An AI red team will run inside a federally certified cloud (FedRAMP High) to attack encryption built to resist future quantum attacks, continuously for five years, the architecture new federal mandates are starting to demand.
Federal cryptography is being rewritten because adversaries are recording encrypted data today, betting that quantum computers will eventually crack it. That threat model, harvest-now-decrypt-later, is what makes a post-quantum migration urgent even when no quantum computer can break current public-key encryption yet. The first architectural proof point for what "post-quantum compliance" looks like in practice inside a federal cloud just landed: Assail's Reaper, an autonomous AI red team, will run inside Qanapi Group's FedRAMP High environment (the federal government's high-baseline cloud security standard, the level used for law-enforcement, financial, and emergency-services workloads) and continuously attack Qanapi's new post-quantum key stack, with an independent auditor checking its work, under a five-year, $4.125 million contract announced 2026-08-03.
The pairing is not a partnership of equals marketing themselves at a trade show. It is the shape that Executive Order 14412 and OMB Memorandum M-26-15 are starting to force on any vendor that wants to do post-quantum work inside a federal boundary: the offensive validator and the cryptography it attacks have to sit in the same authorization envelope, because the auditor needs to see the attack run against the deployed algorithm, not a lab copy.
Qanapi Group sells Karst, a post-quantum key management and encryption platform built on FIPS 140-3 validated modules, the federal cryptographic standard that replaced FIPS 140-2 in 2019 and now governs everything that touches sensitive government data. The company holds a FedRAMP High authorization, the highest of the four FedRAMP baselines and the level agencies use for sensitive unclassified workloads, aligned to DoD Impact Level 4 (DoD's standard for controlled unclassified information in cloud systems).
Assail's Reaper is an autonomous offensive-security agent: it does the job a human red team would do, but continuously. It will run inside Qanapi's authorization boundary and automate STIG assessments (Security Technical Implementation Guides, the Defense Information Systems Agency's hardening checklists) of the Karst stack, draft Plans of Action and Milestones for any failing control, submit them to a Third Party Assessment Organization, retest against Security Assessment Reports to separate true vulnerabilities from false positives, and generate patches for Qanapi to review.
The whole loop sits on top of stackArmor's "The Armory" compliance platform, a FedRAMP High / DoD IL4-5 system that handles the documentation trail an Authorizing Official needs to maintain the Authority to Operate, the formal permission that lets a system stay live in a federal environment. Because the AI model itself runs inside the boundary, every finding, retest, and patch stays inside Qanapi's environment, which is the part of the architecture that matters for federal customers.
The federal post-quantum migration has been talked about as an algorithm story: pick the new lattice-based schemes NIST settled on, swap them into the existing systems, done. According to Assail and Qanapi, the deal is evidence that the migration is becoming an operations story instead — where the boundary architecture and continuous validation matter as much as the algorithm swap itself.
If Reaper were running outside Qanapi's boundary, an auditor would have to take Reaper's word that it had attacked the live system. The whole point of putting the AI red team inside the FedRAMP High envelope, with the post-quantum key manager, with a 3PAO in the loop, is to make the attack evidence as auditable as the cryptography it is attacking. The new algorithm stack has to be continuously validated under sustained adversarial pressure, and the only way an Authorizing Official can sign off on that is if the validator lives where the system lives.
That is also why the contract is five years long. The technical work is not the limiting factor. The limiting factor is the ATO cycle: an initial authorization, then continuous monitoring, then reauthorization, with a 3PAO retesting against the Security Assessment Report on a recurring cadence. A one-year pilot cannot carry the paperwork; a five-year contract can.
Assail positions Reaper as the only autonomous offensive-security platform that lets a customer deploy the full stack, including the underlying AI models, on-premises, in a private or public cloud, or in an isolated network. That is a vendor self-claim, not an independently verified market position, and neither the Assail nor the Qanapi materials cite an outside benchmark, customer, or analyst to back it up. The architecture is real, and the FedRAMP High boundary is the part that does the federal work, but the "only" claim should be read as marketing copy rather than a category fact.
The deal also does not, by itself, prove that continuous AI-driven offensive validation is the new federal default. It is one early pairing inside a much larger PQC migration, and other vendors will run the same experiment with different architectures. The signal worth watching is whether the next round of FedRAMP High authorizations on post-quantum systems start requiring an in-boundary validator the way this one does.
The five-year contract starts now, with the first continuous-monitoring cycle expected inside the standard FedRAMP cadence. The architectural pattern — offensive validation, post-quantum key management, and an auditor loop, all inside one authorization boundary — is the part that will outlive the deal.