Live webinar The Wrong Security Hire Burns Your B2B GTM Pipeline. A fireside chat for founders · Oct 6, 9:30am PTThe wrong security hire · Oct 6 Save your seat

Blog

14 min read Updated September 6, 2026

What Is Deep Tech? Why the Hardest Startups Can't Be Built in a Weekend

Deep tech is built on a hard scientific breakthrough, not on assembling parts that already exist. The core advance has to be invented and proven before there's a product to sell. Here's how the companies that do it actually work: the timeline, the capital, the proof, and where the moat comes from.

Deep tech is technology built on a hard scientific or engineering breakthrough, not on assembling parts that already exist. Quantum computing, advanced cryptography, novel materials, fusion, robotics, and synthetic biology all qualify. The defining trait is that the core advance has to be invented and proven before there’s a product to sell.

That makes deep tech a different animal from a typical software startup. BCG’s research puts numbers on the difference: deep tech ventures take 25% to 40% more time between funding stages than other tech investments, about 70% own patents, and 83% are building a physical product. Episode 96 is a live case study: Kevin Kane, co-founder and CEO of American Binary, builds post-quantum cryptography, deep tech where the breakthrough is mathematical rather than mechanical. The lessons are the same ones every deep tech founder runs into: how the company gets built, where the moat comes from, and what the job asks of the person running it.

What is deep tech? The two-sentence version

Deep tech is a startup whose product depends on solving a substantial scientific or engineering problem first. The technology has to be discovered, made to work outside the lab, and proven to skeptics before a customer can buy it, which is why the timelines, the capital and the moats all look different from software.

The definition is less about a list of fields than about an approach. BCG’s 2021 study, Deep Tech and the Great Wave of Innovation, goes as far as saying “there is no such thing as a deep technology”: what the ventures share is a problem orientation (“solving large and fundamental issues”), a convergence of several technologies, and a design-build-test-learn cycle that de-risks the science one experiment at a time. The Martin Trust Center for MIT Entrepreneurship adds the practical point: “It takes more time, resources, and specialized talent to develop and validate a science-based innovation to the point where it is ready for commercialization,” and the primary risk is technical validation, with market fit coming second.

That reversal is the whole story. A SaaS founder knows the software will run and wonders whether anyone wants it. A deep tech founder often knows exactly who wants it (a bank, a defense program, a hospital) and spends years finding out whether it can be made to work at all.

Three YSecurity team members smiling over dinner and cocktails during Black Hat USA 2026
Three of the team at dinner during Black Hat USA 2026. Episode 96 with Kevin Kane of American Binary is linked at the end of this post.

Deep tech vs. a software startup: what actually differs

Most startup advice quietly assumes the software model: ship in weeks, learn from users, iterate, raise on traction. Five things differ at the root for deep tech.

Comparison table of a software startup versus a deep tech startup across five rows: time to product (weeks to months versus years), capital (cheap to start versus heavier early R&D and 25 to 40 percent more time between funding stages), moat (distribution and brand versus proof, patents and rare talent), failure mode (market risk first versus technical risk first) and buyer (self-serve on a demo versus enterprise, government and defense buying on evidence)
Two kinds of startup. The dashed column is the one most playbooks were written for.

Time to product. A software product is an arrangement of things that already work. A deep tech product has a hole in the middle where the breakthrough goes, and nothing ships until the hole is filled.

Capital. Deep tech needs more money earlier, for R&D and prototypes, and it needs patience: that 25% to 40% extra time between stages, from seed through Series D, is BCG’s finding across the industry. The upside is real: deep tech holds a stable 20% share of venture funding, up from about 10% a decade earlier, and BCG found deep tech-focused funds returned a weighted average IRR of 26% over five years against 21% for traditional venture.

Moat. A software moat is distribution, brand, data and speed, all of which a well-funded rival can attack. A deep tech moat is proof and people: peer review, a formal verification nobody else has, patents, and a team whose knowledge took decades to accumulate.

Failure mode and buyer. Software fails because nobody wants it; deep tech fails first because it doesn’t work yet, and only later because of the market. And deep tech sells to enterprises, governments and defense programs, buyers who purchase on evidence (reviews, standards, security assessments, export paperwork) with the demo as the last step rather than the first.

The eleven-minute version of the definition, from Antoine Gourévitch, a lead author of the BCG research cited above. His TED talk has around 70,000 views on YouTube. Watch on YouTube.

Why deep tech can’t be built in a weekend

The hackathon model, a small team assembling existing tools into a working product over a weekend, is the opposite of how deep tech gets built. The whole premise is that the core technology isn’t sitting in a package manager waiting to be imported.

Kane put a number on it: “Tech nowadays, especially in our area, it’s to the point where you need 20 years of cumulative knowledge to do something like we’re doing. You can’t wing it on a weekend or at a meetup with some friends and hack this.” That cumulative knowledge is the real moat, and the barrier to entry. It can’t be raised in a quarter or copied from a tutorial. It’s built one hard problem at a time, often across a career.

The part founders underestimate most is debugging. When your technology has never run anywhere, every failure is a new failure: no Stack Overflow answer, no vendor support line, no one who has hit the same wall. Kane’s team spent years finding out what was wrong with their systems when they weren’t working in the real world, and the root cause turned out to be one thing:

“We learned that we were having a problem handshaking, which led us to developing a lot of solutions around our key exchange. But we didn’t know that that was the issue. There’s such a long road on learning what’s going wrong with software that is new, doesn’t exist in the wild except for what you built, and then putting it in a complex system. It could have been any infinite number of problems that was causing the failure.”

Kevin Kane, co-founder and CEO of American Binary, on episode 96

This is where deep tech timelines actually go: into discovering why something that should work doesn’t, in a system no one has mapped. A founder building a cybersecurity startup on known architecture can lean on proven patterns. A deep tech founder is often writing the pattern, and the years that takes are the price of admission rather than a sign that something has gone wrong.

How a deep tech company gets built: research, proof, verification, first customer, scale

The deep tech companies we have watched up close move through the same five stages, and each one ends at a gate that has to be passed rather than talked around.

Deep tech company-building timeline in five stages with the gate that ends each one: research (a result that holds up outside your notebook), proof (it works inside a live complex system), verification (peer review and formal verification on the record), first customer (a production deployment and a passed security review) and scale (revenue that funds the next advance), with a dashed loop from proof back to research
Five stages, five gates. Verification is the filled square because it is the one nobody gets to skip.

American Binary is a clean example because the milestones are public. The research was a new key exchange, an alternative to the Diffie-Hellman exchange that, as Kane put it, “guides everything on the internet.” The proof stage was those years of field failures over real and mobile networks, ending in the handshake discovery above. The verification stage is where the company separated itself:

“One of the things that’s unique about our company is we developed a new key exchange that is not theoretical and in the lab, but has completed private peer review and formal verification from two DARPA performers and cryptographers for the US community.”

Kevin Kane, American Binary, episode 96

The two reviewers he named are Thomas Shrimpton and Joseph Kiniry, both principal scientists at Galois, the Portland firm whose cryptography practice, in its own words, uses “cryptographic security proofs, NIST verification suites, and formal methods to guarantee that cryptographic operations function exactly as intended.” Shrimpton was a university cryptographer for two decades before joining Galois in 2025; Kiniry leads its rigorous digital engineering research. The review took six months, used “modern tools that were not available two years ago,” and covered the claims that matter to Kane’s buyers: a post-quantum key exchange, post-quantum authentication, and meeting the NSA’s standard for national security networks in software, over mobile networks. (The threat behind those claims is the subject of the companion post Harvest Now, Decrypt Later.)

Formal verification deserves a plain-English sentence, because most software founders have never needed it. Testing shows a system behaved correctly on the inputs you tried; formal verification is a mathematical proof that the implementation matches its specification for every input. That matters in cryptography, where the algorithm can be strong and the construction around it still wrong, and it is the same instinct behind neuro-symbolic AI: the parts that must be correct get a proof instead of a probability.

Then the first customer stage, where evidence becomes revenue. American Binary’s post-quantum VPN went live on Oracle Cloud Infrastructure for defense and enterprise environments in November 2025, and in April 2026 Whitfield Diffie, co-inventor of the key exchange Kane set out to replace, joined the company’s advisory board. Kane mentioned it almost in passing: “Whitfield Diffie joined our advisory board last week.” That is what the scale stage looks like in deep tech. The growth hack is the people who defined the field deciding your brick house is worth standing in.

What is the moat in deep tech? Brick houses and hay houses

Deep tech forces founders to defend ideas that established experts may not accept yet. Kane’s answer is that authority has to be earned through proof, not borrowed from a title, and his metaphor for it has stuck with us:

“Being able to speak truth to power without being afraid how it will be received by people who disagree with it, because I have such a foundation that it’s not on thin air, it’s not on weak things. So nowadays we challenge directly some of the world’s most famous cryptographers and leaders from institutions around the world to look at problems in a way that they might not have. And to be able to speak with that authority which was earned is an incredible thing. It’s like the three little pigs, right? So we built a brick house and we didn’t build a hay house, and the brick house allows us to do things in it that you might not with a hay house. And everyone wants in your brick house because the hay ones are all collapsing around us.”

Kevin Kane, American Binary, episode 96

Anatomy of a deep tech moat drawn as two houses: a solid brick house whose courses are talent (decades of cumulative knowledge), peer review (reviewed by cryptographers paid to break it), formal verification (mathematical proof the construction is right) and standards (built to the bar national-security buyers use) under a roof labelled earned authority, beside a dashed hay house of good-enough claims: a post-quantum library bolted onto an old construction, a classical key exchange still inside, no outside review, and a product promised in six months
Moat anatomy. Each course of the brick house is something a competitor cannot buy in a quarter.

The hay house is the trap for anyone entering a hot deep tech category late. Kane’s version, from his own market: “Using post-quantum encryption does not make the product quantum safe. You have to follow additional instructions to do the cryptographic construction correctly.” A team can bolt a post-quantum library onto a protocol that still runs a classical key exchange underneath, ship a press release, and be telling the truth about the algorithm while the construction stays breakable. He was blunt about what that means for investors: “Investors might not be wise to invest in a post-quantum encryption company that was founded three months ago, that has zero IP, and that’s going to build a post-quantum encrypted email client in six months, unless their expectation is that they might get a result four years later that’s product-ready, because it’s such a long road.” His name for those companies: “I call those hay houses. Hay houses are solutions that are good enough.”

Good enough holds until the first scary headline. Kane’s scenario is a rumor on X that someone solved the discrete logarithm problem: “I don’t think anyone’s gonna wait for a cryptographer to say, actually, AES-256 is still secure inside. I think they’re gonna leave. Or even worse, a bank.” The brick house survives that day because its owners can show the proof rather than argue about it.

The four courses in the diagram generalize beyond cryptography: talent that took decades to train, peer review by people paid to break your claims before you argue them in public, formal verification on the record, and building to the bar your hardest buyer uses so the sale is a comparison rather than a leap of faith. Patents sit alongside all four (BCG found about 70% of deep tech ventures hold them), and the moat has to survive contact with the customer’s laptop, which is where anti-reverse-engineering work earns its keep: shipping the product without shipping the secret.

Trend-following vs. following the crowd: how deep tech founders time the market

Most startup advice treats market timing as having the right thesis. Kane, whose earlier life was in systematic trading, draws a sharper line:

“Following the crowd and trend following are not the same thing. So when we follow the crowd, we get crap. That’s going to be the outcome, right? Nothing better than the market. Trend following is supposed to be reserved for following the trend of people whose track records are consistently beating the market, which means you’ve got to be there at the time of trade.”

Kevin Kane, American Binary, episode 96

A thesis without execution is worthless: “Theses are meaningless if your trades aren’t executing exactly where they need to be.” Real conviction means being early on something the market hasn’t caught up to yet, and then being there, with a working product, on the day it does.

For deep tech that creates a bind. You often have to start years before demand is obvious, because the technology itself takes years to mature. “When we started this company, the time was not here,” Kane said. “It’s starting to come here now.” His worry is the opposite of being too early: “If you wait too late to start, you’re not going to catch up.” Start too early and you burn capital waiting; start too late and the cumulative-knowledge deficit means you never close the distance. Andrew Rubin founded Illumio in 2013 on a thesis the industry wasn’t ready to hear, and the lessons from that bet rhyme with Kane’s. So does defense, where Reveal Technology built for the corporal on the ground while the program offices caught up, and where the counter-drone market shows demand arriving faster than the technology that has to meet it.

The investor's side of the timing question. Y Combinator's Jared Friedman on why founders should consider starting a hard-tech company and how to solve its most common problems, with examples from seven YC companies and roughly 96,000 views. Watch on YouTube.

What deep tech demands from founders: owning the outcome without institutional cover

Kane was direct about the personal cost, and about the standard he holds his company to. His argument starts with the 2008 financial crisis, which he blames on people who could build something consequential and then move on to the next job:

“I think that the buck should fall on the human being, and they should look into the dark void and say I will accept this problem and I’m not going to face this problem under the cover of an institution. I’m going to face it myself so that the accountability matches the seriousness. And that is how we behave in our company.”

Kevin Kane, American Binary, episode 96

He expects that standard to filter people out as the company scales, and he is fine with it. A few more of his hard-won lessons translate beyond cryptography:

  • Hold a standard you won’t break, even when it costs you. The technical bar and the personal one are linked; shortcuts surface years later as failures.
  • Hire for obsession, and let money be the by-product. He prefers people “so obsessed on solving the problem, so lost in solving the problem, that they forget about money, and money is something that happens to happen as a result of obsession.”
  • Take help from people you don’t click with. His advice to his younger self: “help comes from people sometimes we don’t even like. That’s very humbling.” And a warning for co-founders: “not everyone you start with is the person you’re going to finish with.”
  • Don’t postpone happiness until after the win. At 46, he thinks of it as a role-playing game with “only a few turns left.” His advice: “don’t postpone happiness, integrate it into your work now.” He learned it the hard way: both parents were gone before he could come back and show them what he had built.

None of this shortens the road. It makes the road survivable. Deep tech is a long game with a small number of turns, and the founders who last are the ones who can hold a standard and a life at the same time.

Four attendees talking in the hotel lobby between sessions at MicroConf US 2026 in Portland
MicroConf US 2026, Portland. The lobby track: founders comparing notes with founders, where advice like Kane's gets road-tested.

Where to start if you’re building deep tech

If your buyer purchases on evidence, the practical move is to build the evidence trail from the first month, so that by the time a bank, a hospital or a program office asks, the answers already exist. Three things we would put on the list.

Keep the record. Every review, every verification artifact, every field failure and what fixed it. Kane can name his reviewers and the tools they used because the company treated the review as a product milestone. That record becomes the security review you will pass later and the diligence packet your Series B will read.

Get the product side of security right before the first pilot. Enterprise and government buyers evaluate SSO, audit logging, key management and encryption in the demo, and a deep tech product with a brilliant core and a thin shell around it loses the deal on the shell. A product security roadmap and a penetration test before the pilot cost far less than a stalled procurement. If the buyer is defense, ITAR readiness belongs on the same list, early, because export controls shape who can even see the code.

Decide who does this work. Kane’s company has “very tight rules on LLMs,” and that kind of discipline is a choice about people and process as much as tooling. Hire security in-house, bring in operators on demand, or consciously wait: that is the decision in In-House, On-Demand, or YOLO?, and for a deep tech company the answer usually changes the month the first enterprise pilot is signed.

The reward is Kane’s brick house: a company that can argue with the experts because the foundation holds, and that customers move into when the hay houses around it start to fall. If you are building something that can’t be built in a weekend, a free product security roadmap will show you what your first enterprise buyer is going to ask for and how far along you already are. And for the story in Kane’s own words, trading analogies included, it is 26 minutes on episode 96.

Deep tech frequently asked questions

What is deep tech?
Deep tech is technology built on a substantial scientific or engineering breakthrough that has to be invented and proven before a product can exist, as opposed to software assembled from parts that already work. Quantum computing, post-quantum cryptography, fusion, novel materials, robotics and synthetic biology are typical examples. BCG describes it as an approach rather than a category: a hard problem, converging technologies, and a design-build-test-learn cycle that takes years.
What is the difference between deep tech and a regular tech startup?
The order of the risks. A software startup faces market risk first: the technology works on day one and the question is whether anyone wants it. A deep tech startup faces technical risk first: the question is whether the thing can be made to work at all, and market risk waits its turn. That reversal drives everything else, including longer timelines, heavier early R&D spending, and buyers who purchase on evidence rather than on a demo.
What are examples of deep tech?
Post-quantum cryptography and new key-exchange protocols, quantum computing, fusion and advanced energy, semiconductors and photonics, advanced materials, robotics and autonomous systems, space technology, and synthetic biology. BCG's 2021 study found 83% of deep tech ventures were building a physical product and 96% used at least two technologies. Cryptography is the reminder that the breakthrough can be mathematical rather than mechanical: American Binary's product is software, and it is still deep tech.
Why does deep tech take so long to build?
Because the core technology does not exist yet, so every failure is a new failure with no vendor to call and no answer online. Kevin Kane of American Binary spent years finding out that a handshake problem was breaking his post-quantum protocol in real networks. BCG measures the effect across the industry: deep tech investments take 25% to 40% more time between funding stages than other tech investments, from seed through Series D.
How is deep tech funded?
Mostly by venture capital plus non-dilutive money such as research grants and government programs, because the early years produce proof rather than revenue. BCG reports deep tech now holds a stable 20% share of venture funding, up from about 10% a decade earlier, and that deep tech-focused funds returned a weighted average IRR of 26% over five years against 21% for traditional venture. Rounds are larger and further apart, so runway planning matters more than in SaaS.
What is formal verification, and why does it matter for deep tech?
Formal verification uses mathematical proof, rather than testing alone, to show that a system does exactly what its specification says. In cryptography that means proving the construction is correct, not only that the underlying algorithm is strong. Firms like Galois build the tools for this and review protocols for DARPA and industry. For a deep tech company it converts a claim into evidence a skeptical buyer can check, which is why it belongs in the moat.
Is post-quantum cryptography deep tech?
Yes. A new key exchange has to be invented, made to work over real networks, reviewed by cryptographers and proven correct before a customer will run it, which is the deep tech pattern with mathematics in place of hardware. Kevin Kane's warning is that bolting a post-quantum library onto a classical construction is a different thing: "Using post-quantum encryption does not make the product quantum safe." The construction has to be right, and shown to be right.
Is AI deep tech?
It depends on what is being invented. Training a new model architecture, building neuro-symbolic systems whose outputs must be provably correct, or designing the chips underneath is deep tech. Wrapping an existing model API in a workflow is a software startup, with software timelines and software moats. The test is the same everywhere: does the core advance have to be discovered and proven before there is a product, or does it already ship in a package manager?
Written by the team behind The Security Podcast of Silicon Valley

Put it into practice.