⚛ “Harvest now, decrypt later” is already happening. Be quantum-safe today. Get early access →
Early access · limited to 100 organizations

Email built to survive the QUANTUM ERA

The encryption protecting your email today won't survive quantum computers, and attackers are already harvesting data to crack it later. Dualis Mail keeps your most sensitive conversations private now and after Q-Day, with end-to-end post-quantum encryption.

Protected today. Ready for tomorrow.

NIST FIPS 203 · 204 · 205 End-to-end encrypted Zero-knowledge Engineered across Europe & the U.S.
Standards, not promises

Built on the NIST post-quantum standards

In 2024 the U.S. National Institute of Standards and Technology finalized the first post-quantum algorithms. Dualis Mail implements all three.

FIPS 203
ML-KEM-768

Lattice-based key encapsulation. Establishes the shared secret that keeps every message confidential.

FIPS 204
ML-DSA-65

Lattice-based digital signatures. Proves who sent a message and that it wasn't altered.

FIPS 205
SLH-DSA

Hash-based signatures with conservative security assumptions, for defense in depth. Your choice per account.

The quantum threat

Harvest now, decrypt later

Adversaries are already capturing and storing encrypted traffic, waiting for a quantum computer powerful enough to break it. The day that machine arrives, every email you sent with classical encryption becomes readable. The only defense is to be quantum-safe before that day. Dualis Mail makes that switch invisible to your users.

📨
Classical email (RSA / ECC) Captured today → decrypted on “Q-Day” → fully exposed.
🛡️
Dualis Mail (post-quantum) Captured today → still unbreakable on Q-Day → stays sealed.
Under the hood

Hybrid on the wire. Hybrid at the core.

Classical security. Post-quantum resilience. That pairing is where the name Dualis comes from: every layer combines both, so your email only breaks if an attacker breaks both.

Communication

A hybrid handshake

Every connection is locked by two key exchanges at once: today's battle-tested X25519 and the post-quantum ML-KEM-768. To listen in, an attacker has to break both. If one ever falls, the other still holds the line.

X25519ML-KEM-768
Protection

Sealed and signed, twice

Every message is sealed with X-Wing (X25519 + ML-KEM-768) and signed twice, with ML-DSA-65 and Ed25519. Classical and post-quantum together, so the content only breaks if an attacker breaks both.

X25519ML-KEM-768ML-DSA-65Ed25519
Early access

Get early access

We're opening just 100 seats to organizations that want to run real, quantum-safe email before anyone else. Selected teams receive an email invitation with a private link to set up their account.

🎉
Seat reserved!

We'll send your invitation by email with a link to get started.