Skip to main content

Q by Wentzel · seed pitch · 2026

The board number
for quantum risk.

Adversaries are recording encrypted traffic today. Q finds the cryptographic estate, scores the harvest-now-decrypt-later exposure, and prices it in dollars a board can act on. Private beta — design partners in defense and finance.

The problem

The ciphertext is already in an adversary’s archive. The board wants a number.

The question every CISO in defense and finance gets from the board: “We know harvest-now-decrypt-later is real. What does it cost us, in dollars, and by when?” Today nobody can answer it.

01

Harvest now, decrypt later

Recorded TLS sessions decrypt retroactively the day a cryptographically relevant quantum computer (CRQC) arrives. Long-lived secrets — defense programs, financial records, health data — are breached-in-waiting.

02

Nobody has a cryptographic inventory

Federal mandates now require cryptographic inventories, yet most organizations cannot list the ciphers, certificates, and key sizes across their own estate. No inventory means no migration plan.

03

Risk arrives as a color, not a dollar figure

Vulnerability tools emit severity colors. Boards allocate capital against dollar exposure and dates. Mosca’s inequality (X + Y > Z) says the window is now — hardware trajectories put a CRQC at 2028–2035.

Why now

The standards are final. The mandates are live. The budgets exist for the first time.

NIST PQC standards finalized

FIPS 203 (ML-KEM), 204 (ML-DSA), and 205 (SLH-DSA) were finalized in August 2024. The migration targets are no longer moving — every delayed migration plan just lost its excuse.

source · NIST FIPS 203/204/205

CNSA 2.0 deadlines are on the calendar

NSA’s CNSA 2.0 timeline requires post-quantum algorithms across national security systems, with phase-in deadlines through 2033. Defense suppliers inherit the schedule.

source · NSA CNSA 2.0

Crypto inventories are mandated

OMB M-23-02 requires federal agencies to inventory their cryptographic systems and prioritize migration. A cryptographic bill of materials is becoming a procurement artifact.

source · OMB M-23-02

12-24 month window before the broad vulnerability-management incumbents ship a CBOM-native PQC assessment surface. Q exists to occupy that window.

Market

TAM · SAM · SOM. Order-of-magnitude. Honest.

TAMSAMSOM$24MARR · year 3

TAM

$2.4B

US defense-industrial-base and regulated-finance organizations subject to crypto-inventory mandates — ~4,800 orgs × ~$500K average PQC assessment + migration-planning spend.

estimated from DIB supplier counts + federal/financial mandate scope.

SAM

$480M

Organizations with a dated mandate (CNSA 2.0 phase-in, M-23-02 inventory) and an estate large enough to need continuous scanning. ~1,600 orgs.

mandate-deadline qualifying filter applied to TAM denominator.

SOM (year 3)

$24M

5% of SAM. Blended tier mix across QScout Pro subscriptions and QStrike Enterprise contracts, design-partner beachhead first.

blended plan mix; founder-led + design-partner references.

TBD: confirm hard TAM/SAM figures with founder-approved sourcing spreadsheet before the first investor meeting.

The product

Three surfaces, one chain: find it, score it, price it.

QScout

Cryptographic Bill of Materials

Active TLS inspection and certificate analysis across the estate. Produces a full CBOM in CycloneDX 1.7 (JSON/XML) and ingests existing SBOMs, Shodan data, and passive DNS.

QScore

HNDL risk quantification

Weighted 7-factor harvest-now-decrypt-later score (0–100) plus a real Mosca inequality evaluation — migration time + data shelf-life vs the CRQC window.

QStrike

The Board Number

Probability-weighted dollar exposure per CRQC milestone year, built on isolated classic cryptanalysis modeled against quantum capabilities and published hardware trajectories.

Shipped, not slideware

A working scan pipeline on Cloudflare Queues; a native Rust deep-TLS enumeration engine running in a Cloudflare Container; a pure-TypeScript PQC computation layer — 58+ algorithm catalog with NIST/FIPS status, HNDL scoring, Mosca evaluation, and the QStrike financial engine. Plans in market: QRecon Free at $0, QScout Pro at $299/mo, QStrike Enterprise custom — access by request while the private beta runs.

Why we win

Pick the one that matters most to you.

Click a wedge to surface the proof point. We log the click in localStorage to see which differentiator lands hardest with investors.

First click — be the first to weigh in.

Competitive landscape

Alternatives, not competitors. April Dunford framing.

point-in-timecontinuousPQC-deepcheckboxQTenableQualysBig-4 crypto assessmentsPQC migration vendorsIn-house crypto team

The broad vulnerability-management platforms treat PQC as a plugin check; the consultancies go deep once and leave a PDF. Q is the only continuous, CBOM-native option that ends in a dollar figure. Pre-reference we lose to incumbent brand gravity; that’s precisely why design-partner conversion is milestone one.

The ask · interactive

Move the slider. The deck moves with it.

Seed ask

$5.0MM

Target — the right ask

Deep-TLS fleet scale-up + design-partner conversion + QScout Pro GA.

$3MM
floor
$5MM
target
$15MM
cap

Team

  • Founders1
  • IC engineers2
  • Sales / marketing1
  • Ops0
  • Total headcount4

Speed

  • Design partner 1 paidmonth 5
  • QScout Pro GAmonth 8
  • First QStrike Enterprisemonth 12
  • CNSA 2.0 offering livemonth 15
  • Runway54 months

Risk profile

  • De-riskeddeep-TLS fleet scale + design-partner conversion
  • Bet remainingenterprise sales cycle in defense + finance

Use of funds

Total · $5.0MM
Engineering$2.5MM
Go-to-market$1.1MM
Compliance & certifications$0.5MM
Runway buffer$0.7MM
Contingency$0.3MM

Milestones · 12 / 24 months

  1. M05Design partner 1 converts to paid
  2. M08QScout Pro GA
  3. M12First QStrike Enterprise contract
  4. M15CNSA 2.0 assessment offering live
  5. M18$2MM ARR run-rate

SWOT

Honest. Don’t sandbag. Don’t oversell.

Strengths

  • ·Working scan pipeline shipped — queue, engine, CBOM, persistence
  • ·Native Rust deep-TLS engine in production (Cloudflare Container)
  • ·Pure-TS PQC computation layer: 58+ algorithms, HNDL, Mosca, QStrike
  • ·Honest-by-construction scanning — partial CBOMs flagged, never fabricated
  • ·Solo-founder ship velocity proven across a live product portfolio

Weaknesses

  • ·Solo founder — bus-factor 1 until seed hires land
  • ·Private beta, pre-revenue is the honest state
  • ·No design partner converted to paid yet
  • ·Brand-new entrant against Tenable/Qualys brand gravity

Opportunities

  • ·NIST FIPS 203/204/205 final — migration is budgeted for the first time
  • ·CNSA 2.0 deadlines + OMB M-23-02 inventories pull the market forward
  • ·Incumbent PQC coverage is a checkbox, not a CBOM
  • ·CycloneDX CBOM standardization wave — Q speaks it natively today

Threats

  • ·Incumbents add PQC checkboxes and muddy the category
  • ·CRQC-timeline skepticism stalls security budgets
  • ·Federal budget cycles slip mandate enforcement to the right
  • ·PQC standards keep evolving; the algorithm catalog needs re-baselining

Founder

Solo founder, full-stack across the wedge. The seed buys the team.

Ryan Wentzel

Founder · Operator

Engineering background. Ships the entire Q stack — the Next.js product, the Cloudflare Queues scan pipeline, the Rust deep-TLS engine, and the pure-TypeScript PQC computation layer. Operates a portfolio of shipped products under Wentzel Investments LLC, which is the ship-velocity evidence. Runs founder-led sales into defense and finance design partners.

Founder-led today. Engine and go-to-market hires are the first seed-funded roles.

ryanwentzel.me

Why this founder

The wedge is engineering: a scanner that speaks CycloneDX, a Rust engine that enumerates real TLS, and a financial model a board can interrogate — all of it already shipped by one person. Advisor targets, in conversation: a former defense CISO and a cryptography researcher for the algorithm catalog’s governance. The credibility plan rests on shipped software and honest scan output, not on logo walls. Dedicated engine and go-to-market hires are the first seed-funded roles.

The ask

$5MM seed.
Design partner converted to paid by month 5. QScout Pro GA by month 8. First QStrike Enterprise contract by month 12.
We can do it with $3MM (slower) or absorb $15MM (different motion entirely), but $5MM is what fits the wedge.

Let’s talk.

Investor introductions welcome, and a beta briefing is the fastest way to see the scan pipeline live. Email with one line about your fund focus and the call slot that works for you.

© 2026 Wentzel Investments LLC (Florida). Q is post-quantum cryptography risk assessment, in private beta.security.txtq.wentzel.ai