Post-quantum readiness · cryptographic inventory

Know your cryptography
before the mandate asks.

Quelea discovers the cryptography across your footprint, from certificates to key exchange to protocols, so your inventory is ready before a regulator, auditor or customer asks.

Backed by scans of 5,000+ external footprints.
RemediationWhat to fix first
24
fixable by config alone
3
need to be retired
~3 wks
to clear the high set
1
legacy-api.acme-pay.comCritical
TLS 1.2 with RSA key exchange, no forward secrecy. Recorded traffic is decryptable today, not only post-quantum.
Fix → Retire, or move behind a gateway that enables TLS 1.3 hybrid key exchange.
2
payments.acme-pay.comHigh
Customer-facing payments on TLS 1.2. It cannot negotiate post-quantum key exchange until it moves to TLS 1.3.
Fix → Upgrade to TLS 1.3, then enable X25519MLKEM768. No certificate change.
3
vpn.acme-pay.comHigh
IPsec VPN on classical MODP-2048 Diffie-Hellman (500/udp). VPN traffic is harvestable today.
Fix → Enable RFC 9370 hybrid key exchange on the VPN gateway.
24 of the 80 services reach quantum-safe key exchange with a configuration change alone. Certificate signatures wait on post-quantum certificates, expected from 2028.
Exposureacme-pay.com
28
52
28 quantum-safe52 exposed
35%
quantum-safe today
52
need migration
3
critical exposure
RSA — no forward secrecy3 services
Classical key exchange49 services
Hybrid post-quantum28 services
Traffic on the 52 exposed services, captured today, could be decrypted once a quantum computer exists. Harvest-now, decrypt-later.
Cryptography inventory
80
services inventoried
35%
post-quantum ready
41
harvestable now
Key exchange
X25519MLKEM768 hybrid PQC28
X25519 / ECDHE P-256 classical49
RSA no PFS3
Protocols & ports
TLS 443 · 8443 · 99373
SMTP STARTTLS 5873
SSH 222
IKE / IPsec 500/udp2
78% of certificates from one authority
ServiceKey exchangeCertificateStatus
www.acme-pay.comX25519MLKEM768ECDSA P-256Safe
payments.acme-pay.comECDHE P-256 · TLS 1.2RSA 2048Exposed
mail.acme-pay.comX25519MLKEM768 · 587ECDSA P-256Safe
vpn.acme-pay.comMODP-2048 · IKE 500Exposed
git.acme-pay.comcurve25519 · SSH 22Exposed
legacy-api.acme-pay.comRSA · TLS 1.2RSA 2048Critical
80 services · read from the outsideupdated 2m ago
Live demo

See your quantum exposure
within seconds.

Enter a domain. Watch Quelea find what a future quantum computer could break. No install, no login, no access to anything private, just the view an attacker already has of you.

  • Find your exposure. Every public service you're running, and which ones use encryption a quantum computer will break.
  • See what's already safe. The services that have moved to quantum-resistant encryption, and the ones that haven't.
  • Know where to start. A clear, prioritised picture of what to fix first.
Scan your domain →
Aacme-pay.comSample accountScanning
0
services mapped
0
post-quantum ready
0
harvestable now
standards mapped
Starting…
One inventory, every decision

Post-quantum readiness starts with visibility.

Build a defensible inventory of the cryptography across your public footprint, understand what is already safe, and focus migration work where it matters.

Run a free scanGet early access