Post-quantum TLS hosting.
Check it yourself in one command.

Every site we host negotiates the hybrid X25519MLKEM768 key exchange with clients that support it, so traffic recorded today stays protected against tomorrow's quantum attacks. Hosting from $3 a month, with the same edge in front of our servers and backup vaults.

X25519MLKEM768 on every serviceFalls back cleanlyPrice locked at signup
example.com ยท TLS sessionpost-quantum
Protocol
TLS 1.3
Key exchange
X25519MLKEM768
Classic part
X25519
Post-quantum part
ML-KEM-768
Certificate
Auto-issued, renewed
Older clients
Standard TLS 1.3
Website hostingedgePQ
Server portal and paneledgePQ
Backup vault endpointsedgePQ
The same hybrid group across hosting, servers and backups

The threat

Harvest now, decrypt later, in plain terms.

Every HTTPS connection starts with a key exchange: your browser and the server agree on a secret key without ever sending it across the network. For years that exchange has relied on elliptic-curve math, most often X25519. A large enough quantum computer would solve that math efficiently. Nobody has built one yet, but that is not the point.

The point is that encrypted traffic can be recorded today and kept. If someone captures the handshake and the session now, they can decrypt it later, once the key exchange is breakable. This is called harvest now, decrypt later. It matters most for anything that stays sensitive for years: login credentials that never get rotated, client records, legal and medical correspondence, private business data, and admin sessions to the systems that hold all of it.

The fix is to change the key exchange before that day comes, so that recordings made today are worthless later. That is what post-quantum TLS does.

What X25519MLKEM768 actually is

X25519MLKEM768 is a hybrid key exchange. It runs two algorithms side by side and mixes their results into one session key:

  • X25519, the classic elliptic-curve exchange that browsers already trust.
  • ML-KEM-768, a lattice-based key encapsulation mechanism standardized by NIST in 2024 as FIPS 203, designed to resist quantum attacks.

Because the session key depends on both, an attacker has to break both. If ML-KEM ever turned out to have a flaw, X25519 still protects you exactly as well as standard TLS does today. If a quantum computer arrives, ML-KEM still stands. You lose nothing by running the hybrid, and current Chrome, Edge and Firefox releases offer it by default.

Do not take our word for it.

Claims about encryption are easy to make. This one takes a single command to check. With OpenSSL 3.5 or newer, ask our server to use only the hybrid group:

openssl 3.5
$openssl version
$openssl s_client -groups X25519MLKEM768 -connect servercrate.net:443 </dev/null 2>/dev/null | grep -i 'group'
Negotiated TLS1.3 group: X25519MLKEM768

That last line is the one that matters: the server accepted the post-quantum hybrid. If a server does not support it, the handshake fails instead, because you offered nothing else. Point the same command at your own hosted domain once it is live.

In a browser, open Chrome DevTools, choose the Security panel and look at the connection details for the page. The key exchange shows as X25519MLKEM768. If the security panel is hidden, enable it from the DevTools menu under More tools.

Where we run it, and what it does not cover.

ServicePost-quantum TLSNotes
Website hostingYes, every siteTerminated at our edge with automatically issued certificates
Cloud server portal and panelYesLogins, billing and the browser console travel over the hybrid exchange
Our public edge and websiteYesservercrate.net and the portal
Backup vault endpointsYesRestic over REST uploads use the same edge
Data at restNot applicableProtected with AES-256; backups are also encrypted on your machine first
SSH to your own cloud serverDepends on your OSSet by the OpenSSH version your chosen distribution ships
Services you run on your own serverYour configurationUse OpenSSL 3.5+ or a TLS library with ML-KEM support to match

Post-quantum TLS protects data in transit between a client and our edge. It is one layer, not the whole story. Read our security overview for the rest, and our recovery drill for how restores work when something does go wrong.

Website hosting plans.

Post-quantum TLS on every site, on every plan. Yearly billing is 10 times monthly, two months free. Renewal is always your signup price, with a 30-day money-back guarantee.

Mini
$3/mo
  • 1 website
  • 5 GB NVMe storage
  • Post-quantum TLS on every site
  • Free certificates
  • $30/yr billed yearly, 2 months free
Solo
$5/mo
  • 3 websites
  • 20 GB NVMe storage
  • Post-quantum TLS on every site
  • Free certificates
  • $50/yr billed yearly, 2 months free
Studio
$10/mo
  • 10 websites
  • 50 GB NVMe storage
  • Post-quantum TLS on every site
  • Free certificates
  • $100/yr billed yearly, 2 months free
Agency
$20/mo
  • 25 websites
  • 150 GB NVMe storage
  • Post-quantum TLS on every site
  • Free certificates
  • $200/yr billed yearly, 2 months free

Need more than a website? The same edge sits in front of our Los Angeles cloud servers from $3 a month and our encrypted backup vaults from $2 a month: Lite 100 GB for $2, Starter 250 GB for $3, Standard 1 TB for $9 and Pro 2 TB for $17. Compare everything on pricing, or read more about web hosting and cloud servers.

Post-quantum TLS questions.

What is harvest now, decrypt later?

It is the practice of recording encrypted traffic today and storing it until a future quantum computer is able to break the key exchange that protected it. Anything still sensitive years from now is exposed, even though nothing looks wrong today.

What is X25519MLKEM768?

A hybrid TLS key exchange that combines classic X25519 with ML-KEM-768, the post-quantum algorithm standardized by NIST as FIPS 203. The session key depends on both, so an attacker would have to break both to read the traffic.

How do I check it myself?

With OpenSSL 3.5 or newer, run openssl s_client -groups X25519MLKEM768 -connect servercrate.net:443 and look for Negotiated TLS1.3 group: X25519MLKEM768. In Chrome, open DevTools, go to the Security panel and read the key exchange for the connection.

Which ServerCrate services use it?

Website hosting, the cloud server portal and panel, our public edge, and the backup vault endpoints. Post-quantum TLS is on every service we run.

Does it encrypt my files on disk?

No. TLS protects data in transit. Data at rest is protected separately with AES-256, and our backup vaults store data that is already encrypted on your machine before upload.

Does it cover SSH to my own server?

No. SSH on a cloud server is controlled by the operating system you install and its OpenSSH version. Recent OpenSSH releases include post-quantum hybrid key exchange, so check what your OS ships.

What happens to old browsers?

Clients that do not support the hybrid group fall back to standard TLS 1.3 key exchange. Your site keeps working for everyone.