Chairman. As CTO of Network Solutions in the late 1990s he ran the Domain Name System and managed “the Dot” — the internet’s master root server. Former NSA / Naval Security Group codebreaker and former Chief Scientist, Internet Information Group at IBM..22

 

Sumit Chauhan — Chief Technology Officer. His expertise spans product engineering, technical consulting, solution architecture, and co-founding an IT company, with deep domain knowledge in blockchain, AI, machine learning, big data, and cloud technologies. 25+ years across distributed systems, AI, cloud and enterprise software.

 

Magnus Fyhr — Chief Financial Officer. 25+ years of capital markets experience. Former CFO of AlphaOcean and past CEO of Clarksons Capital Markets.

 

 

21Crunchbase profile; CryptoNews Podcast #482 biography (CISO London City Airport; Global CISO OCS Group; CISSP). https://www.crunchbase.com/person/david-joao-vieira-carvalho

 

22Published biography: https://www.theconcierge.media/bio ; advisory role from August 2022.

 

18

 

Youssef El Maddarsi — Co-Founder & Chief Business Officer. Named the most influential entrepreneur in Morocco in 2025. 10+ years of strategic development and partnership building.

 

This experience is what makes Naoris especially equipped for securing the coming quantum threat.

 

On one hand, a founder who built his career defending systems… and another who worked on the actual infrastructure the internet itself was built on.

 

Both think distributing trust and validation is key.

 

Ironically…

 

The entire internet is already distributed.

 

When one website goes down… the entire internet doesn’t collapse. It’s isolated.

 

Yet much of the internet’s security still depends on centralized sources and centralized points of trust.

 

David believes — “If the entire network is distributed… trust should be distributed as well.”

 

Rather than rely on one central authority to keep track of every new device, system, server and service coming online daily…

 

Naoris makes every one of them another soldier defending the group.

 

Naoris is not a cryptocurrency company. And whether you buy Bitcoin or not, the technology behind Bitcoin did get something right and it’s what Naoris believes at its core:

 

Thousands of computers that don’t know or trust each other can still agree on what is true — with no central computer making the call.23

 

With Bitcoin, there’s a ledger that keeps tabs on Bitcoin ownership.

 

No one can fake ownership or rewrite the ledger for Bitcoin or similar cryptocurrency without breaking the chain of ownership; Bitcoin was designed to resist centralized control.

 

 

23Distributed consensus — many independent computers agreeing on a shared state without a central authority. Naoris applies distributed-ledger technology to machine trust, not to a currency (audited financials, Note 1).

 

19

 

 

Before this type of distributed innovation, if you wanted to know whether Joe had $100 dollars in his account, you asked the bank. The bank kept the ledger and their word was final.

 

Bitcoin proved another model worked: many independent computers agreeing on the state of the ledger and there’s no central figure keeping tabs.

 

Everyone is keeping tabs on what is true and not.

 

That is a distributed consensus… and it’s the core of Naoris.

 

David and Naoris’ founders took ‘distributed consensus’ and applied it to the one thing nobody had applied it to: the integrity of the machines themselves — every device, system, server and service.

 

 

Much like when CrowdStrike took out 8.5 million devices… a centralized network gives you 1 point of failure. Distributed = far less chance for it all to fail.

 

So, instead of one authority deciding whether a machine is healthy… the machines prove it to each other.

 

They built their own consensus mechanism and called it Distributed Proof of Security. dPoSec.

 

What is dPoSec?

 

dPoSec is designed to let devices, systems, servers and services validate one another against known-good baselines. Nothing self-certifies.

 

20

 

Every validation is signed with NIST-standardized post-quantum cryptography, in real time — at the strongest setting the standard defines (ML-DSA-87, “Dilithium-5”), the same level the NSA requires for National Security Systems.24 Naoris calls the result the post-quantum Trust Mesh.

 

It is not an antivirus, a firewall, or a monitoring dashboard, and it does not replace them. It runs alongside whatever a customer already has. Naoris sits beneath the stack — below security tools, below cloud, above hardware — and gives the whole stack the one thing it could never produce on its own: proof.

 

No longer is there a central point of failure or trust…

 

Trust gets distributed across the entire network.

 

No one device is allowed to declare itself trustworthy just because it says so. And the verdict the devices reach together is post-quantum-signed… designed so that no single device can fake it.

 

Flipping all of cybersecurity on its head

 

Traditional security sees another machine and says: “one more thing to protect.”

 

Naoris wants the network to say: “good, here’s another witness.”

 

Naoris’ research calls it a “contrarian design pattern”: turn the number and diversity of devices into part of the defense itself.

 

And the network is designed to get more resilient as more machines join.

 

While centralized points of trust get more risky.

 

 

 

Naoris is designed so other devices keep watch on your device’s health, using anonymized node identity to preserve privacy.

 

The goal: a hacker can’t quietly compromise one machine and disappear. He has to contend with other nodes checking on any machine he touches, plus NIST-standardized post-quantum cryptographyThe amount of time, cost and effort that takes is intended to push attackers somewhere else.

 

 

24Form 1-A, Risk Factors: platform employs ML-DSA (FIPS 204), “referred to in some technical materials as Dilithium-5.” ML-DSA-87 is NIST security category 5 — the highest level in FIPS 204 and the parameter set NSA CNSA 2.0 specifies for National Security Systems. https://csrc.nist.gov/pubs/fips/204/final ; https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF

 

21

 

And even Naoris doesn’t get to be trusted

 

Here’s the real kicker…

 

If the entire point is to remove dangerous central trust, it would be absurd to build a system where everything ends up depending on… Naoris.

 

Then you’d just have a new watchman.

 

So the architecture is built so the customer runs its own nodes and keeps control of its own environment.

 

Naoris doesn’t sit in the middle approving every decision, and the Trust Mesh can run in private, on-premise, sovereign-cloud, hybrid, even fully air-gapped settings — with the same capabilities in every one.

 

Which means a bank, a defense contractor, a government, or an operator of critical infrastructure doesn’t have to ship its most sensitive data somewhere else and hope another company guards it.

 

The trust network runs inside infrastructure the customer already controls.

 

No more single watchman.

 

Instead Carvalho and Naoris built: a network of witnesses where evidence, not any one company’s word, decides who can be trusted.

 

That’s the architecture.

 

The Next Customer is a Machine: AI Trust

 

The internet was built for humans logging in.

 

The next decade belongs to AI agents acting on our behalf — trading, procuring, approving invoices, controlling equipment, talking to other AI agents...

 

But an AI agent has exactly the same problem as Knight Capital’s eighth server: the right credentials, the right permissions… and no way to prove it hasn’t drifted, been poisoned, or been hijacked.

 

Naoris’ post-quantum Trust Mesh is designed to validate device, identity and data for AI agents — at machine speed, in-line, before the action lands.

 

Not a log to read the next morning. A verdict in milliseconds.

 

Naoris describes this as post-quantum-attested AI identity, and uses the assigned “Naoris Decentralized Swarm AI” mark for the distributed intelligence behind it.

 

22

 

The rest of the world is arriving at the same conclusion:

 

The EU AI Act’s Article 50 transparency obligations for AI-generated content have applied since 2 August 2026 — with penalties up to €15 million or 3% of worldwide turnover.25

 

Gartner named digital provenance a Top-10 strategic technology trend for 2026 — and named AI security platforms and digital trust as defining themes for the coming decade.26

 

Naoris’ first announced AI partnership — with Electra AI, applying post-quantum device integrity to AI-driven battery intelligence across grids, data centers, robotics and e-mobility fleets — is exactly this use case: trusting the machines that AI is now running.27

 

Sovereign Infrastructure — and Sovereign AI

 

Governments no longer want to rent their trust from somebody else’s cloud.

 

Naoris is designed for deployment.

 

The nodes belong to the state or the enterprise. The keys stay home. The audit trail is cryptographic — and it belongs to the owner, not the vendor.

 

That’s what Naoris calls digital sovereignty at scale.

 

And it’s why the company’s target market reads like a list of who can’t afford to be wrong: governments, central banks, payment and settlement systems, systemically important financial institutions, defense, energy, transport and telecoms.

 

It’s also why the largest engagement type Naoris plans to sell is a national and sovereign program — a country, or nation state, running its own post-quantum trust layer on its own terms.

 

And these buyers are not waiting for a sales call. The people who run the world’s payment systems are already testing post-quantum:

 

In December 2025 the Bank for International Settlements, working with the Bank of Italy, the Bank of France, the Deutsche Bundesbank and Swift, replaced traditional digital signatures with post-quantum signatures on real liquidity transfers in the euro area’s main payment system (Target2).28

 

 

25European Commission FAQ on Article 50 of the AI Act (applies from 2 August 2026); Regulation (EU) 2024/1689. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act ; https://eur-lex.europa.eu/eli/reg/2024/1689/oj

 

26Gartner, “Top Strategic Technology Trends for 2026,” 20 October 2025. https://www.gartner.com/en/newsroom/press-releases/2025-10-20-gartner-identifies-the-top-strategic-technology-trends-for-2026

 

27Form 1-A, pg. 56. https://www.sec.gov/Archives/edgar/data/2145466/000121390026099378/ea0302771-1aa1_naoris.htm

 

28BIS Innovation Hub, “Project Leap: Quantum-proofing payment systems,” Phase 2, December 2025 (Bank of Italy, Bank of France, Deutsche Bundesbank, Nexi-Colt, Swift) — post-quantum signatures on liquidity transfers in Target2. https://www.bis.org/publ/othp107.pdf

 

23

 

Europol convened a Quantum Safe Financial Forum and issued a call to action to the entire financial sector in February 2025, followed by a migration playbook with FS-ISAC in January 2026.29

 

In January 2026 the G7’s Cyber Expert Group, chaired by the U.S. Treasury and the Bank of England, published a coordinated post-quantum roadmap for the financial sector.30

 

The central banks have started. Main Street’s banks will have to follow.

 

[VISUAL — logo strip or map: BIS · Banca d’Italia · Banque de France · Bundesbank · Swift · Europol · G7 / U.S. Treasury / Bank of England. Sources: https://www.bis.org/publ/othp107.pdf · https://www.europol.europa.eu/publications-events/publications/quantum-safe-financial-forum-call-to-action · https://home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf]

 

Compliance You Don’t Have to Prove — Because it Proves Itself

 

Every regulator is asking the same question in different words: can you prove your systems are what you say they are — continuously, not once a year?

 

DORA. NIS2. PCI DSS 4.0. CMMC 2.0. The Cyber Resilience Act. NSM-10, Executive Order 14144 and CNSA 2.0 in the United States.

 

Each demands evidence of integrity and operational resilience. And NSM-10, Executive Order 14144 and CNSA 2.0 carry a post-quantum deadline landing between 2025 and 2035. The remaining frameworks create mounting pressure toward post-quantum readiness through crypto-agility and resilience-testing requirements.

 

 

29Europol, “Quantum Safe Financial Forum — A call to action,” 7 February 2025; follow-up with FS-ISAC, January 2026. https://www.europol.europa.eu/publications-events/publications/quantum-safe-financial-forum-call-to-action ; https://www.europol.europa.eu/about-europol/european-cybercrime-centre-ec3/qsff

 

30G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector,” January 2026. https://home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf

 

24

 

Naoris is designed to turn that evidence into a network by-product. Continuous validation replaces point-in-time audits. Every validation is post-quantum-signed and time-stamped, producing a tamper-evident audit trail.

 

That is why Naoris positions itself not only in cybersecurity but in compliance automation, operational resilience and data integrity — three budgets that already exist inside every bank and every ministry, and that are all now being told to go post-quantum.

 

The analysts see the same thing. Gartner named digital provenance — proving the origin and integrity of software, data and AI-generated content — a Top 10 Strategic Technology Trend for 2026, and predicts that by 2029 organizations that failed to invest in it will face “sanction risks potentially running into the billions of dollars.”31 That is exactly what a post-quantum-signed audit trail is for.

 

How Big is the Prize? Much Bigger than “Cybersecurity”

 

Here’s where most people get Naoris wrong…

 

If you only count the “post-quantum cryptography” market, you see a small number: about $0.42 billion in 2025, growing fast to $2.84 billion by 2030.32

 

But that doesn’t give the whole picture — not even close…

 

Gartner projects worldwide end-user spending on information security would be $193 billion in 2024, $213 billion in 2025 and $240 billion in 2026.33

 

The new quantum rules force that quarter-trillion-dollar budget to be rebuilt on new foundations.

 

 

31Gartner, Top 10 Strategic Technology Trends for 2026 (20 Oct 2025) — #7 Preemptive Cybersecurity, #8 Digital Provenance, #9 AI Security Platforms; sanction-risk prediction in the press release. https://www.gartner.com/en/articles/top-technology-trends-2026 ; https://www.gartner.com/en/newsroom/press-releases/2025-10-20-gartner-identifies-the-top-strategic-technology-trends-for-2026

 

32MarketsandMarkets, 1 October 2025: PQC market $0.42B (2025) → $2.84B (2030), 46.2% CAGR. https://www.marketsandmarkets.com/PressReleases/post-quantum-cryptography.asp

 

33Offering Circular, Market Opportunity — Gartner projects information-security spending of $193 billion in 2024, $213 billion in 2025 and $240 billion in 2026.

 

25

 

SAnd Naoris doesn’t just sell into security. Eight things that used to be bought separately are becoming one thing:

 

Eight markets becoming one layer

 

1.Operational resilience

 

2.Data integrity

 

3.Digital trust

 

4.Compliance automation

 

5.Device attestation

 

6.Digital identity

 

7.Confidential computing

 

8.Post-quantum cryptography

 

Management believes these markets “are converging into a unified trust infrastructure layer.”

 

Naoris is built to be that layer.

 

It does not compete category by category. It sits underneath all eight.34

 

And to put numbers on a few of those:

 

Digital trust — $110 billion in 2025, projected at $325 billion by 2035 (Precedence Research); Grand View Research puts it at $118.7 billion in 2024, projected to rise to $360.5 billion by 2030.35

 

Zero trust security — Projected to grow from $35 billion in 2024 to $190 billion by 2035.36

 

Data protection and recovery — $6.7 billion in 2023, projected to grow to $18.8 billion by 2030.37

 

Cloud security posture management — $4.2 billion in 2022, projected to grow to $8.6 billion by 2027.38

 

 

34Form 1-A, Summary — “Our Market Opportunity.” https://www.sec.gov/Archives/edgar/data/0002145466/000121390026085345/ea0300508-1a_naoris.htm

 

35Precedence Research, digital trust market: https://www.precedenceresearch.com/digital-trust-market ; Grand View Research: https://www.grandviewresearch.com/industry-analysis/digital-trust-market-report

 

36Roots Analysis, zero trust security market $35.24B (2024) → $190.27B (2035). https://www.rootsanalysis.com/zero-trust-security-market

 

37Grand View Research, data protection and recovery solutions market. https://www.grandviewresearch.com/industry-analysis/data-protection-recovery-solutions-market

 

38MarketsandMarkets, cloud security posture management. https://www.marketsandmarkets.com/Market-Reports/cloud-security-posture-management-market-71228949.html

 

26

 

8 Years Ahead of What’s Happening Now

 

Naoris’ management has quietly spent the past 8 years getting ahead of what’s coming. Not just AI… but the future of computing.

 

And it has spent time and money building an intellectual-property ‘moat’ around its innovation:

 

Patents are in process.

 

Naoris has provisional patent applications in process covering core elements of its Distributed Proof of Security architecture and Trust Mesh. The Naoris Protocol, the Trust Mesh and related software, algorithms, designs and trade secrets are owned by the company.39

 

Its tech survived academic scrutiny.

 

Work connected to the technology has appeared in three papers plus a review. And an independent systematic review in Neurocomputing (Elsevier, 2024) — by researchers at the University of Jaén and the University of Essex who screened 337 papers in the field — describes the Naoris Protocol as “a first effort” in decentralized cybersecurity mesh.40 Their words, not Naoris’.

 

Its tech is built to outlast the standards.

 

Cryptographic standards will change again. Naoris’ Time-Proof Security Architecture is designed so the network can upgrade to stronger methods over time without disruptive overhauls or forks. The goal is thatwhat a customer buys today doesn’t become obsolete when the next standard lands.

 

 

39Form 1-A, Summary — “Our Company”: the Naoris Protocol, the Trust Mesh and all related software, protocols, algorithms, designs and trade secrets are owned by the Company. https://www.sec.gov/Archives/edgar/data/0002145466/000121390026085345/ea0300508-1a_naoris.htm

 

40Ramos-Cruz, Andreu-Perez & Martínez, “The cybersecurity mesh: A comprehensive survey…”, Neurocomputing Vol. 581, 2024 (open access) — 337 articles identified; Naoris described as “a first effort” in decentralized cybersecurity mesh. https://www.sciencedirect.com/science/article/pii/S092523122400198X

 

27

 

It has put the tech through the gauntlet.

 

Out of the lab… into the fire.

 

Naoris opened a public testnet on 31 January 2025, operating through 12 November 2025.41

 

No, these were users, not customers or businesses. It showed the architecture could operate across a very large number of devices around the world.

 

To compare — the largest distributed network most people have heard of, Bitcoin, runs on roughly 13,000–30,000 nodes at a time.

 

Naoris is Going After the Big Fish.

 

Securing a home computer is one thing. Securing a nation is another.

 

Its target customers are banks, central banks, defense, government, energy, telecommunications, transportation… the places where a digital failure lands far beyond one machine.

 

Naoris’ technology intends to allow those organizations to keep control of their own systems, keys and data rather than handing them to another centralized vendor.

 

It has built a product line on top.

 

The same trust infrastructure supports products for deployment discussions:

 

PQVPN by Naoris — a distributed post-quantum VPN and secure-routing layer for regulated data in transit.

 

PetalVault — a post-quantum evidence and audit layer for Bitcoin custodians, insurers and compliance teams.

 

Naoris Community Intelligence Layer — trust-validated, permissioned AI identities for brands, enterprises and communities.

 

Each is built on the same post-quantum Trust Mesh.

 

And in each of those three product categories, Naoris says it is not aware of any direct competing commercial product — the neighbors are custody and proof-of-reserves providers, SASE/ZTNA vendors, and avatar/content platforms, that do not currently provide an integrated post-quantum cryptographic identity attestation layer as a primary product capability.42

 

 

41Offering Circular, Business — public testnet operated 31 January to 12 November 2025; over 100 million post-quantum validations, over 1 million connected endpoint nodes, over 3 million registered digital identities and over 600 million integrity enforcement events.

 

42Form 1-A, Risk Factors — Market and Competition (PetalVault, PQVPN, Community Intelligence Layer category statements). https://www.sec.gov/Archives/edgar/data/0002145466/000121390026085345/ea0300508-1a_naoris.htm

 

28

 

The first announced relationships are public.

 

Naoris has a 49% minority JV interest with XCURE and an Electra AI partnership.

 

The Shift is Already Happening…

 

Governments aren’t waiting to find out when quantum computers will be a threat.

 

They’re already demanding companies change their locks now.

 

 

 

For years, cryptographers have been building new algorithms designed to resist both conventional and quantum attacks. This is called post-quantum cryptography.

 

In 2024, the National Institute of Standards and Technology (NIST) finalized its first principal post-quantum standards for widespread use.

 

Governments are not waiting…

 

They expect companies, banks, governments and corporations to prepare for post-quantum cryptography now.

 

29

 

 

Mandates to come fast and furious…

 

WASHINGTON DIDN’T WAIT FOR Q-DAY

 

2022 — the White House begins directing federal systems toward post-quantum migration (NSM-10; OMB M-23-02)

 

2023 — NSA, CISA and NIST jointly warn that attackers could be stealing encrypted data today to unlock later

 

2024 — NIST finalizes its first major post-quantum cryptography standards

 

2035 — full federal migration baseline under NSM-10, Executive Order 14144 and CNSA 2.0.

 

The digital-signature standard is ML-DSA / FIPS 204 — the standard Naoris signs every validation with.

 

The threat of quantum computers in the hands of hackers or even the wrong country has mass implications.

 

Attacks on our power grid…

 

Weapons turned against their own citizens…

 

An entire financial ecosystem at risk — your money at risk of being deleted in a few strokes.

 

None of this is to scare…

 

But to share how powerful quantum computing can be, especially at the disposal of bad actors.

 

30

 

The government is scrambling to make changes asap.

 

In a rare moment of agreement…

 

NATO allies have committed to a strategy that “will foster the development of a secure, resilient and competitive quantum ecosystem that is able to respond to the fast pace of technological competition in the quantum industry.”

 

 

Article from June 2025

 

The compliance calendar — four governments, one direction

 

2024 — first post-quantum encryption standards finalized (NIST).

 

1 January 2027 — new U.S. National Security Systems must be quantum-safe (NSA CNSA 2.0).43

 

2028 — U.K.: cryptographic discovery and migration plan complete (NCSC).44

 

2035 — full migration baseline for U.S. federal systems.

 

[VISUAL — horizontal timeline 2024→2035 showing 1 January 2027 and 2035.]

 

Organizations are being told to begin preparing now. Because the thieves aren’t waiting either.

 

And here’s the gap Naoris is selling into: a May 2025 survey of 1,042 senior security executives found that 69% know quantum computing is a risk to their encryption… and only 5% have implemented quantum-safe encryption.45

 

Nineteen out of twenty large companies haven’t started. The rules now say they have to.

 

[VISUAL — two-bar or donut graphic: 69% aware vs. 5% deployed. Source: https://www.globenewswire.com/news-release/2025/05/08/3077339/0/en/Quantum-Readiness-Gap-DigiCert-Study-Finds-Just-5-of-Enterprises-Have-Quantum-Safe-Encryption-in-Place.html]

 

 

43NSA CNSA 2.0 — new National Security System acquisitions must be quantum-safe by January 1, 2027, with full enforcement by 2035.

 

44UK NCSC, “Timelines for migration to post-quantum cryptography,” 20 March 2025. https://www.ncsc.gov.uk/guidance/pqc-migration-timelines

 

45DigiCert / Propeller Insights survey of 1,042 senior and C-level cybersecurity managers (US, UK, Australia), 8 May 2025: 69% recognize the risk; 5% have implemented quantum-safe encryption. https://www.globenewswire.com/news-release/2025/05/08/3077339/0/en/Quantum-Readiness-Gap-DigiCert-Study-Finds-Just-5-of-Enterprises-Have-Quantum-Safe-Encryption-in-Place.html

 

31

 

Naoris is already prepped for one of the biggest shifts in computing potentially coming in the next few years

 

When 1 quantum computer can break the encryption of many secure sites in mere seconds

 

Picture a thief who steals a locked safe from your house. He can’t open it today… but he doesn’t throw it away.

 

He stores it in his garage until he finds what he needs to break into it.

 

That’s the concern with encrypted data.

 

A hacker can capture it today, keep it, and wait for future computing that may eventually crack it open.

 

Think about data stolen today that still matters ten years from now.

 

Military intelligence.

 

Weapons designs.

 

Trade secrets.

 

Government communications.

 

Medical records.

 

Financial information.

 

For information that must remain secret for decades, the useful life of the secret may outlast the useful life of today’s encryption.

 

Which is why “quantum isn’t here yet” can’t be the reason for “we can deal with it later.” For some organizations, later may already be too late.

 

 

The race is on…

 

And Naoris is warning that the current suggested solutions won’t work on their own.

 

32

 

Naoris seeks to build the next layer of the internet… post-quantum distributed trust

 

It’s doing it in a way that’s much different from the ‘centralized solutions’ fighting over the billions to be spent on post-quantum protection.

 

 

Security dimension

  Traditional cybersecurity (firewalls, EDR, SIEM, Zero Trust)   Standard post-quantum vendors (PQC / QKD providers)   Naoris Quantum Protocol (post-quantum Trust Mesh)
1. Core trust model (continuous & provable trust)   ❌  Assumed point-in-time trust; machines self-report status   ❌  Point-in-time algorithm swaps; endpoints still self-vouch   ✅ Continuous, peer-witnessed cryptographic proof
2. Distributed architecture (no single point of failure)   ❌ Centralized servers, vendor clouds and CAs   ❌ Centralized key management or proprietary hardware   ✅ Distributed peer-to-peer validation mesh
3. Resilience at scale   ❌ More devices = more attack vectors   ❌ Expanding attack surface regardless of encryption strength   ✅ Designed so each added device is another validator
4. Resistant to “watchman” corruption (tamper-evident verification)   ❌ Compromised security tools or admins still report “healthy”   ❌ Cannot detect if an authorized endpoint is running bad code   ✅ Rotated peer consensus designed to isolate rogue or altered nodes
5. Quantum resistance   ❌ Vulnerable legacy RSA/ECC (“harvest now, decrypt later”)   ✅ Implements NIST post-quantum algorithms or QKD   ✅ NIST FIPS 204 (ML-DSA) signed by default
6. Implementation ease (no rip-and-replace)   ❌ Heavy overlapping agent stacks and complex updates   ❌ Extensive code overhauls or costly physical appliances   ✅ Sub-zero layer sits beneath existing stacks and legacy systems
7. AI & machine-speed trust (real-time in-line proof)   ❌ Post-incident logs; human review bottleneck   ❌ Static packet encryption without behavioral checks   ✅ Millisecond in-line validation
8. Sovereignty (on-prem / air-gapped / in-country)   ❌ Sensitive telemetry and keys routed to vendor clouds   ❌ Vendor-hosted key infrastructure and cloud dependencies   ✅ Designed so no data leaves the perimeter; runs fully air-gapped / on-prem
9. Compliance evidence (continuous audit trail)   ❌ Periodic audits; evidence assembled by hand   ❌ Proves the algorithm, not the machine   ✅ Post-quantum-signed, time-stamped audit trail as a by-product
10. Device footprint   ❌ Heavy CPU, battery and memory overhead   ❌ High compute demand for post-quantum calculations   ✅ Lightweight PQ Daemon Node

 

33

 

Standards will evolve and selling this idea to large enterprises moves slowly. Even the right technology doesn’t guarantee anyone adopts it.

 

For you… the investor… here is the case — Naoris has already done the groundwork to fight a problem that governments and corporations may now be forced to spend years solving.

 

And it has built a distributed designed to integrate with existing devices without replacing them and it will add them to the Trust Mesh.

 

That has the potential to make it an easier sale to companies and governments.

 

Relationships were announced…

 

Now, the next phase of the business is growing awareness and securing contracts.

 

Naoris has demonstrated it can build the technology…

 

Its current mission is to now spread the word to as many companies and governments as possible

 

Selling the tech is the point where many promising technology companies fail.

 

Because inventing something and then turning it into a global business are two entirely different jobs.

 

They’ve built the tech since 2018…

 

Now comes the second job. Commercialization.

 

Naoris is raising up to $24 million in this offering, and management says the capital is intended primarily to move the company from technology development and early commercial agreements into broader enterprise adoption.

 

That means building the teams needed to sell into some of the largest organizations on Earth:

 

Banks and central banks

 

Governments

 

Defense

 

Telecommunications

 

34

 

Energy

 

Critical infrastructure

 

And the AI platforms now running inside all of them

 

These aren’t customers who see an ad on Tuesday and swipe a card on Wednesday.

 

Enterprise cybersecurity can mean technical evaluations, procurement reviews, compliance requirements, pilot programs, security audits and long sales cycles.

 

So the next stage of Naoris isn’t “build more technology.”

 

It must build the sales and marketing army to get this technology in front of the organizations that need it the most… and are hardest to sell to.

 

“Changing the Lock”… or Building a Better Firewall isn’t the Answer

 

Most of the post-quantum scramble is about cryptography. Companies must build locks a quantum computer can’t break.

 

Naoris uses post-quantum cryptography itself.

 

But again…

 

Nobody broke Knight Capital’s encryption…

 

Nobody cracked the cryptography protecting SolarWinds’ customers…

 

No quantum computer touched CrowdStrike…

 

And the AI deepfake that moved $25 million out of Arup didn’t break a single lock.

 

A stronger lock is still guarding a system that has to decide what it should trust.

 

35

 

Naoris isn’t just putting a stronger lock on the same old door.

 

It’s building a smarter fortress around it.

 

A fortress where the guards don’t simply assume the other guards are still trustworthy.

 

They continually check each other.

 

Naoris treats the quantum transition as more than a cryptography swap.

 

Post-quantum cryptography strengthens the locks.

 

Naoris’ distributed architecture is built with post-quantum tech…

 

But also helps secure what happens inside the fortress, too.

 

Because the quantum threat may be coming for the locks…

 

But as we’ve already seen, the intruder doesn’t always come through the front door. They come through the window… the pipes… or the cracks in the wall.

 

With Naoris you don’t have to rebuild the entire fortress…

 

No Rip-and-Replace

 

Imagine walking into a global bank and saying: “We’ve invented a better security architecture… but you’ll need to throw away millions of dollars of equipment and software.”

 

That’s a tough sales pitch.

 

Large organizations have spent decades building their tech stacks.

 

In government, energy and defense, some systems can’t simply be unplugged Friday and replaced Monday. You need months… even years of budget meetings to replace systems.

 

Naoris was designed around that reality.

 

It is designed to run alongside existing infrastructure — modern and legacy — rather than force customers to rebuild around it.

 

Strengthen the infrastructure you already have, rather than replace it.

 

36

 

 

Plugging into existing systems makes this a potentially easier sale for a major corporation or government entity.

 

That doesn’t make adoption automatic, of course. Integration still takes work, buy-in and approval.

 

But from a sales perspective, there’s an enormous difference between “replace your infrastructure” and “strengthen the infrastructure you already have.”

 

Just a Few Contracts Could Mean Large Recurring Subscription Revenue

 

Naoris isn’t trying to sell a product once.

 

Management’s commercialization model is built around enterprise licensing and subscription-style recurring revenue.

 

Once a technology is embedded in a company’s security… and it works…

 

A billion-dollar company could extend the tech across more devices, more locations, more modules, and ongoing licensing and support over time.

 

That alone means 1 major client could potentially be worth a healthy amount of revenue.

 

Naoris’ model is built on licensing and subscription revenue.

 

Disclaimer: This is not a forecast, and it is not a promise. Naoris has no commercial revenue to date, and there is no guarantee it signs any of these contracts. It is simply the shape of the opportunity: in a business like this, a small number of the right customers could change the picture quickly — which is exactly why the risk and the reward sit so close together.

 

37

 

 

Billions in competition dollars up for grabs just in the digital infrastructure space

 

And the early signs have begun.

 

As mentioned earlier, Naoris has its Korea JV interest with XCURE and its Electra AI partnership.

 

It’s early evidence that the post-quantum Trust Mesh is something the market may explore.

 

Just 1 major contract could be worth $10M+ in a year…

 

And that would potentially make Naoris’ valuation appear small next to what the market pays for post-quantum

 

Take a look at what the market is paying in this corner of quantum and security:

 

Company

  Status & ticker   Valuation / market cap   Annual revenue   Architectural model
Naoris Quantum Protocol   Private (Reg A+; Nasdaq listing applied for)   Unstated (implied pre-money)   $0 (pre-commercial; 49% Korea JV interest and partnership)   Post-quantum distributed Trust Mesh: peer-to-peer device, identity and data validation running beneath the OS/cloud
SandboxAQ   Private (Series E, April 2025)   ~$5.75B post-money (~$950M raised)   Not disclosed; 5-year U.S. DoD post-quantum migration contract; FedRAMP Ready   Post-quantum migration platform (same category as Naoris’ reference set)46
Quantinuum   Public (NASDAQ: QNT), IPO 5 June 2026 at $60/share   ~$10B pre-money ($1.68B raised)   ~$30.9M (2025)   Hardware-first quantum computing + key/entropy products47
Arqit Quantum   Public (NASDAQ: ARQQ)   ~$305M   ~$530K (FY2025); $623K in H1 FY2026   Point-to-point symmetric key distribution48
QuintessenceLabs   Private   Undisclosed (~$32M -68.4M raised; 2025 round led by Australia’s National Reconstruction Fund)   ~$9M–$13M est.   Hardware & QKD appliances49
Cloudflare   Public (NYSE: NET)   ~$104B   ~$2.17B (FY2025)   Centralized cloud edge — adjacent category, not a competitor50

 

 

46SHandboxAQ press: ~$950M total funding; Series E April 2025 >$450M at ~$5.75B post-money; investors incl. Google, NVIDIA, BNP Paribas, T. Rowe Price; five-year U.S. DoD contract; AQtive Guard FedRAMP Ready Dec 2025. https://www.sandboxaq.com/press

 

47Quantinuum IPO pricing release (June 2026; $60/share; 28M shares; ~$1.68B gross) and Form 10-Q (2025 revenue ~$30.9M). https://www.quantinuum.com/press-releases/quantinuum-announces-pricing-of-upsized-initial-public-offering ; https://www.stocktitan.net/sec-filings/QNT/10-q-quantinuum-inc-quarterly-earnings-report-130317df60b7.html

 

48Arqit Quantum Form 6-K (H1 FY2026 revenue $623K; FY2025 $530K; cash $28.9M at 31 Mar 2026); market cap ~$305M. https://www.sec.gov/Archives/edgar/data/1859690/000110465926042173/tm2611612d1_ex99-1.htm ; https://stockanalysis.com/stocks/arqq/

 

49QuintessenceLabs funding history. https://www.securityweek.com/quantum-cybersecurity-provider-quintessencelabs-raises-18-million/

 

50Cloudflare statistics (market cap ~$104B; FY2025 revenue ~$2.17B; Q2 FY2026 revenue $696M, +35.9% YoY). https://stockanalysis.com/stocks/net/statistics/. Adjacency per Form 1-A Risk Factors.

 

38

 

Figures as of late August 2026; sources in the footnotes. The filing places Cloudflare, Palo Alto, Fortinet and Cisco in an adjacent category rather than a competing one — which is precisely why their multiples are an execution benchmark, not a ceiling.

 

[VISUAL — bar chart of valuations on a log scale: Naoris (unstated) · Arqit $305M · SandboxAQ $5.75B · Quantinuum $10B · Cloudflare $104B. Sources: https://www.sandboxaq.com/press · https://www.quantinuum.com/press-releases/quantinuum-announces-pricing-of-upsized-initial-public-offering · https://stockanalysis.com/stocks/arqq/ · https://stockanalysis.com/stocks/net/statistics/]

 

Naoris has demonstrated it can build the technology.

 

First relationships were announced…

 

Now it needs to prove it can win at scale.

 

Naoris Quantum Protocol is raising up to $24 million at an implied pre-offering valuation.

 

Shares are priced at $4/share, with a minimum investment of 200 shares ($800).

 

The offering will only close if at least $15 million is raised and the shares are approved for listing on Nasdaq; if not, investor funds are returned.

 

Investing in a small, early-stage technology company bears substantial risks.

 

Naoris has built the architecture and filed provisional patents.. What it has not yet done is turn that into meaningful commercial revenue.

 

The company has a Korea JV interest and an Electra AI partnership. But the audited period showed no revenue, and the selling phase is only just beginning.

 

39

 

Banks, governments and infrastructure operators move slowly. They run pilots, security audits and procurement reviews that can stretch across many months. If that conversion takes longer than expected, revenue could stay limited for some time.

 

The capital is intended primarily to move the company from building the technology into selling it.

 

Please see the Company Deep Dive for the full use of proceeds.

 

Management expects the offering to fund at least 10 months at the minimum raise and 15 months at the maximum.

 

If commercialization takes longer than planned, Naoris would likely need to raise additional capital in the coming years, which could dilute existing shares.

 

There is no guarantee of a return on investor shares, and no guarantee that Naoris reaches commercial success.

 

If you’re considering investing in Naoris at $4/share, make sure you do full due diligence —read the Market Opportunity,the complete Company Deep Dive and the Offering Circular including the full set of risk factors before you decide.

 

READ THE COMPANY DEEP DIVE

 

See how it works, meet the people building it, and read the numbers before you decide.

 

Important Disclosures & Investor Notice

 

DISCLOSURE: All information contained in this communication should not be considered investment advice nor an offer to buy or sell securities, but for educational and informational purposes only. Investing in private or early-stage offerings (such as Reg A, Reg S, Reg D, or Reg CF) involves a high degree of risk. Securities sold through these offerings are not (most of the time) publicly traded and therefore illiquid. Additionally, investors will receive restricted stock that is subject to holding period requirements. Companies seeking capital through these offerings tend to be in earlier stages of development and have not yet been fully tested in the public marketplace. Investing in private or early-stage offerings requires a tolerance for high risk, low liquidity, and a long-term commitment. Investors must be able to afford to lose their entire investment. Such investment products are not FDIC insured, may lose value, and have no bank guarantee.

 

Naoris Quantum Protocol Inc. (the “Company”) has filed an Offering Circular relating to the Company’s securities, initially filed with the Securities and Exchange Commission (the “SEC”) on August 5, 2026 and forming part of the offering statement on Form 1-A qualified by the SEC on [●], 2026 (the “Offering Circular”). An investment in the Company’s securities involves significant risks. Please see the summary of certain risk factors set forth at the end of this communication and the more detailed discussion under “Risk Factors” in the Offering Circular before making an investment decision.

 

40

 

Summary of Risk Factors

 

The following risk factors, among others described more fully in the Offering Circular, should be considered carefully before investing:

 

Risks Related to the Company’s Business and Operations

 

The Company is an early-stage company with a limited operating history, which makes it difficult to evaluate its prospects and increases the risk of your investment.

 

The Company may not achieve profitability, which could cause the value of your investment to decline.

 

The Company’s success depends on market acceptance of post-quantum security solutions, which is an emerging market that may develop more slowly than the Company anticipates.

 

The Company faces long and unpredictable sales cycles, particularly with government and enterprise customers, which may cause its operating results to fluctuate significantly.

 

The Company depends on the continued service of key personnel, including its founder and senior technical leadership, and the loss of any key personnel could adversely affect its business.

 

The Company depends on third-party technology, cloud providers, and infrastructure partners, and any disruption in these relationships or services could adversely affect its platform and business.

 

The Company’s product expansion strategy includes products that the Company currently considers sufficiently developed for customer or partner deployment discussions, including PetalVault, PQVPN by Naoris, and the Naoris Community Intelligence Layer; however, these products may not achieve market adoption, may require additional capital, personnel, customer-specific integrations, certifications, security reviews, independent audits, or regulatory approvals, and may divert resources from the Company’s core platform.

 

The Company holds a 49% minority interest in a Korean joint venture (the “Naoris Korea JV” or the “JV”) that it does not control, and the JV’s failure to commercialize the Company’s products, disputes with its JV partner, or adverse developments in the Korean market could result in impairment of its investment and harm its business and financial results.

 

Risks Related to the Company’s Technology and Products

 

Post-quantum cryptographic standards are still evolving, and changes to these standards could require the Company to make significant modifications to its platform.

 

The Company’s products are complex, and defects, errors, or vulnerabilities could harm its reputation and adversely affect its business.

 

41

 

The Company’s Distributed Proof of Security consensus mechanism and Trust Mesh architecture may face scalability, reliability, and interoperability challenges.

 

The Company’s platform may be the target of cyberattacks, and any security breach could severely damage its reputation and business.

 

PetalVault, PQVPN by Naoris, and the Naoris Community Intelligence Layer are complex product initiatives built on Naoris infrastructure, and failures in security, scalability, usability, data integrity, AI output quality, or integration may adversely affect the Company’s business.

 

PetalVault depends on third-party blockchain infrastructure, cryptographic standards, Bitcoin transaction policies, and Bitcoin-related legal and market developments that the Company does not control.

 

PQVPN by Naoris involves secure routing, node attestation, and data-in-transit services, and may expose the Company to performance, privacy, availability, lawful access, and cross-jurisdictional routing risks.

 

The Naoris Community Intelligence Layer involves permissioned AI identities, community interaction data, digital identity, creator and brand rights, consent-based analytics, cross-platform communications, and monetization workflows, and may create risks involving privacy, publicity rights, intellectual property, consumer protection, AI governance, data protection, transparency, and platform governance.

 

Risks Related to the Company’s Market and Competition

 

The market for cybersecurity solutions is intensely competitive, and the Company competes with well-capitalized incumbents that have significantly greater resources than it does.

 

Larger competitors and technology companies may develop competing post-quantum security solutions that could reduce demand for the Company’s platform.

 

The post-quantum cryptography market may develop more slowly than anticipated, and the timing of the Company’s market opportunity is uncertain.

 

The Company may face customer concentration risks, with a limited number of customers accounting for a significant portion of its revenue.

 

Risks Related to Government Regulation and Compliance

 

The Company operates in a complex and evolving regulatory landscape, and compliance with multiple regulatory frameworks across jurisdictions is costly and challenging.

 

Changes in post-quantum cryptography mandates across jurisdictions could adversely affect the Company’s business.

 

The Company’s products may be subject to export control and sanctions regulations that could restrict its ability to sell internationally.

 

The Company’s platform’s use of blockchain and digital asset-related technology may subject it to evolving and uncertain regulatory requirements.

 

The Company’s application-layer products may be subject to evolving regulation relating to digital assets, AI, privacy, biometrics and voice data, consumer protection, communications services, encryption, export controls, sanctions, and data localization.

 

42

 

Risks Related to Intellectual Property

 

The Company’s ability to protect its proprietary technology, including its Distributed Proof of Security consensus mechanism and Trust Mesh architecture, is critical to its competitive position.

 

The Company’s reliance on NIST-standardized cryptographic algorithms that are publicly available may limit its ability to differentiate its platform from competitors.

 

The Company may be subject to intellectual property infringement claims by third parties, which could be costly and disruptive to its business.

 

The Company’s ability to obtain, maintain, and enforce rights in product names, software modules, AI models and prompts, data workflows, brands, and digital persona licenses may be limited.

 

Risks Related to Financial Condition and Capital Requirements

 

The Company will need to raise additional capital to fund its operations and growth, and such capital may not be available on favorable terms or at all.

 

The Company is dependent on the proceeds from this offering, and a shortfall in proceeds could adversely affect its ability to execute its business plan.

 

Risks Related to This Offering and the Company’s Securities

 

This is a Regulation A offering, and the Company will have limited reporting obligations compared to companies that conduct registered offerings under the Securities Act.

 

The Company’s founder and Chief Executive Officer will control approximately 91% of the total voting power of its capital stock following this Offering, and will therefore be able to control all matters submitted to stockholders for approval.

 

There is no public market for the Company’s securities, and investors may not be able to sell their securities when they want or at a price that is acceptable to them.

 

Investors will experience immediate and substantial dilution as a result of this offering.

 

The Company may conduct future capital raises that could result in additional dilution to investors in this offering.

 

43

 

The Company will have broad discretion over the use of proceeds from this offering, and investors may not agree with how the Company spends the proceeds.

 

Listing the Company’s securities on the Nasdaq Capital Market will increase its regulatory burden.

 

The Nasdaq Capital Market may delist the Company’s securities, which could limit investors’ ability to engage in transactions in the Company’s shares and subject it to additional trading restrictions.

 

The Company will incur increased costs as a result of operating as a public company and will be required to devote substantial time to new compliance initiatives.

 

The Company may issue additional securities or other equity securities without shareholder approval, which would dilute the ownership interests of existing shareholders in the Company and may depress the market price of its shares.

 

The Company’s ability to meet expectations and projections in any research or reports published by securities or industry analysts, or a lack of coverage by securities or industry analysts, could result in a depressed market price and limited liquidity for its securities.

 

The Company may be required to take write-downs or write-offs, restructuring and impairment or other charges that could have a significant negative effect on its financial condition, results of operations and share price, which could cause investors to lose some or all of their investment.

 

The Company does not intend to pay dividends for the foreseeable future.

 

This Offering is being conducted on a “best efforts” basis and the Company may not be able to execute its growth strategy if the maximum offering amount is not sold.

 

This is a fixed price offering and the fixed offering price may not accurately represent the current value of the Company or its assets at any particular time. Therefore, the purchase price paid for the Company’s shares may not be supported by the value of its assets at the time of purchase.

 

As the Company’s initial public offering price is substantially higher than its net tangible book value per share, investors will experience immediate and substantial dilution.

 

The Company recently effected a reverse stock split of both classes of its common stock, which may not achieve its intended effect.

 

Using a credit card to purchase shares may impact the return on an investor’s investment as well as subject the investor to other risks inherent in this form of payment.

 

Forward-looking statements in this Offering Circular may not accurately predict the Company’s future performance, and actual results may differ materially from the Company’s projections.

 

44