Leading the post-quantum shift.

PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.

PQCAT · COMMAND DECK SIMULATION · faithful replay of a real scan
assess CNSA 2.0
github.com:443 · TLS estate
0
READY
0 assets 0 vulnerable 0 transitional 0 quantum-safe
TOP FIX Hybrid ML-KEM key exchange (X25519MLKEM768) →
A faithful replay of a real PQCAT scan. Run the same scan on your own domain →
install the free Enclave edition
# Linux / macOS curl -sSL https://install.pqcat.io | sh # Windows irm https://install.pqcat.io/windows | iex

Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Eleven patents pending.

See it work

From target to decision in four steps. No agents, no console training, no onboarding.

One input covers your whole estate

Type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. Nothing to configure.

PQCAT Command Deck: a single target input and an Assess button.

One score in seconds

The scan streams live, resolves to a readiness score with the vulnerable / transitional / safe breakdown and full asset inventory. GitHub, assessed against CNSA 2.0 in four seconds.

A completed assessment: readiness score dial, zone breakdown, and asset counts.

Copy-paste the fix

Every finding produces a remediation playbook with the exact config for your platform and the standards citation. Other scanners hand a CISO red. PQCAT hands their engineer the patch.

Remediation playbook with copy-paste nginx, Apache, and HAProxy configuration for hybrid post-quantum TLS.

Evidence a skeptic can re-verify

The Challenge Coin is portable proof an auditor re-derives offline with no PQCAT installed. It fails closed the moment a byte is altered. No other scanner ships proof you can re-check yourself.

PQCAT evidence suite: a minted Challenge Coin with a downloadable proof file.
Capabilities

Ten scanner modules cover the estate, eleven with cloud. Five evidence instruments prove what they find. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and a remediation plan that names the fix.

Scan coverage10 modules · 4 surfaces · +cloud in the Cloud edition
TLS · SSH · discovery

Network

Deep TLS assessment, SSH key audit, and CIDR discovery across the perimeter.

source · SBOM · containers

Code & supply chain

Source analysis in 40+ languages, SBOM scanning against 183 quantum-vulnerable library signatures, and container-image inspection.

config · PKI · SCAP · firmware

Infrastructure & firmware

Configuration analysis, PKI and X.509 estate inventory, SCAP compliance, and firmware carving that pulls certificates and keys straight out of UEFI capsules and flash dumps.

CSP scanning · HNDL

Cloud

AWS KMS, ACM, ELB, S3, Route 53, and IAM, with the patent-pending HNDL Risk Engine scoring each asset's harvest-now-decrypt-later exposure.

Evidence instrumentsproof a skeptic can re-run · fails closed

Challenge Coin & Prove-It Kiosk

pqcat coin

Portable proof an auditor re-verifies offline, on their own machine. Fails closed the moment a byte changes. Verify one in your browser now — same math, nothing uploaded.

PQCAT Challenge Coin: a tamper-evident compliance proof minted from a scan.

Harvest Clock Patent pending

pqcat harvest

Puts a number on how many asset-years of traffic an adversary can already have collected. HNDL stops being a slogan and becomes a measured exposure.

PQCAT Pro dashboard, Harvest Clock: 310 asset-years already collectable across 35 harvestable channels, earliest interception 2016, median Q-Day 2035.

Quantum X-Ray Patent pending

pqcat xray

Binds a verdict to excavated firmware bytes. A verifier re-dumps the region and re-derives the verdict from the hardware itself. Below the OS, where most scanners stop.

PQCAT Pro dashboard, Quantum X-Ray: a firmware image carved to two quantum-vulnerable artifacts, RSA-2048 and ECDSA-P256, located at their exact byte offsets.

Closed-Loop Remediator Patent pending

pqcat remediate prove

Binds before-state and after-state under one post-quantum signature. The finding closes only when verification passes. Find, fix, prove — in one command.

PQCAT Pro dashboard, Remediator: the hybrid post-quantum TLS playbook with the problem, the fix, the steps, and copy-paste nginx configuration.

Provenance Passport Patent pending

pqcat disclose

Prove posture while revealing only what you choose. Commits the full inventory under one root, opens exactly one asset class; everything else stays sealed. The dashboard requests a disclosure and verifies the answer, but it cannot produce one. Opening a class needs a master secret the server never holds.

PQCAT Pro dashboard, Provenance Passport: a disclosure request for the tls_certificate class, fulfilled and verified against the committed root. 12 assets opened, 44 leaves still sealed, and a register row recording the counterparty.
Compliance

Eleven frameworks. One normalized score.

PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.

CNSA 2.0NIST SP 800-131ANSM-10FISMAFedRAMPPCI DSS 4.0SOXHIPAANYDFS 500SWIFT CSPCMMC
The nine data items

Four of the nine cannot be scanned. They don’t exist in your infrastructure.

Federal reporting asks for nine data items per system. Five describe cryptography. Four describe the system itself: FISMA ID, FIPS 199 impact, HVA status, hosting. No scanner can find those. GSA says no known tool captures all nine.

PQCAT ingests your system of record (eMASS, CSAM, Xacta, CSV) and binds every cryptographic asset to the system that owns it. Every cell records how it got its value: discovered by a scanner, imported from a named export (with its digest), or asserted by a named person on a date.

The provenance is sealed under one ML-DSA-44 signature. Change an impact level after the fact and it fails closed.

What PQCAT builds on that binding
Reconciliation — separates newly discovered from newly deployed assets, so a higher count reads as better inventory, not worse posture.
Shared-responsibility proposal — splits your boundary between you and your cloud provider.
Cryptographic Agility Index — a published metric for a mandate that defines none.
Draft migration plan — covering all nine required plan sections, in CLI, Enclave, Pro, and Cloud.
Confidential Compliance Engine

Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.

Asset anonymization
BLAKE2b-salted asset IDs · no raw hostnames
Aggregate-only reporting
Statistical summaries · never per-asset detail
Verifiable score
Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
On the horizon
Preview CryptoLedger Tamper-evident posture history across scans
Preview Federated Exposure Grid Cross-org quantum exposure without sharing inventories

The evidence suite ships today. Challenge Coins, Harvest Clock, firmware carving, and Quantum X-Ray all run in the current release. Talk to us about early access.

Editions

Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime. Copy it, run it.

Enclave Apache 2.0

Air-gapped scanner · zero outbound network code
Download
Scanning
All 11 scanner modules
TLS, SSH, PKI, SBOM, Code, Config, HSM, SCAP, Image, CIDR, Firmware
Reporting
PDF, HTML, JSON, CBOM outputs
Scoring across all 11 frameworks
TUI dashboard (terminal-based)
Architecture
Pure static binary, zero CGO
Linux, macOS, Windows · amd64 + arm64
Zero outbound network code compiled in
Verify the air gap yourself go tool nm pqcat | grep 'http.(*Server)' Returns nothing. There is no HTTP server in the binary — not disabled, absent.

Pro ML-DSA-65 Signed

The Command Deck platform · team compliance
Talk to us

Everything in Enclave, plus:

Dashboard & API
Command Deck web dashboard
REST API · 22 endpoints
Multi-user RBAC (admin / auditor / viewer)
Prometheus /metrics endpoint
Enterprise
SIEM forwarding (Splunk, Sentinel, syslog)
Continuous drift monitoring + webhooks
Scan comparison and trend analysis
Reporting
Executive briefing PDF with cover page
Remediation playbooks per finding
Section 508 / WCAG 2.1 AA accessible

Cloud New

GovCloud & CSP scanner · FedRAMP-ready AMI
Talk to us

Everything in Pro, plus:

Cloud scanning
AWS KMS, ACM, ELB, S3, Route 53, IAM
Azure Key Vault, App Gateway, Front Door (roadmap)
Auto-detect CSP via IAM roles / env credentials
ReadOnlyAccess · zero write permissions
Risk analysis
Cloud-native quantum risk classification
HNDL exposure scoring per cloud resource
Deployment
Pre-built AWS Marketplace AMI
Zero-configuration, zero-write scanning
Deployable in GovCloud / FedRAMP environments

Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are delivered directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.

Run it

Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.