Hybrid KEM Integration (ML‑KEM + X25519)

Scope: introduce post‑quantum key exchange alongside a classical KEX for defense‑in‑depth during transition.

Libraries

TLS server (reverse proxy / CDN / ingress)

gRPC / mTLS

Canary & Metrics

  1. Staging validation (PQ‑only / classical‑only / hybrid)
  2. 1% → 25% → 100% canary with rollback
  3. Ship posture: success rate, p95 latency delta, payload sizes