
Product
CaveroKEX™
Post-quantum key exchange sized to the endpoint, proven on live SIMs and delivered over the air to devices already in the field.
CaveroKEX™ is Cavero Secure's patented post-quantum key exchange. Tuned for optimal computation, it performs with around half of the computational requirements as ML-KEM at an equivalent parameter set; tuned for minimum footprint it runs in as little as 2.1KB of RAM*. Neither party ever transmits the key: both derive it, so there is no secret in flight to intercept and no static credential left on the device to steal
Tiny PQC
Small footprint Big gains
Though post-quantum cryptography is advancing rapidly, one class of devices remains critically exposed: constrained devices. That includes IoT sensors, SIMs and eSIMs, industrial controllers, and other miniaturised devices with limited computing resources and battery power.
NIST-approved algorithms such as ML-KEM were not designed for those budgets. On the smallest endpoints, a conventional ML-KEM implementation can exceed the application's available RAM. Many of these devices also depend on keys fixed at manufacture. A pre-shared key is not itself vulnerable to a quantum attack, but a single secret held in place across a twenty-year deployment is a long bet, and on constrained hardware there has rarely been a practical way to establish a fresh one.
The Solution
What is CaveroKex™?
CaveroKEX™ is a post-quantum key exchange protocol built for constrained devices. It is configurable rather than fixed: tuned for computation, it performs around half the work of ML-KEM at an equivalent parameter set, and tuned for minimum footprint, it runs in as little as 2.1KB of working memory. CaveroKEX™ brings post-quantum security to environments other protocols cannot.

CaveroKEX is unique
Familiar hardness, new construction
CaveroKEX uses Learning With Errors over a polynomial ring as the basis of its security, a variant of the same lattice problem that underlies ML-KEM. That is deliberate. The construction is Cavero Secure's own, but the hardness assumption beneath it has been studied by the cryptographic community for over a decade. We innovate in the reconciliation, not in the foundations.
Exchange, not encapsulation
CaveroKEX doesn’t rely on an encapsulation mechanism to securely exchange a key with another party. Both parties exchange highly correlated datasets and use correlation filtering to derive a mutual secret. The secret itself is never transmitted, and recovering it from the public data shared is computationally infeasible.
Optimised for constrained environments
CaveroKEX-1024 performs around half the computational work of ML-KEM-1024 at an equivalent parameter set. Configured instead for minimum footprint, it runs in as little as 2.1KB of working memory, at the cost of additional communication rounds. Memory and computation trade against one another, so the build is tuned to the endpoint rather than fixed. CaveroKEX™ has been demonstrated on live SIMs and microcontrollers, making it a viable ML-KEM alternative that is ready for pilot today.
What can you do with CaveroKEX™?
CaveroKEX™ is more than just an ML-KEM alternative. Along with CaveroCTX™, our continuous verification protocol, it is the foundation of CaveroCore™ – our solution for continuous, mutual trust between endpoints that’s quantum-safe, lightweight, and ready for modern system architectures. CaveroCore™ is already being applied across agentic AI identity, in-field hardware activation, factory-to-field workflows and SIM swap fraud prevention.
If you are working on a project where post-quantum security has to fit inside a constrained device, we’d like to hear about it. Get in touch below – we work directly with partners to prove deployments on real hardware.