Profile.
Schema, cardinality, distributions and constraints are profiled in place, behind the data boundary. Nothing is copied out at this stage.

The Counterpart Engine ships today. The other three are in build or pilot, and each module states its own state and boundary rather than borrowing the suite’s.
The PQC Gateway terminates and re-establishes traffic with hybrid classical and post-quantum key establishment, so traffic captured today does not become readable once a quantum-capable attacker exists.
Negotiation records per session, a key rotation history, and a per-zone suite policy with the exceptions that were granted.
The gateway protects transport only. It does not classify data, does not replace endpoint or identity controls, and cannot protect an exchange that should not have happened.
The Counterpart Engine reads schema and distributions behind the data boundary and produces relational and tabular counterparts, with utility measured separately for each task they are meant to support.
Methods, parameters, results and limitations per release, under a release identifier that stays inspectable afterwards.
Current scope is relational and tabular data. Complete behavioural replication of an enterprise system is not a current product claim, and testing cannot prove the absence of every future attack.
Policy Orchestration holds which privacy model, which approval and which retention period apply to a workload, and refuses releases that do not meet them.
A decision log with policy version, approver, timestamp and the evidence bundle that was accepted.
Holds metadata and decisions only. No production records and no key material pass through it, and it cannot enforce a policy that was never written down.
Adapters attach the suite to databases, message buses, key vaults, CI pipelines and analytics environments, so adoption does not begin with a migration project.
A connection inventory with scope, credentials model and the data classes each adapter is permitted to touch.
Relational sources are in pilot scope first. Message-bus and telemetry adapters are design-partner work and are not contractable today.
Schema, cardinality, distributions and constraints are profiled in place, behind the data boundary. Nothing is copied out at this stage.
Production rows stay in the source zone; only a statistical profile is retained.
Counterparts are generated against the declared privacy model, preserving referential integrity across tables so applications behave as they do against production.
Generation runs inside the same zone as the source system.
Structural fidelity, statistical fidelity and downstream task performance are measured separately, and limitations are written down where a counterpart is not fit for a purpose.
Measurement reads the counterpart and the profile, not the production records.
The accepted counterpart leaves with its evidence record: methods, parameters, results, limitations and a release identifier that stays inspectable.
Only the counterpart and its evidence record cross the boundary.

Bring the workload, data boundary and decision the evidence must support.