Home / News / Cybersecurity Incident

QIZ Security Raises $17 Million Seed Round for Post-Quantum Cryptography Platform

Cybersecurity startup QIZ Security says it has closed a $17 million seed round to develop and commercialise tools that map cryptographic assets, assess exposure and support migration toward post-quantum standards.

Published

QIZ Security has announced a $17 million seed financing led by Bessemer Venture Partners and Merlin Ventures, with the company saying it will use the capital to develop its cryptographic-risk platform and expand into additional markets.

The financing

The round was announced on 9 July and included Evolution Equity Partners, Singtel Innov8, Qbeat Ventures and Qino Cyber Capital, according to the company’s distributed release. QIZ did not publicly disclose a valuation, ownership percentages, revenue, customer count or the detailed allocation of proceeds. Finance Chronicles verified the amount and named investors through the announcement and a funding-industry report, but did not locate a regulatory filing confirming the private transaction terms.

What the company builds

QIZ describes its platform as a system for discovering cryptographic assets, mapping where encryption is used, modelling business risk and managing remediation. The intended problem is “crypto agility”: organisations need to know which algorithms, certificates, keys and libraries are embedded across applications before they can replace vulnerable components. This is especially relevant to banks and payment firms because cryptography supports authentication, transaction integrity, secure communications and protection of stored information.

Post-quantum context

Large-scale quantum computers could eventually undermine widely used public-key systems, although the timing and practical capability remain uncertain. Governments and standards bodies are promoting migration planning because changing cryptography across complex estates may take years. The risk includes “harvest now, decrypt later,” where encrypted information is collected today for possible future decryption. That does not mean existing financial encryption will fail on a specific announced date, and forecasts such as a near-term “Q-Day” should be treated as scenarios rather than facts.

Why financial institutions care

Banks often operate decades of technology, third-party software, hardware security modules, APIs and partner connections. An incomplete cryptographic inventory can turn a standards migration into an operational-risk event. Regulators and customers may expect firms to demonstrate governance, prioritisation and testing. A platform that connects technical discovery to business impact could be useful, but buyers must assess coverage, accuracy, access permissions, integration risk and whether the tool creates another sensitive repository of security information.

Claims and verification limits

QIZ’s release lists technology and consulting relationships, but Finance Chronicles did not independently confirm the scope or commercial status of every named relationship. No public benchmark was available showing how completely the platform finds cryptographic assets or how it compares with established cryptographic-discovery tools. The funding is newsworthy; product-effectiveness claims remain company assertions until supported by deployments, audits or reproducible testing.

What happens next

The company says it will accelerate product development and market expansion. Evidence to monitor includes hiring, enterprise contracts, integrations, security certifications, recurring revenue and independent technical evaluations. Financial institutions considering post-quantum programmes should treat tooling as one component of a broader plan covering inventory, data classification, vendor management, standards selection, testing, key management and controlled migration.

Why inventory comes before migration

An organisation cannot replace vulnerable cryptography that it cannot locate. Certificates and algorithms may sit in applications, network devices, cloud services, archived data and third-party products. Some support authentication while others protect long-lived confidential records. A useful inventory therefore needs ownership, data sensitivity, dependency and replacement difficulty, not just a list of algorithms. Financial institutions should prioritise systems where compromise would create material fraud, privacy or operational consequences and coordinate changes so that connected parties remain interoperable.

Funding-round due diligence

A private funding announcement confirms investor participation only to the extent supported by the parties’ statements. It does not establish valuation, revenue quality or technical leadership. Prospective customers should separate the company’s capital resources from product assurance. Security architecture, access privileges, penetration testing, data handling and incident response remain relevant. Investors and buyers should also examine how a platform maintains its own cryptographic components; a tool designed to find security weaknesses can itself become a high-value target.

Finance Chronicles assessment

The $17 million round is material for an early-stage cybersecurity company and fits a growing regulatory focus on technology resilience. The strongest verified fact is the financing announcement. The urgency and timing of quantum risk are less certain, while product performance remains untested publicly. Coverage should therefore avoid a countdown narrative and focus on the practical, current problem of cryptographic visibility and controlled migration planning.