Post-quantum migration control plane

Find, migrate, verify, and prove every cryptographic transition.

Start with a free public TLS scan, then turn the findings into a living inventory and migration program. PostQ coordinates native AWS, Google Cloud, Microsoft, Cloudflare, and PKI-provider changes, validates runtime adoption and downgrade protection, and seals auditor-verifiable before/after evidence.

No signup required for the basic TLS scan. We only inspect public metadata.

View a sample report →Free TLS/certificate scan · no signup · only public metadata is inspected
Evidence-first migration

A migration record you can actually prove

Every scan can become a provider-aware migration plan with owners, deadlines, runtime validation, downgrade checks, credential rotation, and a signed before/after evidence bundle anchored in the PostQ Ledger.

  • TLS version support, cipher, and negotiated key exchange
  • Certificate public-key + signature algorithm posture
  • RSA / ECDSA / DH / ECDH exposure called out explicitly
  • Hybrid / PQ TLS support detected when present
  • Native-provider target and guided migration action for every finding
  • EO 14412 key-establishment and digital-signature tracks

PQC readiness score

example-bank.com

High risk
52/ 100
Classical key exchange negotiated (X25519)HIGH
Certificate public key uses RSA-2048HIGH
Certificate signed with sha256WithRSAEncryptionMEDIUM
What PostQ scans

Where quantum-vulnerable crypto hides

A single external TLS scan is the starting point. The living inventory reaches into clusters, clouds, pipelines, runtime telemetry, and CMDBs.

TLS certificates
Public APIs
Kubernetes Secrets
cert-manager resources
Ingress certificates
JWT signing algorithms
Code-signing certificates
Cloud KMS keys
HSM-backed keys
CI/CD signing workflows
Embedded PEM files
Service mesh mTLS configs
Why PQC readiness matters

Start your PQC migration with a cryptographic inventory

Harvest-now, decrypt-later is happening today

Traffic protected by classical key exchange (RSA, ECDH, X25519) can be recorded now and decrypted once a cryptographically relevant quantum computer exists. Long-lived data is exposed first.

Auditors are starting to ask

Cryptographic inventory and migration planning are appearing in security questionnaires, NIST guidance, and government mandates. A readiness report is becoming audit evidence.

You can't migrate what you can't see

Most teams have no inventory of where RSA, ECDSA, and DH live. Discovery and prioritization come before any migration work.

Built for cloud-native security teams

Extend the scan into a full inventory

Kubernetes agent

Scan clusters from the inside

An in-cluster agent inventories TLS Secrets, cert-manager Certificates, Issuers, Ingress TLS, embedded PEMs, and Istio / Linkerd mTLS — then reports findings to PostQ.

Kubernetes scanner
Cloud KMS / HSM inventory

Use native cloud PQ keys

Inventory and migrate trust anchors through AWS KMS ML-DSA and Google Cloud KMS / Cloud HSM ML-DSA, while retaining guided paths for Azure and existing enterprise PKI.

Cloud key visibility
Code-signing & JWT risk

Find signing workflow risk

Flag quantum-vulnerable JWT algorithms (RS256, ES256, EdDSA) and code-signing certificates across your CI/CD pipelines and release workflows.

JWT risk checker

Works with your existing cloud-native stack

KubernetesAWSAzureGCPHashiCorp VaultGitHubDocker

Frequently asked questions

What does the free PostQ scan check?

The free scan runs a real TLS handshake against your public domain and inspects the negotiated TLS versions, cipher, and key exchange, plus the certificate chain's public-key and signature algorithms. It produces a 0–100 PQC readiness score with prioritized findings. No signup or private keys are required.

Is the readiness score a guarantee that I'm secure?

No. The score is a readiness indicator based on externally observable cryptography. It is intended to help you prioritize a post-quantum migration, not to certify the overall security of your systems. A complete inventory also covers internal services, cloud KMS/HSM keys, JWTs, and code-signing.

Which algorithms are considered quantum-vulnerable?

Public-key algorithms based on factoring or discrete logs — RSA, ECDSA, DH, ECDH, X25519, Ed25519, and JWT signatures like RS256 and ES256 — can be broken by Shor's algorithm on a future quantum computer. Symmetric algorithms (AES) and hashes are a different, lower-risk category.

What are the post-quantum target algorithms?

NIST has standardized ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) for signatures, and SLH-DSA (FIPS 205) for hash-based signatures. PostQ reports where vulnerable algorithms are used and which targets apply; we don't claim a target is deployed in your stack unless detection confirms it.

Does PostQ upload my private keys?

No. The external scanner only inspects public metadata exposed during a normal TLS handshake. Private keys are never collected. Authenticated integrations (cloud KMS, Kubernetes) read key metadata and usage, not private key material.

Can I share or export a report?

Yes. Every scan has a shareable report URL, and you can export it as a PDF from the report page. The full report (PDF + internal asset coverage) can also be emailed to you.

Find quantum-vulnerable cryptography before your auditors do

Scan any public domain for quantum-vulnerable TLS, certificate, and key-exchange cryptography. No signup required.

No signup required for the basic TLS scan. We only inspect public metadata.

Need cloud, Kubernetes, or signing-workflow coverage? Join the private preview →