Leading the post-quantum shift.
PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.
Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Twelve patents pending.
From target to decision in four steps. No agents, no console training, no onboarding.
One input covers your whole estate
Type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. Nothing to configure.
One score in seconds
The scan streams live, resolves to a readiness score with the vulnerable / transitional / safe breakdown and full asset inventory. GitHub, assessed against CNSA 2.0 in four seconds.
Copy-paste the fix
Every finding produces a remediation playbook with the exact config for your platform and the standards citation. Other scanners hand a CISO red. PQCAT hands their engineer the patch.
Evidence a skeptic can re-verify
The Challenge Coin is portable proof an auditor re-derives offline with no PQCAT installed. It fails closed the moment a byte is altered. No other scanner ships proof you can re-check yourself.
Ten scanner modules cover the estate, eleven with cloud. Five evidence instruments prove what they find. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and a remediation plan that names the fix.
Network
Deep TLS assessment, SSH key audit, and CIDR discovery across the perimeter.
Code & supply chain
Source analysis in 40+ languages, SBOM scanning against 183 quantum-vulnerable library signatures, and container-image inspection.
Infrastructure & firmware
Configuration analysis, PKI and X.509 estate inventory, SCAP compliance, and firmware carving that pulls certificates and keys straight out of UEFI capsules and flash dumps.
Cloud
AWS KMS, ACM, ELB, S3, Route 53, and IAM, with the patent-pending HNDL Risk Engine scoring each asset's harvest-now-decrypt-later exposure.
Challenge Coin & Prove-It Kiosk
pqcat coin
Portable proof an auditor re-verifies offline, on their own machine. Fails closed the moment a byte changes. Verify one in your browser now. Same math, nothing uploaded.
Harvest Clock Patent pending
pqcat harvest
Puts a number on how many asset-years of traffic an adversary can already have collected. HNDL stops being a slogan and becomes a measured exposure.
Quantum X-Ray Patent pending
pqcat xray
Binds a verdict to excavated firmware bytes. A verifier re-dumps the region and re-derives the verdict from the hardware itself. Below the OS, where most scanners stop.
Closed-Loop Remediator Patent pending
pqcat remediate prove
Binds before-state and after-state under one post-quantum signature. The finding closes only when verification passes. Find, fix and prove, in one command.
Provenance Passport Patent pending
pqcat disclose
Prove posture while revealing only what you choose. Commits the full inventory under one root, opens exactly one asset class; everything else stays sealed. The dashboard requests a disclosure and verifies the answer, but it cannot produce one. Opening a class needs a master secret the server never holds.
Eleven frameworks. One normalized score.
PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.
Four of the nine cannot be scanned. They don’t exist in your infrastructure.
Federal reporting asks for nine data items per system. Five describe cryptography. Four describe the system itself: FISMA ID, FIPS 199 impact, HVA status, hosting. No scanner can find those. GSA says no known tool captures all nine.
PQCAT ingests your system of record (eMASS, CSAM, Xacta, CSV) and binds every cryptographic asset to the system that owns it. Every cell records how it got its value: discovered by a scanner, imported from a named export (with its digest), or asserted by a named person on a date.
The provenance is sealed under one ML-DSA-44 signature. Change an impact level after the fact and it fails closed.
What PQCAT builds on that binding
Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.
- Asset anonymization
- BLAKE2b-salted asset IDs · no raw hostnames
- Aggregate-only reporting
- Statistical summaries · never per-asset detail
- Verifiable score
- Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
Every capability is free on up to 25 hosts per scan. Not a feature-limited demo: the scanners, the scoring, the web dashboard, the Challenge Coins and the reports, all of it. A licence raises the scope and adds what only starts to matter once this is a programme rather than an evaluation.
Install it, point it at something you own, and read the report. The 25-host bound is enough to see the whole evidence chain work end to end, and small enough that it is not a deliverable.
Two questions people mix up, so answer them separately. Which binary do I have is decided at build time and a licence will not change it. What am I entitled to use is decided by the licence and a rebuild will not change it. The most common mix-up is expecting a licence to switch on cloud scanning; it cannot, because cloud is compiled in.
Enclave Apache 2.0
Air-gapped scanner · zero outbound network codego tool nm pqcat | grep 'http.(*Server)'
Returns nothing. There is no HTTP server in the binary. Not disabled, absent.
Pro ML-DSA-65 Signed
Everything in Enclave, plus a serverWhat this build adds:
Cloud Enterprise licence
Everything in Pro, plus the CSP APIsWhat this build adds. Cloud scanning is the one capability a licence does gate, because it reads a whole account rather than a host you pointed at:
Capability is not what is for sale. Scale, automation, more than one person, integration with what you already run, and the submission formats an authority will accept: those are. Each tier below is a job someone is doing, not a feature list.
- All ten offline scanner modules
- Scoring across every framework
- Challenge Coins and selective disclosure
- The web dashboard and the REST API
- PDF, HTML, CBOM and executive briefings
- Everything above, at estate scale
- Drift between scans, so posture becomes a trend rather than a snapshot
- Accounts and roles, for more than one person
- Scheduled scans and webhooks
- SIEM forwarding and Prometheus metrics
- Cloud scanning across AWS, with CSP auto-detect
- Vendor supply-chain analysis
- Everything in Enterprise
- ATO package assembly
- eMASS integration
Need to pilot at real scale before you decide? pqcat license trial starts a fourteen-day evaluation at 250 hosts with the Enterprise feature set, so you can answer the questions the free bound cannot: does it hold up across the estate, does it run on a schedule, does it land in our SIEM. It is hardware-bound, signed, and validated entirely offline. When it lapses the product keeps working, back at 25 hosts.
Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.