# Message test — https://quantumnetwork.ch/

After reading your page, only 7 of 15 personas could name a reason to pick you over a similar option.

- **Page tested:** https://quantumnetwork.ch/
- **Audience tested against:** critical infrastructure managers, ciso's and head of IT, who are aware that sending data over the open internet is deemed dangerous. data can get intercepted, changed or stolen.
- **Personas:** 15 simulated
- **Report:** https://grader.wynter.com/r/quantum-network-WVG0QMg

> These answers are generated by AI, scored on Wynter's B2B Message
> Layers framework using behaviorally-diverse simulated personas. The
> methodology is real and the critique is directional. What a simulated
> persona cannot have is a live budget, a renewal coming up, or a boss
> asking about this quarter.

---

## 01 · The scores

Every persona answered all four questions. These are four independent
proportions of the same panel, not stages of a funnel.

| Layer | Question | Cleared the bar | Strength | Of those who passed |
| --- | --- | --- | --- | --- |
| 1. Clarity | Do they understand what you do? | 15/15 | 85% | 5 without hesitation, 10 with reservations |
| 2. Relevance | Can they tell what it solves, and who it's for? | 15/15 | 84% | 4 without hesitation, 11 with reservations |
| 3. Value | Do they actually want it? | 13/15 | 70% | all with reservations |
| 4. Differentiation | Is there a reason to pick you over the alternatives? | 7/15 | 48% | all with reservations |

**Brand alignment** (a side metric, not one of the four layers) — 10/15, 62% strength (all with reservations). Does the page read like the company you actually are?

**Fix first: Differentiation.** Earliest failing layer, walking the sequence in order — not simply the lowest score.

---

## 02 · What to change, layer by layer

Ordered worst-first. Specific edits, not a restatement of the score.

### Differentiation

**Add a comparison line under the three deployment modes naming what rivals require.**

Mixing physical, virtual and client gateways in one network is the strongest claim on the page, but nothing says competitors cannot do it. Write that single-topology and cloud-managed VPNs force endpoint or firewall changes, while QPN needs only route edits.

*effort medium · impact high · tested against Give a reason to choose you*

**Add test conditions and hardware beside the one-millisecond latency line.**

The page claims "a typical latency of one millisecond on the protected line" with no test setup behind it, so readers treat it as marketing. State the link type, packet size, throughput and gateway model measured.

*effort low · impact high · tested against Proof next to the claim*

**Define crypto-agile in one sentence where the term first appears.**

"Our gateways are crypto-agile: when the standards move, the software moves" does not say what actually changes or how. Name the algorithm swap as a signed software update, with no hardware or endpoint changes.

*effort low · impact high · tested against Plain language*

### Value

**Name the buyer role in the hero subhead instead of "your network".**

OT and utility operators are only inferred from the SCADA diagrams further down. Say in the opening lines that this is for teams protecting SCADA and control traffic across sites over the public internet.

*effort low · impact medium · tested against Name the audience*

**Replace "Talk to an expert" so one action leads the hero.**

"Get my proposal" and "Talk to an expert" compete before the reader knows what the gateway is. Keep the proposal button primary and demote the other to a text link.

*effort low · impact medium · tested against One clear next action*

### Brand alignment (side metric)

**Add a deployment reference block after the diagrams with sector, site count and duration.**

Nothing on the page shows the gateway running in a real utility or OT network, so it reads as untested. Add an anonymised reference such as sector, number of protected sites and months in production.

*effort medium · impact high · tested against Proof next to the claim*

**State security testing and certification status near the NIST FIPS-203 line.**

Buyers in critical infrastructure need to know who has audited the box, and the page leaves it blank. Say what independent pen-test or certification work exists, or is in progress with a date.

*effort medium · impact high · tested against Answer the live objection*

**Relabel the logo strip to say what each partner supplies.**

A bare row of Red Hat, Advantech, OnLogic and NIST logos reads as a young vendor borrowing other names. Label them as certified hardware platforms, supported Linux distributions and the standards body behind ML-KEM.

*effort low · impact medium · tested against Proof next to the claim*

---

## 03 · What is working

### The core product description lands: a post-quantum encryption gateway for SCADA that…

Five points restated the offer accurately and unprompted as a NIST ML-KEM site-to-site gateway protecting SCADA over the internet without hardware replacement. The no-rip-and-replace framing was read as the concrete value.

> They sell a hardware gateway box you drop into your existing network stack, in front of or behind your firewall, that encrypts traffic between two sites so anyone intercepting it on the public internet just gets ciphertext — basically a quantum-resistant VPN/encryption appliance for SCADA and OT links.
> 
> — Infrastructure Manager, Energy and Utilities, 1001-5000

> I get quantum-resistant encryption on my inter-site and remote-access links without touching SCADA, PLCs or firewalls — that's a real gap closed, since "harvest now, decrypt later" against a water utility is a genuine board-level risk
> 
> — Chief Information Security Officer, Water Management, 501-1000

> quantum-safe encryption for existing networks, no hardware swap. Reader's inferred - OT/SCADA operators, from "SCADA and dispatch" diagram.
> 
> — IT Director, Energy and Utilities, 501-1000

### The page names its audience in seconds through SCADA imagery and OT use cases

Seven points said the header, diagrams and named use cases make OT and critical-infrastructure operators the obvious audience, not generic enterprise IT. Two noted the audience is inferred from visuals rather than stated outright.

> The problem is spelled out too: "Traffic can be read, changed or stored" over public internet, which is precisely the SCADA-over-internet exposure I deal with.
> 
> — Infrastructure Manager, Energy and Utilities, 1001-5000

> the diagram right after with the control room, SCADA, PLCs, sensors, cameras spelled out who this is for even before they said it explicitly
> 
> — Critical Infrastructure Manager, Transportation and Logistics, 5000+

> The named use cases — solar parks, container ports, airport control towers, water treatment plants, SCADA/OT environments — make it obvious this is aimed at critical infrastructure and industrial network operators, not a generic enterprise IT buyer
> 
> — Head of IT, Government and Defense, 5000+

> It was obvious fast — the hero line "Protect your network with quantum-safe encryption, without replacing your existing hardware" plus the diagram with control room, PLCs, SCADA and "Your machines... all unchanged" told me within seconds this is for OT/critical-infrastructure operators
> 
> — Infrastructure Manager, Transportation and Logistics, 1001-5000

> the header line "Protect your network with quantum-safe encryption, without replacing your existing hardware" tells you the problem (quantum-era encryption risk on existing infra) and the fix in one sentence, and the SCADA/control-room diagram with "Solar park, Container port, Airport control tower, Water treatment plant" makes it obvious this is aimed at critical infrastructure / OT operators
> 
> — Critical Infrastructure Manager, Water Management, 5000+

> The intended reader isn't spelled out in a sentence like "for CISOs at utilities" — I inferred it from the imagery: solar parks, container ports, airport control towers, water treatment plants, SCADA.
> 
> — CISO, Government and Defense, 1001-5000

### Deployment flexibility, no endpoint touches and offline operation separate the product…

Four points named multi-topology deployment, avoiding endpoint and firewall changes, and no-telemetry offline capability as differentiation against single-topology and cloud-managed rivals. One added that unproven latency undercuts the position.

> The "combinable deployment modes" line — site-to-site, edge-to-cloud, and remote client gateways all sitting in the same QPN — is the one concrete differentiator here, because most competitors force you into one topology
> 
> — Chief Information Security Officer, Water Management, 501-1000

> The "drop it in front of or behind your existing firewall, adjusting a few network routes, without touching servers, clients or applications" line is the thing that would actually pull me toward this one over a rival — that's a concrete deployment claim, not just a slogan, and it maps to a real procurement fear (rip-and-replace risk)
> 
> — Head of IT, Government and Defense, 5000+

> The thing that would tip it toward a shortlist call rather than a tab-close is the "physical gateways, virtual gateways and software clients can be combined within the same QPN" line plus the three named deployment modes — site-to-site, edge-to-cloud, remote access. That's concrete enough to mean we could pilot on one port/SCADA link without committing our whole topology to it
> 
> — Infrastructure Manager, Transportation and Logistics, 1001-5000

> The "no telemetry, no cloud dependency" line and the claim it can run on private networks and offline OT environments is what would push it up my shortlist over a cloud-managed competitor
> 
> — Critical Infrastructure Manager, Water Management, 5000+

### NIST FIPS-203/ML-KEM standardization and crypto-agility are the differentiators…

Four points cited the NIST ML-KEM standard as verifiable and concrete, and crypto-agility as closing a real IPsec risk by avoiding re-architecting when standards rotate. These were the claims respondents repeated back.

> I'd need the NIST FIPS-203 compliance and a reference deployment in a comparable water/OT environment before this goes anywhere near budget
> 
> — Critical Infrastructure Manager, Water Management, 5000+

> The one concrete thing that would keep them on the shortlist is the NIST FIPS-203/ML-KEM standardization line — that's a real, checkable technical detail, not marketing fluff
> 
> — Critical Infrastructure Manager, Transportation and Logistics, 5000+

> the "crypto-agile" pitch means I'm not re-architecting again in five years when NIST rotates ML-KEM. That's worth a technical call
> 
> — Head of IT, Government and Defense, 5000+

---

## 04 · What the personas said

### "Crypto-agile" reads as marketing shorthand without an engineering definition

Two points said the term is undefined and that vague operational detail on firmware updates undermines the crypto-agility claim rather than supporting it.

> don't tell me what a firmware update actually requires: downtime, a truck roll, remote push? That vagueness is what stops me from calling it a settled category name
> 
> — Critical Infrastructure Manager, Transportation and Logistics, 5000+

> "crypto-agile" which sounds great but is never defined — agile how, does it need a firmware push, a config change, or a hardware swap when the standard changes?
> 
> — CISO, Telecommunications, 1001-5000

### No named customer blocks the deal, not just credibility

Seven points said the absence of named OT or utility references, independent certification and pen-test evidence stops progression past pilot and budget approval. Two called it a major weakness versus competitors.

> What would rule this vendor out, or at least drop them a slot, is the total absence of independent certification or a named reference deployment
> 
> — Head of IT, Government and Defense, 5000+

> it's the actual proof (latency numbers, deployment cost, who's already running it at OT scale) that's missing
> 
> — Infrastructure Manager, Energy and Utilities, 1001-5000

> I'd want them to map our actual stack and show me one existing OT customer reference before I'd let this near a live control network
> 
> — Critical Infrastructure Manager, Transportation and Logistics, 5000+

> the heavy reliance on logos (Red Hat, Advantech, OnLogic, NIST) instead of named customer case studies suggests they're still building credibility and don't yet have big reference logos of their own to show
> 
> — Infrastructure Manager, Transportation and Logistics, 1001-5000

> No named utility customers, so not worth a meeting yet.
> 
> — IT Director, Energy and Utilities, 501-1000

> A named reference customer running this on a port, airport or utility network, with a sourced number for latency and throughput under real OT traffic, plus a plain answer to how a crypto update is pushed and verified for audit — that would make it feel built for me rather than aimed at me.
> 
> — Infrastructure Manager, Transportation and Logistics, 1001-5000

> no third-party pen test, no named customer, no latency benchmark methodology behind that "one millisecond" number
> 
> — CISO, Telecommunications, 1001-5000

### The 1ms latency claim is disbelieved because no test conditions, methodology or…

Five points flagged the latency figure as specific but unsourced, with no benchmarking methodology, test conditions or reference deployment behind it. Several tied validated benchmarks directly to a pilot or budget decision.

> I need a reference deployment at OT scale, real latency test data under load, and a price point before I take this past a first call.
> 
> — Infrastructure Manager, Energy and Utilities, 1001-5000

> what's not proven is the "crypto-agile" claim and the 1ms latency figure — I'd want a reference deployment in a similar water/OT environment before I'd believe it holds under load
> 
> — Chief Information Security Officer, Water Management, 501-1000

> "1ms latency" claim is specific enough to matter, but no named utility deploying it - that rules it out for now.
> 
> — IT Director, Energy and Utilities, 501-1000

> But "typical latency of one millisecond" has no test conditions attached, and I still have no named customer or case study, so right now it's worth one technical call to get those specifics, not a purchase commitment.
> 
> — CISO, Government and Defense, 1001-5000

> A named critical-infrastructure or government deployment with a third-party validated latency/throughput benchmark under real traffic conditions — that's the single proof point that turns this from a sales page into something I'd put in front of my team for a pilot.
> 
> — CISO, Government and Defense, 1001-5000

### The partner logo wall reads as borrowed credibility from a small startup

Three points said the logo strip signals an early-stage vendor leaning on others' names rather than an established one, compounded by the missing case study. Two others read the page as a lean specialist software vendor without judging it.

> The naming of partners like Advantech, OnLogic and Red Hat/Ubuntu/SuSE/Debian as "industry-standard" hardware/OS support feels like a young company trying to borrow credibility by association rather than a Cisco or Thales who'd just say "runs on your existing infrastructure"
> 
> — Head of IT, Government and Defense, 5000+

> The Advantech/OnLogic/Red Hat/NIST logo strip is them borrowing credibility rather than having their own track record
> 
> — Head of IT, Energy and Utilities, 5000+

> smallish, engineering-heavy vendor — probably under a few hundred people, maybe 5-10 years old, spun out of a crypto or networking R&D background rather than a big incumbent
> 
> — Chief Information Security Officer, Government and Defense, 501-1000

---

## 05 · The hardest read

An adversarial pass over the findings. Every claim below was checked
against the panel's own answers; unsupported ones were dropped.

- **The page is comprehensible but unbuyable — clarity wins do not convert into a purchase decision** *(high)*
  Six respondents said missing named OT references, certification and pen-test evidence halt progression past pilot and budget approval, while the positive themes cover only comprehension of the offer and audience fit.
- **Every quantified proof point on the page is treated as unverified vendor assertion** *(high)*
  Four respondents rejected the 1ms latency figure for lacking methodology or test conditions, and two said 'crypto-agile' has no engineering definition. The page's specifics read as marketing, not evidence.
- **The differentiation story collapses because its two pillars are the same claims respondents refuse to accept** *(high)*
  Crypto-agility is named a differentiator by three respondents yet dismissed as undefined by two, and one explicitly said unproven latency undercuts the deployment-flexibility position. The strongest claims are the least substantiated.
- **The page actively signals immaturity, which compounds every other evidence gap** *(medium)*
  Three respondents read the partner logo strip as an early-stage vendor borrowing others' names, explicitly compounded by the missing case study that six others flagged as deal-blocking.
- **Audience targeting works by accident rather than by statement, leaving the fit unowned** *(medium)*
  Six respondents identified OT and critical-infrastructure operators, but two noted this is inferred from SCADA visuals rather than stated outright — the page never claims the audience it wins.
- **Only the NIST standard survives scrutiny, so the page's credibility rests entirely on a third party's name** *(medium)*
  Three respondents cited FIPS-203/ML-KEM as the verifiable, concrete claim, while latency, crypto-agility, partner logos and customer proof were all challenged. Nothing proprietary stands up.

---

## 06 · Who answered

| # | Role | Industry | Company size |
| --- | --- | --- | --- |
| 1 | Infrastructure Manager | Energy and Utilities | 1001-5000 |
| 2 | Critical Infrastructure Manager | Transportation and Logistics | 5000+ |
| 3 | Chief Information Security Officer | Water Management | 501-1000 |
| 4 | CISO | Telecommunications | 1001-5000 |
| 5 | Head of IT | Government and Defense | 5000+ |
| 6 | IT Director | Energy and Utilities | 501-1000 |
| 7 | Infrastructure Manager | Transportation and Logistics | 1001-5000 |
| 8 | Critical Infrastructure Manager | Water Management | 5000+ |
| 9 | Chief Information Security Officer | Telecommunications | 501-1000 |
| 10 | CISO | Government and Defense | 1001-5000 |
| 11 | Head of IT | Energy and Utilities | 5000+ |
| 12 | IT Director | Transportation and Logistics | 501-1000 |
| 13 | Infrastructure Manager | Water Management | 1001-5000 |
| 14 | Critical Infrastructure Manager | Telecommunications | 5000+ |
| 15 | Chief Information Security Officer | Government and Defense | 501-1000 |

---

## 07 · Before you act on this

The methodology is real, and the critique is directional. What a
simulated persona cannot have is a live budget, a renewal coming up, or
a boss asking about this quarter. **Validate anything you're betting on
with real ICPs who are actually in-market.** Being wrong is more
expensive than you think. Finding out is cheaper than you'd guess.

Wynter runs message testing with verified B2B professionals — trusted
by HubSpot, RingCentral, Shopify, Cognism, Paddle, Veeam, Rippling and
Miro. <https://wynter.com>

This report is kept for 60 days from 2026-09-15, then deleted along with the personas and their answers.

