Post-quantum migration readinessFor regulated institutions. Inventory, exposure, roadmap, board briefing.Technical due diligenceFor investors. Architecture, security and regulatory exposure, reported to the IC.InsightsWriting on cryptography, energy and verificationAbout and evidenceThe record, and what you can checkStart a conversation
Evidence and background

One person, and that is the point

A five-figure engagement rests on one person’s judgement. Here is where mine comes from, and what you can verify without contacting me.

01

US patent 19/330,220

Sole inventor and sole applicant. Energy-aware compute scheduling, with the saving attested rather than asserted.

02

Post-quantum Layer-1, in production

Quantum-resistant primitives designed into the consensus layer, not retrofitted. Live since March 2026.

03

Group CTO, three jurisdictions

UAE, India and US entities. Around eighty engineers, and the compliance surface that comes with them.

04

Both sides of the table

Four years in derivatives risk before the engineering. It is why the architectures survive review.

Arijit Biswas
Kolkata, India

I build and evaluate infrastructure where a hard physical or economic limit is the binding constraint — latency, cost per transaction, watts per job — and where the result has to be verifiable by somebody other than the person claiming it.

I have done that twice. Once in cross-border settlement, where the constraint was time and the verification was cryptographic: a Layer-1 built post-quantum from the consensus layer up, now in production. Once in compute scheduling, where the constraint is energy and verification is the harder half of the problem, which is what the patent application covers.

Group CTO across the Diamante group since November 2021 and on a retained basis since October 2025, spanning entities in the UAE, India and the United States. Around eighty engineers on payroll, forty or so contributors, and the security and compliance surface of three regulatory jurisdictions.

Before that, product architecture for enterprise trade finance and exchange infrastructure at HashCash Consultants, deployed with commercial banks across three regulatory regimes.

Before any of it, four years in wealth management at Kotak and ICICI running derivatives hedging and portfolio risk, with an MBA in banking and finance behind it. It reads oddly on a CTO’s profile. It is also where I learned what a clearing house does under stress, and why I can see an architecture heading for a regulator eighteen months out.

Verifiable

Everything a stranger can check

  1. 01

    US patent application 19/330,220

    Energy Aware Infrastructure Management. Filed 16 September 2025, sole inventor and sole applicant, no assignee. Foreign filing licence granted 3 October 2025. Twenty claims, three independent. Publication projected March 2027.

    Filing receipt
  2. 02

    Panel — “The RWA Revolution: Tokenising Trillions in the Real World”

    Istanbul Blockchain Week, 13 August 2024. Moderated by BeInCrypto, alongside the CEO of MANTRA, the CEO of Chateau Capital, and Ava Labs’ head of Turkish business development.

    Watch it
  3. 03

    Diamante Quantum White Paper

    Credited contributor. Architecture, cryptographic primitive selection and state-machine design for a quantum-resilient Layer-1 now running in production.

    Read it
  4. 04

    Future Hackers podcast

    Guest episode on blockchain infrastructure, distributed across the major podcast platforms.

    Ask for the link
Before you ask

The questions that come up first

We are not convinced we have a quantum problem yet.

That is where most institutions sit, and it is a defensible read of the evidence. The threat has been announced for a decade, every vendor has an urgent-sounding deck, and you have a finite budget against risks that are hurting you today.

The question worth putting in its place is not when a cryptographically relevant quantum computer appears. It is how long the data you are protecting right now has to stay confidential. Mortgage files, medical underwriting, KYC records, long-dated contracts — some of that has to hold for twenty years, and traffic captured today can be decrypted whenever the capability lands. That turns a forecast into arithmetic, and the exposure check runs it in ninety seconds.

We have already had a consultancy look at this.

Send me what you have and I will tell you where it holds and where it thins out. That reading costs nothing and often settles the question either way.

Where I add something, it is usually the same gap. A firm that has read the standards can name the approved algorithms. It is harder for them to say what breaks when you swap a primitive out in your estate — the HSMs that will not hold the new key sizes, the counterparty integration that stops negotiating, the certificate chain nobody has owned since 2019. I have made those choices in production, and got some of them wrong the first time.

Do you implement, or only advise?

Both, deliberately. The most common failure I see is an institution left holding a roadmap with nobody to execute it, and an assessment that dies in a drawer has cost money and bought nothing.

The assessment stands on its own. Beyond it, the work continues in whatever shape helps: selecting and onboarding a technology partner, taking the roadmap into solutioning and architecture design, prototyping the difficult part, or hands-on development assistance where the cryptographic work needs the experience. One route from the problem to a working system, without a handover gap in the middle.

Three things keep the assessment independent: the fee is fixed before the work starts and does not move with what it concludes; anything beyond it is separately scoped and separately decided; and no vendor or partner pays me anything.

What does an engagement cost?

Fixed fee, quoted in a one-page written scope after we have talked. What drives it: the size of your cryptographic estate, the number of jurisdictions it spans, and how much is already documented. An institution that knows where its keys live is a materially smaller piece of work.

No day rates. A day rate pays for time instead of for the answer, which leaves you unable to budget and me with no reason to finish early. The scope is free, so you get a real number and can compare it before committing.

How quickly could you start?

I run a small number of engagements at once, which is what allows me to be in the detail rather than reviewing someone else’s slides. You will get a real date on the call. If your board date is fixed, say so first and we will work backwards from it.

How do you work?

Based in Kolkata, working with institutions in the US, UK, GCC and India. Most of the work is remote — document review, architecture sessions, interviews with the people who run the systems — with travel for the workshops early on and the presentation at the end, where being in the room changes the outcome.

Weekly written updates throughout. Contracts are entered personally and invoices raised in my own name; if your procurement needs a particular structure, raise it early and it gets sorted before it becomes a delay.

Start a conversation

Tell me what you are dealing with

Three short steps, about ninety seconds. It means the first call opens on your situation rather than on introductions.

Which of these is closest?

This decides what I ask next, and what I read before we speak.

What happens next

A twenty-minute call on your situation, then a one-page written scope with a fixed price. Both free, and the scope is yours to take elsewhere.

Response time

Two working days, from me rather than an assistant.

Confidentiality

What you send stays between us. An NDA before the first call is fine, and I will sign yours rather than send mine.