Frontier AI, Patents and the UK Trail
Last year I wrote Decrypting The Exit: Nubeva’s Patent Play. The thesis was fairly straightforward: Nubeva Technologies was beginning to look like a company methodically assembling a potentially valuable software and intellectual-property asset focused on ransomware reversal.
Building a strategic technology asset is difficult. You need novel, genuinely differentiated technology, defensible intellectual property, real-world validation and evidence that the product can operate inside the environments of very large customers.
Over the last year, Nubeva has continued moving in that direction. Two important ransomware-recovery patents have been granted. The company continues to develop its IP portfolio, says it is working alongside multiple AI companies, and remains engaged with large “lighthouse” enterprise accounts. Most recently, it announced that it had been approved “for access to a frontier artificial-intelligence model made available specifically to vetted organizations conducting authorized defensive cybersecurity work.”
And then there is the customer. Nubeva’s unnamed “top 10 global financial institution” remains very much alive in the story, and the evidence continues to point toward the United Kingdom.
The Frontier Model
On September 3, 2026, Nubeva announced that it had been approved for access to a frontier AI model available to vetted organizations for authorized defensive cybersecurity work. Access was application-based and required verification of both the applicant’s identity and its intended defensive use. Nubeva intends to evaluate the model against its ransomware detection and decryption technology, including agent software already deployed on enterprise systems.
At first glance, that sounds like another small technology company announcing that it has access to AI. Except something rather remarkable happened on exactly the same day.
OpenAI announced Daybreak for Frontline Defenders, committing “$1 billion in subsidized Daybreak access, training, technical support and partnerships” to help defenders protect essential services, explicitly including banking.
The timing is hard to ignore, and so is the language. OpenAI describes Daybreak as a controlled cybersecurity capability intended for approved defensive use. Nubeva, on the same day, described being approved for access to a frontier model made available to vetted organizations for authorized defensive cybersecurity work.
That does not prove Nubeva’s unnamed provider is OpenAI. But identical timing, highly similar access criteria and an unusually well-aligned use case make OpenAI Daybreak a very credible candidate.
And that matters because Nubeva is not looking for AI to write marketing copy. It is trying to automate one of the hardest parts of ransomware recovery.
From Capturing Keys to Building the Decryptor
Nubeva’s original ransomware-reversal concept is novel. Rather than trying to identify and block every possible ransomware variant before it attacks, Nubeva’s sensors capture copies of the encryption keys while the ransomware is actually encrypting data.
That potentially solves one of the most difficult parts of the recovery problem, but not all of it. When an unfamiliar ransomware variant attacks, somebody still has to determine exactly how those keys were applied, understand the encryption method, build the correct decryptor, test it and then safely apply it across what could be enormous amounts of damaged data.
That is the part Nubeva is automating.
Management says its patented technology uses a private, cryptographically trained AI engine to analyze encrypted samples alongside captured keys, determine the appropriate decryption methods and mechanisms, and then create decryptor software, test kits and documentation. The goal is to reduce both the time and the specialist expertise required to create recovery tools for previously unseen ransomware variants.
That is why the frontier-model announcement is potentially much more important than it first appears.
Nubeva already appears to have patented important parts of the recovery workflow. A frontier cybersecurity model may now be getting inserted to speed up and improve the reasoning and automation layer.
The Patents Matter
Beyond its existing patent portfolio and the patents sold to Netskope — more on that below — Nubeva now holds two particularly important ransomware-recovery patents.
The first, granted in 2025, covers core innovations around recovering from ransomware attacks by analyzing how encrypted data and captured keys interact and determining the appropriate decryption process. The second, granted in 2026, extends that concept into large data-storage environments using computational intelligence.
Management has been very clear about why it is spending time and money here: the patents are intended to strengthen Nubeva’s market position and increase its optionality for licensing, partnerships and M&A.
The broader portfolio also appears unfinished. Nubeva continues to describe its IP strategy as something it is actively building and completing, and the CEO has publicly commented that two additional patent applications have been submitted.
So we have two significant new ransomware patents granted, while the broader IP portfolio continues to be developed.
Then There Is the Bank
In April 2024, Nubeva announced that it had entered into an agreement the previous month with an unnamed top 10 global financial institution with “substantial retail and corporate banking operations.” Nubeva said its cybersecurity solutions would be deployed across extensive client and server workloads globally.
That description matters. It sounds much more like a very large multinational bank than an asset manager or investment firm.
Two years later, the enterprise thread remains visible. Nubeva says it has expanded beyond Windows to Linux and is testing OSX specifically “in line with the enterprise requirements.” It also says it is selectively engaging large, high-profile “lighthouse accounts” to demonstrate the strength and scalability of its solution and “make the company more attractive for expansion, strategic partnership or M&A.”
Then the September frontier-model release adds another breadcrumb: the company referred to agents already deployed on enterprise systems.

A Very British Fingerprint
The financial statements add another intriguing layer.
Nubeva reports revenue geographically. During fiscal 2024, it recorded $30,709 of revenue from the United Kingdom. That increased to $193,986 in fiscal 2025 and $204,055 in fiscal 2026.
Now compare that with customer concentration.
In fiscal 2026, each of Nubeva’s two largest customers represented approximately 41% of total revenue. UK revenue of $204,055 represented about 40.8% of total company revenue.
The prior year is almost as striking. UK revenue represented about 36.6% of revenue, while one major customer represented 37%.
The simplest interpretation is that one of Nubeva’s major customers is the UK customer.
The timing makes it more interesting. The top-10 financial institution agreement was signed in March 2024, only about two months before fiscal year-end. Nubeva then recorded $30,709 of UK revenue for that short period. Annualized very roughly, that equates to about $184,000, remarkably close to the roughly $194,000 and $204,000 of UK revenue recorded in the next two full fiscal years.
That does not prove that the UK revenue comes from the unnamed financial institution, but it is a very strong fingerprint.
At minimum, it suggests that one of Nubeva’s major revenue-generating customer relationships is tied to a UK entity.
Which Brings Us to HSBC
If it walks like a Brit and talks like a Brit…
Nubeva described its mystery customer as “a top-10 global financial institution with major retail and corporate banking operations and extensive client and server workloads around the world.”
HSBC fits that description exceptionally well. HSBC Holdings plc is incorporated in England, is headquartered in London and operates globally through major regulated banking subsidiaries.
Then layer in the Nubeva evidence: the agreement was signed in March 2024, UK revenue appears immediately, that UK revenue subsequently settles into a roughly $194,000-$204,000 annual range, and the percentage of company revenue attributed to the UK almost perfectly matches one of Nubeva’s largest disclosed customers.
None of this proves HSBC.
But the thesis is now more than simply “HSBC seems to fit.” There is a coherent chain of circumstantial evidence suggesting that Nubeva’s mystery institution is a large UK-based global banking organization. That narrows the field considerably.
And Then There Is Netskope
Netskope adds another layer.
In March 2024, Nubeva sold its TLS technology to an unnamed mid-sized U.S. cybersecurity company for $1 million. Patent records subsequently show former Nubeva patents being assigned to Netskope on March 19, 2024, making Netskope the obvious explanation for the unidentified buyer.
Netskope also maintains a public, account-specific webpage titled “Netskope + HSBC.” The page discusses HSBC’s digitization strategy, AI ambitions, global infrastructure, regulatory requirements and how Netskope’s security architecture could support them.
That page is not proof that HSBC is a deployed Netskope customer, and it certainly does not establish that Netskope is involved in Nubeva’s ransomware engagement.
But the relationships are intriguing. Nubeva developed key-interception technology. Netskope acquired Nubeva’s TLS IP. Nubeva retained its ransomware-reversal business. Nubeva then worked with an unnamed top-10 bank whose revenue footprint appears British. HSBC fits the customer profile extremely well, and Netskope is visibly pursuing HSBC at an enterprise level.
Those facts may still be independent. But they are becoming increasingly interesting when viewed together.
The Strategy Is Becoming Clearer
The other important development is what Nubeva itself says it is trying to accomplish.
Management has acknowledged that its current support structure is not economically scalable. Rather than simply adding people, the company says it is working with multiple AI companies to automate support, onboarding and customer operations. If that succeeds, Nubeva says it can potentially re-expand commercial activity. If it does not, management says it “will continue completing the IP portfolio and position the company for strategic partnerships or M&A”.
At the same time, Nubeva says its large lighthouse accounts are intended to validate the technology and its scalability.
This is not a company focused on maximizing near-term SaaS revenue. It looks much more like a company trying to prove, protect and package a trophy technology asset.
The Frontier Model — A Force Multiplier?
The most interesting question is what AI actually does for Nubeva. The original technical breakthrough was not AI. It was capturing the keys.
Once the keys exist, however, the remaining problem becomes much more suitable for frontier models: understand unfamiliar malware, determine how it encrypted the data, identify the cryptographic implementation, match the keys, write the decryptor, test it and apply it safely against large datasets.
That is exactly the type of complex, multi-stage defensive cybersecurity work frontier models are increasingly being built to perform. OpenAI is explicitly positioning Daybreak as a way to bring frontier cyber capabilities into existing security offerings and defensive workflows.
Nubeva has spent the last several years patenting pieces of that workflow.
If the unnamed model really is OpenAI Daybreak, the fit is remarkably logical.
Nubeva’s Breadcrumbs — Summary
We know considerably more than we did a year ago.
The patents are being granted, the IP strategy continues, and Nubeva is working with multiple AI companies while its software operates in enterprise environments. A major customer appears closely tied to the United Kingdom, with UK-based revenue appearing in an amount and at a time that closely match the “top-10 global bank” relationship. That customer also fits Nubeva’s description of a major global bank remarkably well.
Meanwhile, Netskope owns former Nubeva intellectual property and is actively engaging HSBC. And on the exact day OpenAI announced a $1 billion Daybreak initiative around controlled frontier cybersecurity access, Nubeva announced that it had been approved for access to a restricted frontier cyber model under strikingly similar terms.
One breadcrumb proves very little. At this point, though, Nubeva has accumulated quite a trail. And increasingly, that trail appears to lead toward the exit.
AI Disclosure: The author uses AI as a research and analytical tool. The thesis, research direction, source selection, assumptions and valuation framework are the work of the author. AI was used to accelerate the research process, test ideas, compare data, challenge assumptions and improve the clarity of the final work. The author uses AI as an enhancement and accelerant to the research process — helping produce higher-quality, more accurate and hopefully more useful research and analysis.

Leave a Reply