Automated map of your post-quantum cryptographic exposure. Public-surface evidence, a Q-Ready score, and a board-ready report — no network access required at the External tier.
The public-key cryptography protecting almost all enterprise traffic (RSA, ECC) will be vulnerable to a cryptographically relevant quantum computer via Shor’s algorithm. The replacements are already standards. Migration takes years. The defense timeline is fixed by public policy; the attack timeline is a probability distribution.
A long-horizon adversary can collect encrypted traffic today and decrypt it once a CRQC exists. Data whose confidentiality must outlive ~10 years should be treated as potentially exposed under classical cryptography.
The adversary records TLS traffic encrypted in transit.
Stores it — cheaply — waiting for capability.
A quantum computer runs Shor against RSA/ECC.
Years-old traffic becomes readable, retroactively.
We do not claim “your data was already stolen.” We claim measurable exposure under a public timeline.
If the time your data must stay secret (X) plus the time it takes to migrate (Y) exceeds the time until a CRQC (Z), the organization is late. A typical banking example:
Enter legal name, root domain(s), and industry.
We probe public endpoints only: TLS, certificates, CT.
The engine computes your Q-Ready 0–100 and HNDL posture.
You receive the sealable report and portal, in 24–72 h.
Q-Ready is not a certification (not ISO/PCI/NIST) and does not replace a formal internal review.
The External tier does not see inside: it does not inventory HSM/KMS, apps, VPN, encrypted DBs or internal mTLS. Those visibility gaps are covered in Assisted and Enterprise.
We do not sell panic. The cryptographic threat (Shor/CRQC) is a theorem + policy calendar; quantum advantage in optimization is a measured verdict on the Evidence Ledger. Separate claims.
Not at the External tier. We probe only public endpoints of the domains you authorize. Assisted adds uploads and read-only integrations you control.
No. It is a measurement with evidence and an actionable verdict. It complements, not replaces, formal compliance reviews.
Yes, because of “harvest now, decrypt later” and because migration takes years. The 2030/2035 milestones are policy, not hardware.
A theorem (Shor on RSA/ECC) versus a measured verdict (Ledger: did quantum beat the classical baseline on this instance?). Q-Ready measures cryptographic exposure; the Ledger measures optimization advantage. Keeping them separate is part of our discipline.
Your surface changes. The Monitor add-on re-scans quarterly (USD 990/yr) to track your migration progress.
Start with the External tier: public evidence, no access required.