Two patents pending · from the team behind the Halborn-audited Soqucoin L1

Quantum-ready compliance starts with visibility.

PQCAT scans your infrastructure for quantum-vulnerable cryptography, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks — then proves it with evidence your auditors will accept.

install
# Linux / macOS curl -sSL https://install.pqcat.io | sh # Windows irm https://install.pqcat.io/windows | iex
PQCAT radar scan A scanner sweeps an inventory of cryptographic assets and classifies each by quantum risk: red (quantum-vulnerable, e.g. RSA/ECDSA), amber (transitional), green (post-quantum ready).
Fig. 1 — Every key, certificate, and cipher in your estate, classified by quantum risk.
quantum-vulnerable transitional post-quantum ready
§ 01 — Capabilities

Ten scanner modules across four domains. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and an actionable remediation plan.

01

NetworkTLS · SSH · discovery

TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.

02

Code & supply chainsource · SBOM · containers

Source analysis across 40+ languages, SBOM & supply-chain scanning against 183 quantum-vulnerable library signatures, and container-image inspection.

03

Infrastructureconfig · PKI · SCAP

Configuration analysis, full PKI & X.509 estate inventory, and SCAP compliance.

04

CloudCSP scanning · HNDL

AWS KMS, ACM, ELB, S3, Route 53, and IAM scanning, plus the patent-pending HNDL Risk Engine for per-asset harvest-now-decrypt-later exposure scoring.

§ 02 — Compliance

Eleven frameworks. One normalized score.

PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score — with the evidence to back it.

CNSA 2.0NIST SP 800-131ANSM-10FISMAFedRAMPPCI DSS 4.0SOXHIPAANYDFS 500SWIFT CSPCMMC
§ 03 — Confidential Compliance Engine

Prove compliance without revealing your infrastructure. The Confidential Compliance Engine — patent-pending — lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.

Asset anonymization
BLAKE2b-salted asset IDs · no raw hostnames
Aggregate-only reporting
Statistical summaries · never per-asset detail
Zero-knowledge proof
zk-STARK proof of compliance
§ 04 — Editions

Three editions, one engine. Single static binaries — no Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.

Free & open source

Enclave

Air-gapped scanner · Apache 2.0
  • All ten scanner modules
  • Scoring across all 11 frameworks
  • PDF / HTML / JSON / CBOM outputs
  • Pure static binary, zero CGO
Licensed · ML-DSA-65 signed

Pro

Team compliance platform
  • REST API & web dashboard
  • RBAC + SIEM forwarding
  • Executive PDF reporting
  • Section 508 / WCAG 2.1 AA
New

Cloud

GovCloud & CSP scanner
  • Deployable in AWS GovCloud / FedRAMP environments
  • AWS KMS, ACM, ELB, S3, Route 53, IAM
  • Patent-pending cloud assessment
  • Azure Key Vault & Front Door (roadmap)

Enclave is free and open source — download it and run it today. Pro and Cloud are available through Soqucoin Labs: contact us for a pilot or a license.

§ 05 — Run it

Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.