Find, migrate, verify, and prove every cryptographic transition.
Start with a free public TLS scan, then turn the findings into a living inventory and migration program. PostQ coordinates native AWS, Google Cloud, Microsoft, Cloudflare, and PKI-provider changes, validates runtime adoption and downgrade protection, and seals auditor-verifiable before/after evidence.
No signup required for the basic TLS scan. We only inspect public metadata.
A migration record you can actually prove
Every scan can become a provider-aware migration plan with owners, deadlines, runtime validation, downgrade checks, credential rotation, and a signed before/after evidence bundle anchored in the PostQ Ledger.
- TLS version support, cipher, and negotiated key exchange
- Certificate public-key + signature algorithm posture
- RSA / ECDSA / DH / ECDH exposure called out explicitly
- Hybrid / PQ TLS support detected when present
- Native-provider target and guided migration action for every finding
- EO 14412 key-establishment and digital-signature tracks
PQC readiness score
example-bank.com
Where quantum-vulnerable crypto hides
A single external TLS scan is the starting point. The living inventory reaches into clusters, clouds, pipelines, runtime telemetry, and CMDBs.
Start your PQC migration with a cryptographic inventory
Harvest-now, decrypt-later is happening today
Traffic protected by classical key exchange (RSA, ECDH, X25519) can be recorded now and decrypted once a cryptographically relevant quantum computer exists. Long-lived data is exposed first.
Auditors are starting to ask
Cryptographic inventory and migration planning are appearing in security questionnaires, NIST guidance, and government mandates. A readiness report is becoming audit evidence.
You can't migrate what you can't see
Most teams have no inventory of where RSA, ECDSA, and DH live. Discovery and prioritization come before any migration work.
Extend the scan into a full inventory
Scan clusters from the inside
An in-cluster agent inventories TLS Secrets, cert-manager Certificates, Issuers, Ingress TLS, embedded PEMs, and Istio / Linkerd mTLS — then reports findings to PostQ.
Kubernetes scanner →Use native cloud PQ keys
Inventory and migrate trust anchors through AWS KMS ML-DSA and Google Cloud KMS / Cloud HSM ML-DSA, while retaining guided paths for Azure and existing enterprise PKI.
Cloud key visibility →Find signing workflow risk
Flag quantum-vulnerable JWT algorithms (RS256, ES256, EdDSA) and code-signing certificates across your CI/CD pipelines and release workflows.
JWT risk checker →Works with your existing cloud-native stack
Frequently asked questions
What does the free PostQ scan check?
The free scan runs a real TLS handshake against your public domain and inspects the negotiated TLS versions, cipher, and key exchange, plus the certificate chain's public-key and signature algorithms. It produces a 0–100 PQC readiness score with prioritized findings. No signup or private keys are required.
Is the readiness score a guarantee that I'm secure?
No. The score is a readiness indicator based on externally observable cryptography. It is intended to help you prioritize a post-quantum migration, not to certify the overall security of your systems. A complete inventory also covers internal services, cloud KMS/HSM keys, JWTs, and code-signing.
Which algorithms are considered quantum-vulnerable?
Public-key algorithms based on factoring or discrete logs — RSA, ECDSA, DH, ECDH, X25519, Ed25519, and JWT signatures like RS256 and ES256 — can be broken by Shor's algorithm on a future quantum computer. Symmetric algorithms (AES) and hashes are a different, lower-risk category.
What are the post-quantum target algorithms?
NIST has standardized ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) for signatures, and SLH-DSA (FIPS 205) for hash-based signatures. PostQ reports where vulnerable algorithms are used and which targets apply; we don't claim a target is deployed in your stack unless detection confirms it.
Does PostQ upload my private keys?
No. The external scanner only inspects public metadata exposed during a normal TLS handshake. Private keys are never collected. Authenticated integrations (cloud KMS, Kubernetes) read key metadata and usage, not private key material.
Can I share or export a report?
Yes. Every scan has a shareable report URL, and you can export it as a PDF from the report page. The full report (PDF + internal asset coverage) can also be emailed to you.
Find quantum-vulnerable cryptography before your auditors do
Scan any public domain for quantum-vulnerable TLS, certificate, and key-exchange cryptography. No signup required.
No signup required for the basic TLS scan. We only inspect public metadata.
Need cloud, Kubernetes, or signing-workflow coverage? Join the private preview →