All posts

Vendor Risk Brief

The Vendor Pitch That Should Cost Them Points: “Proprietary and Patent-Pending”

August 10, 2026 ·  PQCClear  ·  2 minute read

Somewhere in your vendor portfolio, there's probably a pitch deck with the phrase “mathematically proven unbreakable” in it. It's one of the most common claims in the post-quantum vendor market right now, and it should be one of the easiest to disqualify.

The Rule Is Simple Enough to State in One Sentence

If an algorithm hasn’t gone through NIST or a national cryptographic authority’s standardization process, it hasn’t been tested. It is just unbroken so far, which is a much weaker claim than the marketing implies. No demo, patent filing, or whitepaper changes that.

The reason the rule holds isn’t intuition. It’s a long, well-documented track record.

The Graveyard Is Longer Than Most Pitches Admit

History hasn’t been kind to proprietary cryptography.

  1. 1982

    The 1978 knapsack cipher is broken on stage

    Designed by two of public-key cryptography's own founders, it was broken live at a conference, on an Apple II, in front of an audience.

  2. 2007

    SFLASH falls after four years inside a standards process

    A European standards process had recommended it in 2003. A single 2007 paper ended it.

  3. 2017–2018

    A third of NIST's first-round field disappears

    Roughly a third of the 69 first-round post-quantum candidates were broken or withdrawn within months of submission.

  4. Feb 2022

    Rainbow, a NIST finalist, is broken

    Not despite years of open scrutiny, but because of them. The break came from the process working as intended.

  5. Jul 2022

    SIKE is broken on a single classical core

    A fourth-round NIST candidate, undone in about an hour by a line of attack its designers had not anticipated.

“Nobody has cracked it” measures exactly one thing: how hard anyone has actually tried. For an algorithm no cryptanalyst has ever seen, the honest answer is not at all.

How We Score It

When a vendor tells us they’re running a custom or proprietary protocol, or a bulk-encryption algorithm outside the standard list, we don’t treat it as a defensible middle option. It scores at the floor of our model, the same tier as practices that are already broken today, like 3DES.

We also require the vendor to document the actual mechanism: protocol name, key-establishment method, and the specific algorithms involved. “Proprietary” doesn’t get to stand in as its own credential.

What This Means for Your Vendor List

We don’t decide what’s cryptographically safe. NIST, national cryptographic authorities, and years of open, adversarial cryptanalysis do that. Our job is making sure a vendor who skipped that process entirely doesn’t quietly average out to a passing score on your next assessment.

See where your vendors actually stand

PQCClear assesses the quantum readiness of every fintech vendor in your portfolio: a PQC Readiness Score, a full CBOM, and an examination-ready report for each one.

Request access
proprietary encryption riskcustom cryptography vendor scoringNIST standardizationpost quantum third party risk management

This post represents the editorial view of PQCClear as of August 10, 2026. It should not be construed as legal or cryptographic advice.

Key sources: cryptanalysis of the Merkle-Hellman knapsack cryptosystem (Crypto ’82); differential cryptanalysis of SFLASH, a NESSIE recommendation (Crypto 2007); NIST post-quantum cryptography standardization first-round status reports; the 2022 breaks of Rainbow and SIKE; NIST FIPS 203/204/205 (August 2024).