# Cyber Company Profiles: SandboxAQ

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-07-11
Canonical: https://cybercompanyprofiles.com/companies/sandboxaq
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of SandboxAQ, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [sandboxaq.com](https://www.sandboxaq.com)
- Profile: https://cybercompanyprofiles.com/companies/sandboxaq
- Type: Data Security, Governance Risk Compliance, Identity Access
- Also known as: Sandbox AQ
- Market readiness: Established (29/40)
- Defensibility: Contested (13/21)
- Founded: 2022
- Funding: $950M total
- Last updated: 2026-09-01

## Executive Summary

This analysis is scoped to AQtive Guard.

The record a buyer can check on SandboxAQ's AQtive Guard is federal. The company has an agreement with the Department of War's chief information officer to deploy the platform, program work for the military agency DISA, and FedRAMP Ready status, an eligibility step toward federal cloud approval. The product finds an organization's cryptography by tracing what runs live in production, catching hidden algorithms and shadow keys that tools scanning stored files miss. Commercial proof is thinner. Telecom and enterprise names appear in SandboxAQ's statements rather than independent reporting. SandboxAQ has raised over 950 million dollars since leaving Alphabet to fund several business lines. Public sources do not disclose the cryptography line's sales separately.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | AI and advanced-computing company whose AQtive Guard platform discovers an organization's cryptography through runtime tracing, manages certificates and keys, detects non-human-identity risk, and orchestrates the migration to post-quantum cryptography. | [\[f1\]](#company-detail-sources) |
| Founded | 2022 | [\[f2\]](#company-detail-sources) |
| HQ | Palo Alto, California | [\[f3\]](#company-detail-sources) |
| Funding | $950M total | [\[f4\]](#company-detail-sources) |
| Latest funding | Series E, over $450M (April 2025, about $5.75B valuation, new investors Google, NVIDIA, BNP Paribas, Ray Dalio) | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| AQtive Guard | Cryptography management platform that inventories certificates, keys, and algorithms via runtime tracing, scores crypto and non-human-identity risk, and orchestrates post-quantum migration. |
| Flint AI CLI | Command-line tool for proving an AI agent is safe to ship. It scans the agent, tests it, and reports what fails, running entirely on the developer's own machine. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Networks | ✓ | ✓ |  |  |  |
| Data | ✓ | ✓ |  |  |  |
| Applications | ✓ |  |  |  |  |
| Users | ✓ |  |  |  |  |

AQtive Guard inventories cryptography across networks, data in transit, and applications through runtime tracing and discovers non-human identities. SandboxAQ's cybersecurity line defends conventional cryptographic infrastructure and is mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (29/40)**

Analyzed 2026-07-04. Scope: AQtive Guard, the cryptography-management line.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 4/5 | AQtive Guard targets a precise buyer pain, cryptography managed ad hoc across an enterprise with no live inventory, quantified by certificate- outage cost and the post-quantum migration deadline, and corroborated by independently reported federal demand through the DoW agreement and DISA program work. \[[s1](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | The platform is generally available with public product documentation, a distinctive runtime-tracing discovery approach over static scanning, named integrations with Tanium and ServiceNow, and independent federal demonstrations through DISA's QRC PKI program. \[[s1](#profile-analysis-sources), [s3](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Market Timing | 4/5 | Post-quantum migration is an active buyer-side driver, with federal cryptographic-modernization mandates and the DoW agreement dated within the last year. The enabler is the 2024 finalization of NIST post-quantum standards that turned migration from advisory to scheduled work. \[[s4](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | NIST's National Cybersecurity Center of Excellence independently names SandboxAQ among the technology collaborators that signed a research agreement for its post-quantum migration project, which corroborates the standards-body roles across GSMA and the PQCA that the company states. With the Alphabet spinout pedigree backed by Google and NVIDIA, that independent confirmation supports sustained recognized standing rather than a single signal. \[[s8](#profile-analysis-sources), [s3](#profile-analysis-sources), [s6](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | A DoW CIO agreement builds on DISA QRC PKI work, and deployment partners Accenture, Deloitte, EY, and Carahsoft produce joint engagements. Commercial customer names trace mostly to SandboxAQ's own statements, which caps the score below the independent-benchmark bar. \[[s5](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The over 950 million dollars raised funds multiple product lines, not the cryptography line alone, so parent capital does not evidence the line's output per dollar. The line ships one product on a steady cadence while reported revenue is early, supporting an adequate rather than strong score. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Cryptography management and post-quantum migration is a buyer-placeable category with a federal procurement path, evidenced by FedRAMP Ready status and the DoW agreement that name the work directly. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources), [s9](#profile-analysis-sources)\] |
| Incumbent Defensibility | 2/5 | Cryptographic discovery and certificate management is a plausible release for certificate-lifecycle, identity, and cloud incumbents already adjacent to the buyer. The federal relationships and runtime-tracing depth are real but not yet a structural moat that bundling alone could not replicate. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |

### Business Risks

- A certificate-lifecycle or machine-identity incumbent already deployed with the same buyers could add runtime crypto discovery and PQC migration planning as a feature, absorbing the line's core capability.
- The cryptography line's commercial traction is not separately disclosed, so its standalone revenue could stay thin even while the parent stays well funded across its other product lines.
- FedRAMP Ready is an eligibility designation, not a full authorization to operate, so a delay reaching an ATO could stall federal expansion.
- A possible SandboxAQ IPO would put the conglomerate's economics under public-market scrutiny, which could redirect investment away from the cryptography line.
- Cloud providers could ship native cryptographic inventory and post-quantum enablement for their own key-management and TLS services, undercutting an orchestration layer in the environments where most cryptography runs.

### Problem & Market

AQtive Guard addresses cryptography that enterprises manage without a live inventory. SandboxAQ describes cryptography as the foundation of cybersecurity that still gets managed in an ad hoc, siloed manner, leaving certificates, keys, and algorithms uncataloged across an estate.

Two dated drivers make the problem urgent. The 2024 arrival of finalized NIST post-quantum standards turned migration into scheduled work, and federal mandates push agencies to discover and modernize cryptography ahead of quantum threats. The Department of War CIO agreement in December 2025 names exactly this work, automated cryptographic discovery and post-quantum migration across its systems.

The buyer is a CISO or federal security program owner who needs to find weak cryptography and plan its replacement without breaking production. Certificate outages that cost up to 9,000 dollars per minute, a figure SandboxAQ cites on its product page, give that buyer a quantified reason to act before a forced migration. \[[s1](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Product Capabilities

AQtive Guard discovers cryptography from runtime behavior rather than static scans. Network analysis and runtime tracing reveal what cryptography is actively running in production, including dynamically loaded libraries and shadow keys that inventory tools managing only their own certificates miss.

The platform extends from discovery into remediation. It correlates data across code, runtime, and the network to build a cryptographic inventory, then orchestrates key rotations, algorithm replacements, and PQC migrations with impact simulation and risk scoring. SandboxAQ added enterprise-grade operational features to serve large regulated customers.

The line reaches beyond cryptography into non-human-identity risk. The FedRAMP announcement describes AQtive Guard providing visibility, assessment, and remediation of vulnerabilities stemming from weak encryption and the proliferation of AI agents and non-human identities. Integrations with Tanium and ServiceNow place the inventory inside tools the buyer already runs. \[[s4](#profile-analysis-sources), [s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Competitive Positioning

SandboxAQ positions AQtive Guard against legacy PKI tools that see only the certificates they manage. Its claimed differentiation is correlation across code, runtime, and network to surface hidden algorithms and shadow keys that static and certificate-bound tools cannot reach.

The closest cataloged peers are QuSecure and QIZ Security, both post-quantum cryptography specialists. QuSecure carries named federal references and inline orchestration, while QIZ focuses on posture discovery and readiness ranking. AQtive Guard sits above both on traction and on its runtime-tracing discovery method, and matches QuSecure on the federal-procurement footing.

The harder competition comes from adjacent incumbents. Certificate-lifecycle, machine-identity, and cloud platform vendors all sit next to the same buyer, and any of them could add crypto discovery and PQC planning. SandboxAQ's defense is the federal position and reference base, not the discovery feature itself. \[[s1](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Go-to-Market & Traction

AQtive Guard reports a customer base across government, telecom, and enterprise, though most names come through SandboxAQ's own statements rather than customer testimony. The public federal anchor is a Department of War CIO agreement, announced in the company's press coverage, which builds on demonstrations with DISA's QRC PKI program and opens a path for other DoW agencies to adopt the platform.

FedRAMP Ready status gives federal buyers a standardized evaluation route, which shortens procurement for the agencies the line targets. That status is itself a go-to-market asset, not only a trust signal.

Channel partners extend reach. SandboxAQ has trained cybersecurity teams at Accenture, Deloitte, EY, and Carahsoft to deploy AQtive Guard, producing joint customer engagements that a pure-play startup would take years to assemble. \[[s5](#profile-analysis-sources), [s3](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Team & Credibility

SandboxAQ carries pedigree from its origin and its standards work. The company spun out of Alphabet in 2022 under a publicly recognized CEO and raised over 950 million dollars from investors including Google and NVIDIA.

The cryptography team holds active roles in the bodies that define post-quantum practice. NIST's National Cybersecurity Center of Excellence names SandboxAQ among the technology collaborators that signed a research agreement for its Migration to Post-Quantum Cryptography project, an independent confirmation of standards work the company also describes across the GSMA post-quantum telecom network effort, the Linux Foundation's Post-Quantum Cryptography Alliance, and MITRE's PQC Coalition. That confirmation distinguishes the standing from a self-reported affiliation. \[[s6](#profile-analysis-sources), [s3](#profile-analysis-sources), [s8](#profile-analysis-sources)\]

### Trust Readiness

SandboxAQ has built federal-grade trust collateral for AQtive Guard. The platform reached FedRAMP Ready status on December 4, 2025, and AQtive Guard now appears in the FedRAMP Marketplace at the Moderate impact level.

Commercial attestations sit alongside the federal path. SandboxAQ holds a SOC 2 Type I report for AQtive Guard and an ISO/IEC 27001 certificate covering the whole company. FedRAMP Ready is an eligibility designation rather than a full authorization to operate, so the federal trust story is credible but not yet complete. \[[s2](#profile-analysis-sources), [s9](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| QuSecure | competes with | Post-quantum cryptography orchestration platform with named federal reference customers, the closest same-asset peer. |
| QIZ Security | competes with | Cryptographic posture management platform focused on discovery and post-quantum readiness ranking. |
| Keyfactor | adjacent | PKI and machine-identity incumbent whose certificate-lifecycle and crypto-agility scope overlaps AQtive Guard's inventory and remediation. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (13/21)**

Band guidance: reinforce or reposition. Analyzed 2026-07-11. Scope: AQtive Guard, the cryptography-management line.

The public record shows no asset that grows with each AQtive Guard sale and no cross-customer dataset. AQtive Guard is SaaS per its FedRAMP listing, and the reviewed record discloses no managed-service or accountability layer. Its FedRAMP Ready listing rests on an independent assessment a rival must repeat, while the Department of War agreement and DISA work are deployment evidence rather than assessments passed. Tracing cryptography in production is harder than the static scanning peers ship, though a funded rival could copy it. A rival that rebuilds the Tanium and ServiceNow integrations could take over the rotation and migration work. Federal and regulated buyers run swaps through procurement review. SandboxAQ's edge is a head start backed by credentials rather than a widening lead.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | AQtive Guard is SaaS-delivered per its FedRAMP listing. The reviewed record describes software and discloses no managed-service or accountability layer, and it does not state who operates the workflows or owns the results. Risk scoring and orchestration are software output on that record, not a service blend that accepts accountability. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Switching Cost | 2/3 | A deployed AQtive Guard holds the customer's cryptographic inventory, its documented dependencies and policies, and operational integrations with Tanium and ServiceNow, which takes effort to rebuild on a rival. Nothing public adds network effects or data residency beyond that operational friction. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Compliance Moat | 2/3 | AQtive Guard holds FedRAMP Ready status and a FedRAMP Marketplace listing at the Moderate impact level, a federal eligibility path a commercial rival cannot quickly clear, which earns a 2 under the federal-or-mandate boundary. FedRAMP Ready is readiness rather than a full authorization to operate, and the SOC 2 Type I and ISO 27001 certificates alone would be table stakes, so the score is capped below a verified authorization. \[[s2](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Problem Complexity | 2/3 | Discovering cryptography from runtime traces and network correlation in production, rather than static binary scanning, is the distinctive claim on the product page and a real engineering build. The public record does not show the implementation to be unusually hard to replicate, and the rationale elsewhere concedes incumbents could copy the discovery feature, so it reads as solid engineering rather than a defensible technical moat. \[[s1](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | AQtive Guard sells to federal agencies and regulated enterprises whose procurement and legal review gate any replacement, with the DoW CIO and DISA programs at the most demanding end of that set. \[[s5](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Layer | 2/3 | AQtive Guard orchestrates live cryptography in the path systems rely on, more operationally embedded than a read-only scanner. The marketed no-disruption design and the absence of evidence that removal halts production keep it below a production-critical 3. \[[s4](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | No proprietary dataset, threat feed, or licensed content is claimed publicly. No cross-customer asset appears in the record, and the differentiator is runtime-discovery engineering rather than an accumulating corpus a rival could not re-earn. \[[s4](#deep-dive-sources), [s1](#deep-dive-sources)\] |

### Strategic Market Segmentation

AQtive Guard targets regulated enterprises and government agencies that must inventory and modernize their cryptography. SandboxAQ frames cryptography as the foundation of cybersecurity that organizations still manage ad hoc, which positions the purchase as a cryptographic program rather than a single tool.

The dated demand driver is post-quantum migration. Finalized NIST standards and federal modernization mandates turn discovery and migration into scheduled work, and the Department of War CIO agreement names exactly that work across its systems.

The public record skews federal. The DoW agreement and DISA program work anchor the record but arrive as vendor announcements republished by the trade press, while telecom, banking, and enterprise names come through SandboxAQ's own statements. That weighting makes the line a defense and public-sector supplier first in the verifiable record. \[[s5](#deep-dive-sources), [s4](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

AQtive Guard discovers cryptography from runtime behavior rather than static scans. Network analysis and runtime tracing show what cryptography runs in production, surfacing hidden algorithms and shadow keys that certificate-bound inventory tools miss, and the platform correlates code, runtime, and network into one inventory.

The capability extends into orchestration. It runs key rotations, algorithm replacements, and PQC migrations with impact simulation and risk scoring, the control-plane move that separates it from a discovery scanner. Enterprise features such as single sign-on, audit logging, horizontal scaling, and high availability support large regulated deployments.

The AI advantage in the cited record is method, not a data moat: the pages document risk scoring, remediation orchestration, and non-human-identity coverage without naming an AI triage mechanism, and no cross-customer aggregation of runtime traces appears in it. The durable technical asset is the runtime-discovery engineering itself, not an aggregating corpus. \[[s4](#deep-dive-sources), [s1](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

AQtive Guard runs a sales-led government and enterprise motion, and the verifiable proof is federal. A DoW CIO agreement builds on DISA QRC PKI demonstrations and opens a path for other DoW agencies to adopt the platform, with FedRAMP Ready status giving federal buyers a standardized evaluation route.

Channel partners extend the reach. SandboxAQ says it trained cybersecurity teams at Accenture, Deloitte, EY, and Carahsoft to deploy AQtive Guard, resulting in joint customer engagements.

Commercial breadth is the thinner layer. Telecom and enterprise names appear through SandboxAQ's own statements rather than customer testimony, so the public traction reads as federal procurement plus partner-led engagements more than a checkable commercial logo list. \[[s5](#deep-dive-sources), [s3](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Pricing Model

SandboxAQ publishes no pricing or packaging for AQtive Guard in the reviewed materials. The product is a sales-led platform with FedRAMP Ready status, and the site routes to demos rather than a price list, which for a platform aimed at government and regulated enterprises signals large negotiated deals.

The charging unit will be a strategic choice the public record does not yet settle. Per-asset pricing would penalize the thorough discovery the product exists to produce, while per-environment or per-system pricing would better match how migration programs budget. A buyer cannot yet compare the platform on cost. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Product Delivery & Operations

AQtive Guard deploys as a hosted platform, per its FedRAMP listing, with a federal-grade path made explicit. The FedRAMP Ready designation signals eligibility for a federal cloud evaluation route, and SandboxAQ added high availability and horizontal scaling for enterprise-scale operation.

The architecture aims to ease change. SandboxAQ describes orchestrating key rotations, algorithm replacements, and PQC migrations with impact simulation so customers move cryptography without breaking production. Integrations with Tanium and ServiceNow place the inventory inside operational tools the buyer already runs.

Operational transparency beyond those signals is thin in public materials. No documentation portal, SLA, or support-tier description appears in the reviewed sources, so a buyer's operational diligence starts inside the sales process. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources), [s3](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Earning Customers' Trust

SandboxAQ has built federal-grade trust collateral for AQtive Guard. The company announced FedRAMP Ready status on December 4, 2025, saying the designation reflects an independent third-party assessment, while the FedRAMP Marketplace lists AQtive Guard as FedRAMP Ready as of November 13, 2025, at the Moderate impact level.

Commercial attestations sit alongside the federal path. SandboxAQ announced a SOC 2 Type I report for AQtive Guard and an ISO/IEC 27001 certificate covering all of SandboxAQ. Neither document appears in the reviewed materials, so a buyer cannot yet see the controls tested. FedRAMP Ready is an eligibility designation, not a full authorization to operate, and SOC 2 Type I tests controls at a point in time rather than over a period, so the trust story is credible but not yet at its strongest form. \[[s2](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

SandboxAQ presents AQtive Guard as a cryptographic control plane inside an account rather than an ecosystem others build on. It integrates outward into Tanium, ServiceNow, and IT-management platforms, which is the product reaching into the buyer's stack rather than third parties extending the product.

The partnership posture is distribution-borrowing. SandboxAQ leans on Accenture, Deloitte, EY, and Carahsoft to deploy the platform, a channel mix matched to its federal weighting. The dependency risk is that cloud providers operate the key-management and TLS endpoints a cryptographic orchestration layer coordinates and could absorb the function natively.

A durable category path runs through the cryptographic inventory itself. If auditors and regulators converge on cryptographic inventories as standing evidence, the system that holds an enterprise's crypto inventory and orchestrates its rotation becomes a hard-to-replace integration point. AQtive Guard gestures at that role but the public record does not yet establish it as a system of record. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Team & Execution Capability

SandboxAQ carries pedigree from its origin and its consortium work. The company spun out of Alphabet in 2022 under a publicly recognized CEO and raised over 950 million dollars from investors including Google and NVIDIA.

SandboxAQ participates in NIST NCCoE's post-quantum migration consortium. The National Cybersecurity Center of Excellence names SandboxAQ among the technology partners and collaborators that signed a research agreement for that project, which independently confirms the affiliation. SandboxAQ separately reports affiliations with the GSMA's PQTN, the Linux Foundation's PQCA, and MITRE's PQC Coalition, and those remain company statements rather than confirmed standards-setting roles.

The execution test is the security line's commercial scale. The consortium participation and federal relationships are strong, while repeatable commercial sales for the cryptography line specifically, separate from the parent's other businesses, are not yet shown in public. \[[s6](#deep-dive-sources), [s3](#deep-dive-sources), [s8](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [SandboxAQ AQtive Guard product page](https://www.aqtiveguard.com/) | official | 2026-06-21 |
| f2 | [SandboxAQ: Closes $450M Series E Round](https://www.sandboxaq.com/press/sandboxaq-closes-450m-series-e-round-with-expanded-investor-base) | official | 2026-06-21 |
| f3 | [PR Newswire: SandboxAQ Achieves FedRAMP Ready Status](https://www.prnewswire.com/news-releases/sandboxaq-achieves-fedramp-ready-status-powering-enterprise-readiness-across-the-defense-and-public-sector-302632552.html) | press | 2026-06-21 |
| f4 | [PYMNTS: SandboxAQ Raises $450 Million for Quantitative AI Platforms](https://www.pymnts.com/news/investment-tracker/2025/nvidia-and-google-backed-sandboxaq-raises-450-million-for-quantitative-ai-platforms/) | press | 2026-06-21 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [SandboxAQ AQtive Guard product page](https://www.aqtiveguard.com/) “Legacy PKI tools only see what they manage. AQtive Guard correlates data across code, runtime, and the network. Discover every managed certificate, hidden algorithm, and shadow key with zero manual effort.” | official | 2026-06-21 |
| s2 | [PR Newswire: SandboxAQ Achieves FedRAMP Ready Status](https://www.prnewswire.com/news-releases/sandboxaq-achieves-fedramp-ready-status-powering-enterprise-readiness-across-the-defense-and-public-sector-302632552.html) “AQtive Guard provides complete visibility, assessment, and remediation of critical vulnerabilities stemming from weak encryption and the rapid proliferation of AI agents and non-human identities (NHIs). ... the SOC 2 Type I report for AQtive Guard and the ISO/IEC 27001 certificate.” | press | 2026-06-21 |
| s3 | [SandboxAQ: Redefines Cybersecurity with Unified Cryptography Management](https://www.sandboxaq.com/post/sandboxaq-redefines-cybersecurity-with-unified-cryptography-management) “integrations ... including Tanium, ServiceNow and others ... training cybersecurity teams at Accenture, Deloitte, EY and Carahsoft to deploy AQtive Guard ... affiliations with prominent industry consortiums such as NIST's NCCoE, the GSMA's PQTN, the Linux Foundation's PQCA, and MITRE's PQC.” | official | 2026-06-21 |
| s4 | [SandboxAQ AQtive Guard product page (orchestration)](https://www.aqtiveguard.com/) “Certificate outages cost up to $9,000/minute. ... Confidently orchestrate safe key rotations, algorithm replacements, and PQC migrations without breaking production. ... Network analysis and runtime tracing reveal what's actively running in production.” | official | 2026-06-21 |
| s5 | [The Quantum Insider: SandboxAQ Partners with DoW CIO](https://thequantuminsider.com/2025/12/11/sandboxaq-dow-cryptography-modernization/) “SandboxAQ is partnering with the Department of War (DoW) CIO to deploy its AQtive Guard platform for automated discovery and inventory of cryptographic assets ... builds on SandboxAQ's prior success with DISA Emerging Technology's QRC PKI program.” | press | 2026-06-21 |
| s6 | [SandboxAQ: Closes $450M Series E Round with Expanded Investor Base](https://www.sandboxaq.com/press/sandboxaq-closes-450m-series-e-round-with-expanded-investor-base) “SandboxAQ ... announced the addition of Ray Dalio, Horizon Kinetics, BNP Paribas, Google, and NVIDIA to its Series E funding round, which raised over $450 million. Since spinning out from Alphabet in 2022, SandboxAQ has raised over $950 million.” | official | 2026-06-21 |
| s7 | [PYMNTS: SandboxAQ Raises $450 Million for Quantitative AI Platforms](https://www.pymnts.com/news/investment-tracker/2025/nvidia-and-google-backed-sandboxaq-raises-450-million-for-quantitative-ai-platforms/) “Since spinning out from Alphabet in 2022, the company has raised over $950 million, SandboxAQ said in a Friday (April 4) press release.” | press | 2026-06-21 |
| s8 | [NIST NCCoE: Migration to Post-Quantum Cryptography consortium](https://www.nccoe.nist.gov/applied-cryptography/migration-to-pqc) “Organizations participating in this project ... signed a Cooperative Research and Development Agreement to collaborate with NIST in a consortium to build this example solution. ... SandboxAQ” | research | 2026-06-30 |
| s9 | [FedRAMP Marketplace: AQtive Guard listing FR260215856](https://www.fedramp.gov/marketplace/products/FR260215856/) “SandboxAQ AQtive Guard Package ID FR260215856 ... Status ... FedRAMP Ready ... Certification Class ... Class C (Moderate)” | regulatory | 2026-06-30 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [SandboxAQ AQtive Guard product page](https://www.aqtiveguard.com/) “Legacy PKI tools only see what they manage. AQtive Guard correlates data across code, runtime, and the network. Discover every managed certificate, hidden algorithm, and shadow key with zero manual effort.” | official | 2026-06-21 |
| s2 | [PR Newswire: SandboxAQ Achieves FedRAMP Ready Status](https://www.prnewswire.com/news-releases/sandboxaq-achieves-fedramp-ready-status-powering-enterprise-readiness-across-the-defense-and-public-sector-302632552.html) “SandboxAQ ... has achieved Federal Risk and Authorization Management Program (FedRAMP) Ready status ... AQtive Guard provides ... remediation of critical vulnerabilities stemming from weak encryption and ... non-human identities (NHIs) ... the SOC 2 Type I report and the ISO/IEC 27001 certificate.” | press | 2026-06-21 |
| s3 | [SandboxAQ: Redefines Cybersecurity with Unified Cryptography Management](https://www.sandboxaq.com/post/sandboxaq-redefines-cybersecurity-with-unified-cryptography-management) “single sign-on integration, audit logging, horizontal scaling, high availability ... integrations ... including Tanium, ServiceNow ... teams at Accenture, Deloitte, EY and Carahsoft ... affiliations with ... NIST's NCCoE, the GSMA's PQTN, the Linux Foundation's PQCA, and MITRE's PQC Coalition.” | official | 2026-06-21 |
| s4 | [SandboxAQ AQtive Guard product page (orchestration)](https://www.aqtiveguard.com/) “Certificate outages cost up to $9,000/minute. ... Confidently orchestrate safe key rotations, algorithm replacements, and PQC migrations without breaking production. ... Network analysis and runtime tracing reveal what's actively running in production.” | official | 2026-06-21 |
| s5 | [The Quantum Insider: SandboxAQ Partners with DoW CIO](https://thequantuminsider.com/2025/12/11/sandboxaq-dow-cryptography-modernization/) “SandboxAQ is partnering with the Department of War (DoW) CIO to deploy its AQtive Guard platform for automated discovery and inventory of cryptographic assets ... builds on SandboxAQ's prior success with DISA Emerging Technology's QRC PKI program.” | press | 2026-06-21 |
| s6 | [SandboxAQ: Closes $450M Series E Round with Expanded Investor Base](https://www.sandboxaq.com/press/sandboxaq-closes-450m-series-e-round-with-expanded-investor-base) “SandboxAQ ... announced the addition of Ray Dalio, Horizon Kinetics, BNP Paribas, Google, and NVIDIA to its Series E ... Since spinning out from Alphabet in 2022, SandboxAQ has raised over $950 million ... across biopharma, chemistry, materials science, cybersecurity, and financial services.” | official | 2026-06-21 |
| s7 | [PYMNTS: SandboxAQ Raises $450 Million for Quantitative AI Platforms](https://www.pymnts.com/news/investment-tracker/2025/nvidia-and-google-backed-sandboxaq-raises-450-million-for-quantitative-ai-platforms/) “Since spinning out from Alphabet in 2022, the company has raised over $950 million, SandboxAQ said in a Friday (April 4) press release.” | press | 2026-06-21 |
| s8 | [NIST NCCoE: Migration to Post-Quantum Cryptography consortium](https://www.nccoe.nist.gov/applied-cryptography/migration-to-pqc) “Organizations participating in this project ... signed a Cooperative Research and Development Agreement to collaborate with NIST in a consortium to build this example solution. ... SandboxAQ” | research | 2026-06-30 |
| s9 | [FedRAMP Marketplace: AQtive Guard listing FR260215856](https://www.fedramp.gov/marketplace/products/FR260215856/) “SandboxAQ AQtive Guard Package ID FR260215856 ... Status ... FedRAMP Ready ... Certification Class ... Class C (Moderate)” | regulatory | 2026-06-30 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
