A new Sheffield built national security unit targets allied defense networks and the legacy operational systems a software patch cannot reach.
A decade from now, an adversary with a cryptographically relevant quantum computer could read every piece of encrypted defense traffic it recorded today. The hard part is not the future decryption. It is the legacy bases, radar systems, and logistics networks that cannot be taken offline to install a software patch.
Sitehop, a Sheffield post-quantum hardware startup, launched a dedicated national security unit on Tuesday to sell a hardware-isolated answer to that exact retrofit problem. The unit will pitch Sitehop's SAFEcore Edge device, a self-wiping encryption appliance, at the operational technology networks of Five Eyes defense customers: the United States, the United Kingdom, Canada, Australia, and New Zealand (Quantum Computing Report).
Post-quantum cryptography refers to encryption algorithms designed to resist attack by a future quantum computer, not just conventional machines. NIST finalized its first post-quantum standards in 2024, and US federal agencies have begun mandating the transition. The harder problem is the systems the standards leave behind.
Defense operational technology, the equipment that runs radar, base logistics, fuel, and physical-security systems, was built to last decades, not to be patched. Many of these networks still run cryptographic routines that a sufficiently powerful quantum computer would break, and they cannot simply be reflashed. The industry's term for the threat this creates is "harvest now, decrypt later": adversaries record encrypted traffic today and store it until a quantum computer can unlock it. For long-life defense systems, the exposure window is measured in decades (Quantum Computing Report).
Sitehop's pitch is that the only viable retrofit is hardware. SAFEcore Edge is a small appliance that sits between the legacy equipment and the wider network, running post-quantum key exchange in a physically isolated processor. The device is designed to wipe its own keys on tamper detection and to operate without a software management plane, a deliberate contrast with software-defined wide-area networking products, which Sitehop argues share processors across management, configuration, and payload data and so leave cryptographic keys exposed to any software vulnerability on the box (The Quantum Insider).
That hardware-only posture also lets Sitehop frame the unit as a sovereign supply-chain answer. The company, founded in Sheffield, manufactures in the UK and pitches itself as an alternative to overseas cryptographic hardware suppliers, a framing that aligns with allied preferences for trusted-supply-chain vendors (Prolific North).
Tuesday's launch is one vendor's commercial product announcement, not a Five Eyes procurement decision. Sitehop's only disclosed deployment evidence, beyond a UK retailer payment-security trial covered by CFO Tech, is a claim that the hardware is deployed across seven countries with a tier-one telecom carrier; the truncated tail of the source description leaves the partner's identity and the deployment's outcome unstated. No UK Ministry of Defence, US Department of Defense, or allied-nation confirmation appears in the trade-press coverage that surfaced Tuesday.
"World's smallest PQC footprint" is Sitehop's own marketing line, drawn from the company's architecture table, not an independent benchmark. And the broader category, hardware-isolated post-quantum appliances for legacy defense and industrial networks, already has competitors, including larger US vendors that have been selling into defense primes for years.
What the launch does establish is the shape of the retrofit question. The PQC migration for legacy defense networks is a hardware swap, not a software swap, because the systems that need it most cannot be taken offline to install patches. Sitehop is the first UK sovereign-supply-chain vendor to package that pitch explicitly for allied defense buyers. Whether any of them buy it is a procurement question the launch itself does not answer.