Leading the post-quantum shift.

PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.

PQCAT · COMMAND DECK SIMULATION · faithful replay of a real scan
assess CNSA 2.0
github.com:443 · TLS estate
0
READY
0 assets 0 vulnerable 0 transitional 0 quantum-safe
TOP FIX Hybrid ML-KEM key exchange (X25519MLKEM768) →
A faithful replay of a real PQCAT scan. Run the same scan on your own domain →
install the free Enclave edition
# Linux / macOS curl -sSL https://install.pqcat.io | sh # Windows irm https://install.pqcat.io/windows | iex

Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Twelve patents pending.

See it work

From target to decision in four steps. No agents, no console training, no onboarding.

One input covers your whole estate

Type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. Nothing to configure.

PQCAT Command Deck: a single target input and an Assess button.

One score in seconds

The scan streams live, resolves to a readiness score with the vulnerable / transitional / safe breakdown and full asset inventory. GitHub, assessed against CNSA 2.0 in four seconds.

A completed assessment: readiness score dial, zone breakdown, and asset counts.

Copy-paste the fix

Every finding produces a remediation playbook with the exact config for your platform and the standards citation. Other scanners hand a CISO red. PQCAT hands their engineer the patch.

Remediation playbook with copy-paste nginx, Apache, and HAProxy configuration for hybrid post-quantum TLS.

Evidence a skeptic can re-verify

The Challenge Coin is portable proof an auditor re-derives offline with no PQCAT installed. It fails closed the moment a byte is altered. No other scanner ships proof you can re-check yourself.

PQCAT evidence suite: a minted Challenge Coin with a downloadable proof file.
Capabilities

Ten scanner modules cover the estate, eleven with cloud. Five evidence instruments prove what they find. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and a remediation plan that names the fix.

Scan coverage10 modules · 4 surfaces · +cloud in the Cloud edition
TLS · SSH · discovery

Network

Deep TLS assessment, SSH key audit, and CIDR discovery across the perimeter.

source · SBOM · containers

Code & supply chain

Source analysis in 40+ languages, SBOM scanning against 183 quantum-vulnerable library signatures, and container-image inspection.

config · PKI · SCAP · firmware

Infrastructure & firmware

Configuration analysis, PKI and X.509 estate inventory, SCAP compliance, and firmware carving that pulls certificates and keys straight out of UEFI capsules and flash dumps.

CSP scanning · HNDL

Cloud

AWS KMS, ACM, ELB, S3, Route 53, and IAM, with the patent-pending HNDL Risk Engine scoring each asset's harvest-now-decrypt-later exposure.

Evidence instrumentsproof a skeptic can re-run · fails closed

Challenge Coin & Prove-It Kiosk

pqcat coin

Portable proof an auditor re-verifies offline, on their own machine. Fails closed the moment a byte changes. Verify one in your browser now. Same math, nothing uploaded.

PQCAT Challenge Coin: a tamper-evident compliance proof minted from a scan.

Harvest Clock Patent pending

pqcat harvest

Puts a number on how many asset-years of traffic an adversary can already have collected. HNDL stops being a slogan and becomes a measured exposure.

PQCAT Pro dashboard, Harvest Clock: 310 asset-years already collectable across 35 harvestable channels, earliest interception 2016, median Q-Day 2035.

Quantum X-Ray Patent pending

pqcat xray

Binds a verdict to excavated firmware bytes. A verifier re-dumps the region and re-derives the verdict from the hardware itself. Below the OS, where most scanners stop.

PQCAT Pro dashboard, Quantum X-Ray: a firmware image carved to two quantum-vulnerable artifacts, RSA-2048 and ECDSA-P256, located at their exact byte offsets.

Closed-Loop Remediator Patent pending

pqcat remediate prove

Binds before-state and after-state under one post-quantum signature. The finding closes only when verification passes. Find, fix and prove, in one command.

PQCAT Pro dashboard, Remediator: the hybrid post-quantum TLS playbook with the problem, the fix, the steps, and copy-paste nginx configuration.

Provenance Passport Patent pending

pqcat disclose

Prove posture while revealing only what you choose. Commits the full inventory under one root, opens exactly one asset class; everything else stays sealed. The dashboard requests a disclosure and verifies the answer, but it cannot produce one. Opening a class needs a master secret the server never holds.

PQCAT Pro dashboard, Provenance Passport: a disclosure request for the tls_certificate class, fulfilled and verified against the committed root. 12 assets opened, 44 leaves still sealed, and a register row recording the counterparty.
Compliance

Eleven frameworks. One normalized score.

PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.

CNSA 2.0NIST SP 800-131ANSM-10FISMAFedRAMPPCI DSS 4.0SOXHIPAANYDFS 500SWIFT CSPCMMC
The nine data items

Four of the nine cannot be scanned. They don’t exist in your infrastructure.

Federal reporting asks for nine data items per system. Five describe cryptography. Four describe the system itself: FISMA ID, FIPS 199 impact, HVA status, hosting. No scanner can find those. GSA says no known tool captures all nine.

PQCAT ingests your system of record (eMASS, CSAM, Xacta, CSV) and binds every cryptographic asset to the system that owns it. Every cell records how it got its value: discovered by a scanner, imported from a named export (with its digest), or asserted by a named person on a date.

The provenance is sealed under one ML-DSA-44 signature. Change an impact level after the fact and it fails closed.

What PQCAT builds on that binding
Reconciliation. Separates newly discovered from newly deployed assets, so a higher count reads as better inventory rather than worse posture.
Shared-responsibility proposal. Splits your boundary between you and your cloud provider.
Cryptographic Agility Index. A published metric for a mandate that defines none.
Draft migration plan. Covers all nine required plan sections, and needs no licence.
Confidential Compliance Engine

Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.

Asset anonymization
BLAKE2b-salted asset IDs · no raw hostnames
Aggregate-only reporting
Statistical summaries · never per-asset detail
Verifiable score
Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
Get it

Every capability is free on up to 25 hosts per scan. Not a feature-limited demo: the scanners, the scoring, the web dashboard, the Challenge Coins and the reports, all of it. A licence raises the scope and adds what only starts to matter once this is a programme rather than an evaluation.

Start here, no licence, no form

Install it, point it at something you own, and read the report. The 25-host bound is enough to see the whole evidence chain work end to end, and small enough that it is not a deliverable.

curl -sSL https://install.pqcat.io | sh pqcat scan tls your-domain.com

Two questions people mix up, so answer them separately. Which binary do I have is decided at build time and a licence will not change it. What am I entitled to use is decided by the licence and a rebuild will not change it. The most common mix-up is expecting a licence to switch on cloud scanning; it cannot, because cloud is compiled in.

Enclave Apache 2.0

Air-gapped scanner · zero outbound network code
Download
Scanning
All 10 offline scanner modules
TLS, SSH, PKI, SBOM, Code, Config, HSM, SCAP, Image, Firmware
Reporting
PDF, HTML, JSON, CBOM outputs
Scoring across all 11 frameworks
TUI dashboard (terminal-based)
Architecture
Pure static binary, zero CGO
Linux, macOS, Windows · amd64 + arm64
Zero outbound network code compiled in
Verify the air gap yourself go tool nm pqcat | grep 'http.(*Server)' Returns nothing. There is no HTTP server in the binary. Not disabled, absent.

Pro ML-DSA-65 Signed

Everything in Enclave, plus a server
Ask for the binary

What this build adds:

Runs as a service
Command Deck web dashboard (no licence needed)
REST API · 50+ endpoints
Scan history in a local database
Compiled in, licence-gated
Accounts and roles, for more than one person
SIEM forwarding and Prometheus metrics
Scheduled scans and drift over time
Reporting
Executive briefing PDF (no licence needed)
Remediation playbooks per finding
Section 508 / WCAG 2.1 AA accessible
How you get this one today The public download is the Enclave edition. The Pro archive is not on the public release yet, so ask and we will send it the same day. There is no trial key to chase and no call to sit through: it runs on 25 hosts the moment you unzip it.

Cloud Enterprise licence

Everything in Pro, plus the CSP APIs
Ask for the binary

What this build adds. Cloud scanning is the one capability a licence does gate, because it reads a whole account rather than a host you pointed at:

Cloud scanning
AWS KMS, ACM, ELB, S3, Route 53, IAM
Azure Key Vault, App Gateway, Front Door (roadmap)
Auto-detect CSP via IAM roles / env credentials
ReadOnlyAccess · zero write permissions
Risk analysis
Cloud-native quantum risk classification
HNDL exposure scoring per cloud resource
Deployment
Pre-built AWS Marketplace AMI
Zero-configuration, zero-write scanning
Deployable in GovCloud / FedRAMP environments
What a licence adds

Capability is not what is for sale. Scale, automation, more than one person, integration with what you already run, and the submission formats an authority will accept: those are. Each tier below is a job someone is doing, not a feature list.

No licence
The evaluator
"Is my estate exposed, and is any of this real?"
25 hosts per scan
  • All ten offline scanner modules
  • Scoring across every framework
  • Challenge Coins and selective disclosure
  • The web dashboard and the REST API
  • PDF, HTML, CBOM and executive briefings
Download it
Professional
The deliverable owner
"I have to produce an inventory and a migration plan."
500 hosts per scan
  • Everything above, at estate scale
  • Drift between scans, so posture becomes a trend rather than a snapshot
Talk to us
Enterprise
The programme
"This runs continuously, and several teams touch it."
10,000 hosts per scan
  • Accounts and roles, for more than one person
  • Scheduled scans and webhooks
  • SIEM forwarding and Prometheus metrics
  • Cloud scanning across AWS, with CSP auto-detect
  • Vendor supply-chain analysis
Talk to us
Federal
The submitter
"I have to hand this to an authority."
Unlimited scope
  • Everything in Enterprise
  • ATO package assembly
  • eMASS integration
Talk to us

Need to pilot at real scale before you decide? pqcat license trial starts a fourteen-day evaluation at 250 hosts with the Enterprise feature set, so you can answer the questions the free bound cannot: does it hold up across the estate, does it run on a schedule, does it land in our SIEM. It is hardware-bound, signed, and validated entirely offline. When it lapses the product keeps working, back at 25 hosts.

Run it

Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.