Sector comparison
69.9V
60.9E
79.0H
IEQ measures your organization's cryptographic exposure and places it on the same ruler as its sector. Security, risk, and board teams get to know where migration starts, and how urgently.
Data captured today still counts in 2046
Measured base
The first thing you contract is the IEQ Exposure Report: a dated assessment of the organization, with a score from 0 to 100, sector comparison, risk factors, and priorities for the cryptographic migration.
IEQ Exposure Report
From 0 to 100, explainable and reproducible.
Executive Summary
The dimensions that weigh most in the reading, with the evidence behind each one.
Sector comparison
69.9V
60.9E
79.0H
No agent, no credentials, no access to internal systems. The engine computes over what is already exposed and returns a result on the sector's ruler.
DNS, TLS, and exposed technologies
Public signals in one structure
Vulnerability, exposure, and horizon
Sector context and governance
A 0-to-100 ruler for prioritization
Collection observes what the organization keeps lit on the internet: DNS, TLS, headers, and published technologies. An optional declarative layer refines the result with internal information no public signal reveals.
See the layers and the maturity of eachThe panel below uses the same component and the same sample data as the demonstration page — not a mockup.
Product sample
exemplo.com.br
IEQ score
12.1 points above the sector median.
Suggested priority: review the protocol and certificate signals identified in the full report.
Signal coverage
Breakdown
Fictional domain, for demonstration
See the full sample reportBoard, security, risk and compliance, migration program, research: every card leads to the reading that answers whoever is deciding.
Board and executives
Security and infrastructure
Risk and compliance
Migration program
Research and audit
Traffic captured today can be decrypted later: the harvest-now, decrypt-later scenario, and the risk IEQ measures. NIST has finalized the PQC standards and the Brazilian ITI norm 35/2026 is in force.
What the index measures is not abstract: it is the cipher a load balancer negotiates, a certificate's validity, a protocol version.
39.903
organizations analyzed
76.4%
in high or critical exposure
90%
confidence interval of the study
10
recurring technical archetypes
IEQ Technical Report 2026-S1, June 2026. It covers 39,903 organizations across 17 sectors, aggregated under k-anonymity (K = 30) and published on Zenodo under a CC-BY licence.
Read the 2026-S1 sector reportComparability
A number alone is only partly useful. On a shared ruler, it becomes an order of priority.
Market snapshot
There are 67 points between the most and the least exposed sector
The ordering sets the market's migration sequence, not the outcome of any single organization.
4 of 17
sectors in the critical band
8 of 17
above the sector median
14.6 vs 2.9
exposure and vulnerability spread across sectors
Risk is also time
Level is not enough. Urgency comes from how long data captured today still counts: 20 years in health and government, 5 in retail.
See the exposure window by sectorQuestions about the risk
The objections that come up in the first conversation, answered before it.
Because the adversary doesn’t need to wait. Intercepting and storing encrypted traffic today is enough to decrypt it once the capability exists. What matters is whether your cipher will hold for as long as the data still has value.
Years. Replacing cryptography means touching servers, applications, libraries, integrations, and contracts, almost always without being able to stop the operation. Because the transition is long, data captured while it runs stays exposed for as long as it takes.
A contract that must stay confidential for twenty years and a session token that expires in an hour do not carry the same risk, even under the same cipher. Traffic captured today is only worth anything to the adversary while its contents still matter.
A great deal. The cryptography protecting your operation runs through cloud providers, payment gateways, service providers, and software vendors. Exposure arriving through the chain is usually invisible in the internal inventory.
Because no organization has the budget and maintenance windows to replace everything at once. The order in which migration happens determines how much risk stays exposed along the way, and that order needs a defensible criterion.
The Exposure Report, above, is the first thing you contract. The other four deliverables extend the same measurement: sector comparison, regression alerts, post-quantum migration, and third-party exposure.
IEQ score with the contributors that weigh most
Sector percentile, against anonymous aggregates
Difference between successive collections
Current score against projected score, on the same ruler
Reach of exposure per supplier
The Quantum Exposure Index takes an evidence envelope, computes, and returns an explainable result on the same ruler for any organization.
Takes
An evidence envelope: signals observed by public collection and, where it exists, what the organization declared.
Returns
A score from 0 to 100, the four dimensions, the contributors that weigh most, and the signal coverage achieved.
Used for
Prioritizing migration: where to act first, how urgently, and why.
How to read the result
Where the engine's job ends
It does not monitor between collections, does not certify, and does not estimate when the quantum computer arrives.
The collection layer runs the sweep and hands over the envelope. The engine receives that finished material and computes on it.
Each assessment is a dated measurement. Nothing watches the organization between one collection and the next.
The result supports internal prioritization. Certification requires an accredited body, which GWK is not. And this readout does not replace an audit: it records what was declared, without internally verifying what the organization asserts.
The horizon measures how long the data still needs secrecy. The arrival date of the quantum computer stays outside the calculation.
What goes into the index
Three come from public signal and have a market median. The fourth exists only if the organization reports it.
How long the data still needs to stay secret. This is the time factor of risk: data requiring twenty years of secrecy carries more exposure than short-lived data, even under the same cryptography.
Market median · 79.0
The cryptographic fragility of what is actually in use. It considers the observed algorithms, key sizes, and protocol versions, and how well each resists an adversary with quantum capability.
Market median · 69.9
The size of the observable surface. How many services the organization publishes on the internet, how much of that traffic is interceptable today, and what share of it carries long-lived data.
Market median · 60.9
What no external signal reveals: cryptographic inventory, migration plan, and milestones already delivered. The organization reports it if it wants to, and that refines the diagnosis without ever replacing what was observed from outside.
Reported by the organization
More context, more depth, and more value for decision-making.
Scope
Public collection has an exact reach, and it is written here. A number only holds up in a committee when you know what went into it.
Five columns separate what was seen, derived, declared, and estimated. The last names what other evidence decides.
Observed
Public collection saw
Calculated
The IEQ engine derived
Declared
The organization reported
Inferred
The model estimated
Out of scope
Other evidence decides
Public mode and complete mode start from different kinds of evidence and sit on distinct rulers.
Public mode
Signals the organization already exposes on the internet. It requires no agent, credential, or integration, which makes it possible to assess any entity, suppliers included, without opening a change window.
Complete mode
Widens the scope with what the organization declares: cryptographic inventory, internal controls, and governance milestones.
The two modes start from different kinds of evidence and sit on distinct rulers. Today's public score does not compare to tomorrow's complete score: the difference would measure the change in evidence, and not the change in exposure.
After the measurement
Whoever runs the environment is who reduces the exposure.

Lowering exposure means changing concrete things: a load balancer, a certificate, a library, a supplier contract. That work belongs to the organization's own teams and suppliers, who hold the access and the responsibility for the environment. GWK measures before and after, always on the same ruler.
GWK is building EVA, for Exposure, Vulnerability and Adequacy, to cover that step. It is an ongoing project, with no closed scope and no date.
Executive decisions without a black box: observable signals, published methodology, and privacy-preserving aggregation.
See the formal basis of IEQ100%
integration independent
First readout from public signals, with no access to systems.
100%
reviewable statistical model
Monte Carlo and Sobol calibrate the model once. Each organization's calculation is deterministic.
DOI
public report
Methodology and aggregated data published for citation and external verification.
CC-BY
open license
The report can be reused and reviewed with attribution.
DOI
2026-S1 technical report published on Zenodo under a CC-BY license.
Two collections, two roles
The public report and the operational ruler are distinct collections, with distinct cutoffs. Results from one do not add up with the other.
GWK works with two collections. Technical report 2026-S1 publishes 39,903 organizations across 17 sectors under CC-BY, so the method can be reviewed by third parties. The ruler that orders sector comparisons comes from the operational base, with 316,911 companies in run producao_324k_20260712, cut off on July 12, 2026. These are distinct collections with distinct cutoffs: neither is a sample of the other, and results from one do not add to the other.
What this comparison is measured against
Limits of the comparison
Who is GWK
GWK Security is a Campinas deep-tech focused on post-quantum cryptography and quantitative cryptographic risk measurement. The work combines scientific research, data engineering, and product to support security decisions.
GWK GitHub
Matheus Rufino
Founder & CEO
PhD in Physics
Leads the scientific and strategic direction. Principal author of the IEQ formal framework.

Rafael Duarte Marcelino
Founder & CTO
Mechanical Engineering · MBA in Data Science
Data architecture, analytics, and platform engineering for IEQ. Experience in regulated sectors.

Julio Smanioto Garcia
Founder & CSO
Physics · MSc student
Scientific front for QKD, post-quantum cryptography, and the interface with experimental research.
Publications
Peer-reviewed output by the founders, plus an open technical report.

arXiv:2605.22569
Defines cryptographic exposure under the HNDL threat and supports the structure of the index.
Rufino, Marcelino & Garcia (2026) · submitted to Elsevier
Open publication
arXiv:2605.24230
Statistical limits for detecting temporal drift in finite-key entanglement-based QKD.
Marcelino, Garcia & Rufino (2026) · Springer Nature (under review)
Open publication
DOI 10.5281/zenodo.20767648
Applies IEQ to 39,903 organizations and consolidates HNDL exposure by sector, with migration priorities.
Garcia, Marcelino & Rufino (2026) · Zenodo · CC-BY
Open publication10Next step
Tell us how many organizations need to be assessed and which decision the result will support.
Score, risk factors, and migration priority in a decision-ready readout.