Company News
Nobody Is Reading Your Data Tonight.That Is the Problem.
Why the bottlenecks of the AI and quantum era are physics problems, and what Physivitis is doing about them.
It is a little after two in the morning in a data centre you will never visit.
The cold aisle is louder than people expect. Thousands of fans push chilled air across rack after rack of blinking lights, and somewhere inside that noise a stream of your organisation’s encrypted traffic is being copied. Nobody is attacking it. Nobody is trying to open it. It is simply being copied and put somewhere safe, by someone who is in no hurry at all.
They will not read it this year, and probably not next year either. They are not waiting for a password. They are waiting for a machine.
I know how that sounds. It sounds like a security problem, the kind you fix with better tooling and a bigger budget.
But it is not really a security problem, and it took me a while to find a simple way of explaining why. The mathematics protecting that stream rests on a physical assumption: that no machine on Earth can factor a large enough number in any useful amount of time. A large enough quantum computer does not weaken that assumption; it takes it away altogether. So no firewall, policy or audit can help, because none of them changes the physics of how the information is protected. The only thing that helps is changing the physics.
That is one bottleneck. In my experience the AI and quantum era has three, and they share the same root.
What I could not walk past
Let me tell you what bothers me, because it is honestly why Physivitis exists.
It bothers me to watch organisations spend serious money engineering around a limit that was set by a law of nature, because the workaround was never going to hold. It bothers me when someone says “we will scale our way out of this” when scale is the very thing that is failing. And it bothers me most that the people who are told “it is fine, we follow best practice” tend to be the ones left holding the cost when it turns out not to be fine.
I am a physicist, and I am passionate about what happens at the point where physics meets industry. Over the years I kept noticing the same pattern. Every industry pushing into AI and quantum runs into the same three walls. It needs to be secure enough, scalable enough and efficient enough, and it cannot yet manage all three at once. Each time I looked underneath the problem, the cause was not in the software. It sat below the software: in how information is protected, in how computation scales, in how energy moves.
Those are not engineering questions. They are physics questions. And it is in trying to address those challenges, with physics rather than workarounds, that Physivitis was born.
Wall one: secure enough
Let me go back to the data centre.
Something that surprised me when I first started looking closely: most organisations cannot list the cryptography they run. Not roughly, not at all. It lives in certificates, libraries, firmware, third-party code, and in a keystore that somebody set up years ago and then moved on from. You cannot migrate what you cannot see.
So the first thing we built was not a fix at all. It was a torch. CETI-VCC discovers every piece of cryptography an organisation runs and turns it into a verified inventory with a confidence score attached, so that the first honest question, “where are we exposed?”, finally has an answer.
But an inventory is not a decision, and a board cannot act on a list. Cryptographic strength, entropy quality, implementation evidence, protocol behaviour and architectural exposure have each had their own metric for years, and those metrics were never designed to combine. USMC is, to the best of our knowledge, the first tool to bring them together into a single assurance result and, where the evidence supports it, an estimated security margin in bits against the 128-bit post-quantum threshold. When the evidence is too thin to judge, USMC says “insufficient evidence” instead of inventing a verdict. We built that in on purpose, because a confident wrong answer is worse than an honest one.
But knowing you are exposed is not the same as being safe. So CADRE turns the assessment into a migration a team can actually carry out. Dependencies are tested rather than assumed, the work is sequenced into waves, every change can be rolled back, and the assurance is measured again after each wave. Discover, assess, migrate. That suite is live today, and it is the part of our work I can point to most easily.
The same way of thinking has taken us well beyond cryptography. TCBA audits an AI model before it is trusted. A separate framework checks that an AI agent actually holds the authority it claims before it is allowed to touch anything that matters. Another watches the API layer, where machines talk to machines, for signs of a breach. And QABRE scores how a blockchain network holds up under attack, including the quantum-era attacks it was never designed to meet.
Wall two: scalable enough
Now step out of the data centre and into a quantum lab.
It is quiet here, and cold in a completely different way. At the bottom of a cryostat, colder than deep space, a processor is trying to hold a computation together. What most people outside the field do not realise is that the enemy of that computation is not a hacker. It is a detector that fires when no photon arrived. A signal that drifts by a fraction of a degree. A component that behaves a little differently today than it did yesterday.
Quantum computing is not struggling to scale because the engineers are not clever enough. It is struggling because the hardware sits right up against physical limits that nobody has measured precisely enough to design around. So that is where we work. QUDL calibrates the detectors that quantum and photonic systems depend on, so that what the machine reports is what actually happened. Around it sits a body of work on the hardware limits of quantum computers themselves, and on quantum sensing, where the same physics stops being a problem and becomes a product.
AI has its own version of this wall. An organisation can deploy ten agents by watching them closely. It cannot deploy ten thousand until it can verify each one before it is trusted. That is why the model audit and the agent verification work sit in the same portfolio as the quantum work: in both cases, scale is gated by verification.
Wall three: efficient enough
The third wall is the one you can see on an invoice.
Picture a training run. Weeks long, a building full of accelerators drawing power like a small town. The part nobody puts in the brochure is that a large share of that energy is spent carrying precision the model does not need. Every number is stored with more bits than the calculation calls for, and every unnecessary bit ends up as heat.
That is not a budgeting problem. It is a physics problem: how much energy does it cost to move and multiply a number, and how few bits can you use before the answer falls apart? SLATE is our answer, a method that cuts the cost of training AI at very low precision without the training collapsing. We published it openly, because a bottleneck that big should not be one company’s secret.
And energy is not only about compute. PBPF-IDO is a battery design tool built on the physics of how energy is stored and released, so the people designing the next generation of cells can start from the laws that govern them rather than from trial and error.
How we work
People sometimes ask how one company ends up working across cryptography, AI, quantum hardware and energy at the same time. The honest answer is that, from where I sit, they are not four fields. They are one field, physics, showing up as four expensive symptoms.
Every innovation goes through the same five stages. Identify a genuine gap in the physics behind an industry bottleneck. Theorise what mathematical structure a solution must have. Synthesise across disciplines to find the connection others miss. Develop and validate the framework, then protect it with a patent filing. Discover the commercial applications and take it to market, as software where it can run today and as licensed IP where it depends on specialist hardware.
Eighteen UK patent filings have come out of that engine so far, along with a live post-quantum security suite and membership of NVIDIA Inception. And two rules we do not bend: measure, do not assume; and say when we do not know.
The floor
So, the ending.
Every technology stack has a floor. Below the applications, below the frameworks, below the cloud, there is a layer where the rules are not written by developers. They are written by nature: how much information a channel can protect, how much computation a device can hold together, how much energy a calculation must cost. Most companies build on that floor and hope it holds.
Physivitis builds the floor.
That is the space we intend to occupy: the layers and tools beneath the software that industries will need before they can take the next step into the AI and quantum era, whether or not they know it yet. Not the app, not the dashboard, but the physics underneath, turned into something a team can actually put to work.
The limits are real. But they are physics limits, and physics limits can be moved.
Where the same approach has already taken us
Some of the walls we have worked on so far, using the same five stages each time (innovation names are given in their short form by house rule):
Secure enough
- CETI-VCC, USMC and CADRE: the live post-quantum suite; discover, assess, migrate.
- TCBA: auditing an AI model before it is trusted.
- QABRE: scoring how a blockchain network holds up under attack.
- PSMB: quantum-era security with an embodiment for central bank digital currencies.
- QCTS: our foundational quantum cybersecurity framework.
- A framework for detecting breaches at the API layer, where machines talk to machines.
- A framework that verifies an AI agent’s authority before a sensitive action is allowed to execute.
- A hardware-backed safeguard for drones and robots, so that a protected command is not carried out unless every stated condition passes.
Scalable enough
- QUDL: calibrating the detectors that quantum and photonic systems rely on.
- DFCBL: further work on quantum photodetection.
- CMDM and CFMDI: work on the hardware limits of quantum computers.
Efficient enough
- SLATE: cutting the cost of training AI at very low precision, published openly.
- IGTR: a second line of work on AI training.
- SARC: tensor compute designed to keep its answers correct while running at reduced voltage.
- PBPF-IDO: battery design from the physics of the cell.
Our vision is a world where no industry is held back by a problem physics has already solved. If your organisation is up against one of these walls, or one we have not met yet, I would like to hear about it.
Up against one of these walls?
If the bottleneck your organisation faces is a physics problem, we would like to hear about it.
Talk to PhysivitisPhysivitis Ltd · Deep-Tech IP and Software for the AI and Quantum Era · London