Aerospace cybersecurity: the control plane stays inside your fence
Programme work comes with conditions that rule out most modern tooling: no third party cloud in the management path, separation between programmes that has to be shown, and documentation for every cryptographic choice. QS-WAN can be licensed to run entirely inside your boundary, which is where this conversation usually ends.
A supplier that cannot meet all three is not in the conversation.
The prime sets the rules, and they do not bend
A supplier to an aerospace or defence programme inherits the customer’s security requirements, and those requirements are written with the assumption that the supplier is the weak link. They arrive as conditions in a contract rather than suggestions in a framework.
The condition that breaks most tooling is simple: the management layer cannot live in somebody else’s cloud. That single line removes a large part of the market, and it is not negotiable because it was not written by the person you are talking to.
The second is separation. Work for one programme must not be reachable from another, and the proof has to be structural rather than procedural, because procedures drift and audits look for the drift.
Where the control plane lives
Not where the data sits: where the thing that configures the network sits. That is the question that decides whether a tool is usable at all.
Whether separation is enforced or promised
A policy document describing programme separation is weaker than a drawing of gateways and the edges between them.
Whether claims survive scrutiny
Technical evaluators check. A vague quantum ready claim costs credibility; a documented inventory earns it.
Licensed inside, separated by design, documented by subsystem
QS-WAN runs a private network from one console, and QNova Client puts it on the device. For programme work, three properties matter more than features.
Licensed onto your own infrastructure
The console runs inside your boundary, physical or virtual, with no dependency on an external service. A site with no route to the public internet keeps working, management included.
A gateway per programme, and edges you can point at
Each programme sits behind its own gateway with its own VLANs and address space, and a permitted path between two segments is an edge that is on, off, one way or zero trust. Separation becomes a picture rather than a paragraph.
Cryptography you can attach to a response
Key establishment and signatures are post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design, with the inventory documented by subsystem.
Identity per membership
A device holds a separate certificate for each gateway it belongs to, so an engineer moved off a programme loses exactly that access and nothing else.
Kernel drivers attested by Microsoft
Our kernel drivers are attested by Microsoft. That is the exact scope of the claim, and the evidence is available, because this buyer verifies.
The questions a prime asks a supplier
These arrive in audits and in flow down clauses, and the answers sit in the console rather than in a policy folder.
Where does the management plane run?
On your infrastructure, under your control, with no external dependency when licensed in house.
How are programmes separated?
A gateway per programme, its VLANs and address space, and the edges between segments drawn in the Network Map.
Who can reach programme systems?
User profiles, devices and one certificate per gateway membership, revocable individually, with a CSV export.
What cryptography is in use, exactly?
The inventory by subsystem, naming the standards, rather than a marketing sentence.
One sentence that buys credibility. A green confirmation means the intention was recorded. A gateway that was offline applies it on reconnect, and we would rather write that in a response than have an evaluator find it.
What we do not claim in this sector
Aerospace and defence buyers are used to being oversold. These are the limits.
Nothing airborne
This is enterprise and site networking. Avionics, mission systems and their certification regimes are a different world with different rules.
No accreditation claims
The platform produces evidence that helps with programme requirements. It does not accredit you, and we do not describe ourselves as approved by any authority.
Not a managed service
Nobody at QuantumNova watches your network. The console and everything it records are yours.
Platform coverage differs
Windows is the complete implementation, Linux is a genuine port with gaps we declare, and macOS and iOS are planned.
Start with the clause that blocked the last tool
Usually it is the one about external management planes. Bring it to a free demonstration and we will go through it line by line.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.