
Matheus Rufino
Founder & CEO
PhD in Physics
Leads the scientific and strategic direction. Principal author of the IEQ formal framework.
IEQ, the Quantum Exposure Index, shows how much your organization depends on cryptography that may become vulnerable to quantum computing and where to act first. An executive readout that turns technical risk into migration priority.
Median market exposure
76.3
High level
Organizations measured
39.903
across 17 sectors
Vulnerability
69.9
Exposure
60.9
Horizon
79.0
Executive readout
Score, ranking, and priority in a single view for technical and executive teams.
Some data protected today must remain confidential for years. If that traffic is captured now, it can be stored and decrypted later, once quantum computers can break algorithms that are widely used today. This is the harvest-now, decrypt-later scenario.
The transition to post-quantum cryptography has already begun: NIST has finalized PQC standards, and the Brazilian ITI norm is in force. The challenge is not just knowing that risk exists. It is knowing where to start.
What is IEQ?
IEQ means Quantum Exposure Index. It is a way to measure, compare, and explain how exposed an organization is to cryptographic migration risk.
What problem does it solve?
It makes the discussion concrete. Instead of saying only “we need PQC”, IEQ shows which domains, sectors, and signals point to higher priority.
How is exposure read?
The methodology combines time urgency, cryptographic fragility, exposed surface, and governance maturity into one comparable readout.
What decision does it support?
Migration priority. The result helps define where to act now, where to monitor, and how to explain investment to leadership and the board.
39.903
organizations analyzed
76.4%
in high or critical exposure
90%
statistical confidence
10
recurring technical archetypes
The first scan requires no agent, credential, or integration. It reads public signals your organization already exposes on the internet and turns them into a comparable score, with an explanation of the factors that most influence the result.
Collects public signals
DNS, TLS, PQC readiness, HTTP headers, and exposed technologies
Translates signals into risk
Vulnerability and exposure enter the same readout
Calculates the IEQ score
A 0 to 100 ruler for comparison and prioritization
Sector context
Data horizon and governance maturity
Delivers priority
Comparable diagnosis to guide migration, without exposing organizations
Then, an optional declarative layer can refine the diagnosis with internal information that does not appear in public signals.
A number alone is only partly useful. When the readout is comparable across organizations and sectors, it becomes a decision map. IEQ puts each organization on the same ruler and shows who should move first.
The sector snapshot shows where the market is most exposed today. Your organization follows the same method, domain by domain.
Risk composition by sector
The larger the critical/high share, the more urgent sector migration tends to be
Exposure window by sector
The longer data must remain confidential, the earlier migration should begin
Health and government keep data for ~20 years; retail and e-commerce, around 5. The color follows sector exposure level. The decision is not only technical: it is a race against data lifetime.
Risk changes as time passes. Data that must remain secret for twenty years carries more exposure than short-lived data, even when both use the same cryptography.
IEQ brings that clock into the readout. The question shifts from “how much risk exists” to “where do we act now to reduce accumulated exposure”.
IEQ is designed to support executive decisions without becoming a black box. Measurement uses observable cryptographic signals, published methodology, and privacy-preserving statistical aggregation.
100%
integration independent
First readout from public signals, with no agent, credential, or access to systems.
100%
reviewable statistical model
Monte Carlo, Sobol analysis, and technical clustering support the score readout.
DOI
public report
Methodology and aggregated data are published for reading, citation, and external verification.
CC-BY
open license
The report can be reused and reviewed with attribution, reinforcing transparency.
2026-S1 technical report published on Zenodo under a CC-BY license.
Read the reportGWK Security is a Campinas deep-tech focused on post-quantum cryptography and quantitative cryptographic risk measurement. The work combines scientific research, data engineering, and product to support security decisions.
IEQ is the main engine behind that vision: academic rigor in the back, a simple readout in the front, and a focus on prioritizing migration before exposure accumulates.

Matheus Rufino
Founder & CEO
PhD in Physics
Leads the scientific and strategic direction. Principal author of the IEQ formal framework.

Rafael Duarte Marcelino
Founder & CTO
Mechanical Engineering · MBA in Data Science
Data architecture, analytics, and platform engineering for IEQ. Experience in regulated sectors.

Julio Smanioto Garcia
Founder & CSO
Physics · MSc student
Scientific front for QKD, post-quantum cryptography, and the interface with experimental research.
GWK’s technical work is documented in scientific output by the founders and in an open technical report.
A Formal Basis for Quantum Cryptographic Exposure Measurement under HNDL Threat
Rufino, Marcelino & Garcia (2026) · submitted to Elsevier
The formal basis of IEQ. It defines cryptographic exposure under the harvest-now, decrypt-later threat and supports the structure of the index.
arXiv:2605.22569Detectability Limits for Intra-Block Temporal Drift in Finite-Key Entanglement-Based QKD
Marcelino, Garcia & Rufino (2026) · Springer Nature (under review)
Statistical limits for detecting temporal drift in finite-key entanglement-based quantum key distribution.
arXiv:2605.24230Quantum Exposure Index Technical Report 2026-S1: Sector-Level HNDL Exposure
Garcia, Marcelino & Rufino (2026) · Zenodo · CC-BY
Applies IEQ to 39,903 organizations and consolidates HNDL exposure by sector, with migration priorities for post-quantum cryptography.
DOI 10.5281/zenodo.2076764808Next step
Apply the IEQ method to your domains and see which public signals increase your organization’s cryptographic exposure.
Score, risk factors, and migration priority in a decision-ready readout.