Vendor Risk Brief
The Vendor Pitch That Should Cost Them Points: “Proprietary and Patent-Pending”
August 10, 2026 · PQCClear · 2 minute read
Somewhere in your vendor portfolio, there's probably a pitch deck with the phrase “mathematically proven unbreakable” in it. It's one of the most common claims in the post-quantum vendor market right now, and it should be one of the easiest to disqualify.
The Rule Is Simple Enough to State in One Sentence
If an algorithm hasn’t gone through NIST or a national cryptographic authority’s standardization process, it hasn’t been tested. It is just unbroken so far, which is a much weaker claim than the marketing implies. No demo, patent filing, or whitepaper changes that.
The reason the rule holds isn’t intuition. It’s a long, well-documented track record.
The Graveyard Is Longer Than Most Pitches Admit
History hasn’t been kind to proprietary cryptography.
1982
The 1978 knapsack cipher is broken on stage
Designed by two of public-key cryptography's own founders, it was broken live at a conference, on an Apple II, in front of an audience.
2007
SFLASH falls after four years inside a standards process
A European standards process had recommended it in 2003. A single 2007 paper ended it.
2017–2018
A third of NIST's first-round field disappears
Roughly a third of the 69 first-round post-quantum candidates were broken or withdrawn within months of submission.
Feb 2022
Rainbow, a NIST finalist, is broken
Not despite years of open scrutiny, but because of them. The break came from the process working as intended.
Jul 2022
SIKE is broken on a single classical core
A fourth-round NIST candidate, undone in about an hour by a line of attack its designers had not anticipated.
“Nobody has cracked it” measures exactly one thing: how hard anyone has actually tried. For an algorithm no cryptanalyst has ever seen, the honest answer is not at all.
How We Score It
When a vendor tells us they’re running a custom or proprietary protocol, or a bulk-encryption algorithm outside the standard list, we don’t treat it as a defensible middle option. It scores at the floor of our model, the same tier as practices that are already broken today, like 3DES.
We also require the vendor to document the actual mechanism: protocol name, key-establishment method, and the specific algorithms involved. “Proprietary” doesn’t get to stand in as its own credential.
What This Means for Your Vendor List
We don’t decide what’s cryptographically safe. NIST, national cryptographic authorities, and years of open, adversarial cryptanalysis do that. Our job is making sure a vendor who skipped that process entirely doesn’t quietly average out to a passing score on your next assessment.
See where your vendors actually stand
PQCClear assesses the quantum readiness of every fintech vendor in your portfolio: a PQC Readiness Score, a full CBOM, and an examination-ready report for each one.
Request accessThis post represents the editorial view of PQCClear as of August 10, 2026. It should not be construed as legal or cryptographic advice.
Key sources: cryptanalysis of the Merkle-Hellman knapsack cryptosystem (Crypto ’82); differential cryptanalysis of SFLASH, a NESSIE recommendation (Crypto 2007); NIST post-quantum cryptography standardization first-round status reports; the 2022 breaks of Rainbow and SIKE; NIST FIPS 203/204/205 (August 2024).