See the cryptography a quantum computer will break.

PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.

PQCAT · COMMAND DECK SIMULATION · faithful replay of a real scan
assess CNSA 2.0
github.com:443 · TLS estate
0
READY
0 assets 0 vulnerable 0 transitional 0 quantum-safe
TOP FIX Hybrid ML-KEM key exchange (X25519MLKEM768) →
A faithful replay of a real PQCAT scan. Run the same scan on your own domain →
install the free Enclave edition
# Linux / macOS curl -sSL https://install.pqcat.io | sh # Windows irm https://install.pqcat.io/windows | iex

Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Seven patents pending.

See it work

The Pro Command Deck is built for one thing: get a security team from a target to a decision fast. No agents, no console training, no three-week onboarding.

01 · Start

One input covers your whole estate

Open the deck and type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. There is nothing to configure first.

PQCAT Command Deck: a single target input and an Assess button.
The Command Deck runs the whole assessment from a single field.
02 · See

The whole scan resolves to one score in seconds

The scan streams live, then resolves to a readiness score, the quantum-vulnerable / transitional / safe breakdown, and the full asset inventory. This is GitHub, assessed against CNSA 2.0 in about four seconds.

A completed assessment: readiness score dial, zone breakdown, and asset counts.
Score, zones, and one-click paths to the report and the fix.
03 · Fix

It shows you how to fix what it finds

Every finding rolls up into a remediation playbook: the problem in plain terms, the target algorithm, and the copy-paste config for your platform, with the standards citation next to it. Other scanners hand a CISO a dashboard of red. PQCAT hands their engineer the patch.

Remediation playbook with copy-paste nginx, Apache, and HAProxy configuration for hybrid post-quantum TLS.
Hybrid post-quantum TLS, ready to paste into nginx, Apache, or HAProxy.
Capabilities

Ten scanner modules across four domains. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and an actionable remediation plan.

01

NetworkTLS · SSH · discovery

TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.

02

Code & supply chainsource · SBOM · containers

Source analysis across 40+ languages, SBOM & supply-chain scanning against 183 quantum-vulnerable library signatures, and container-image inspection.

03

Infrastructureconfig · PKI · SCAP

Configuration analysis, full PKI & X.509 estate inventory, and SCAP compliance.

04

CloudCSP scanning · HNDL

AWS KMS, ACM, ELB, S3, Route 53, and IAM scanning, plus the patent-pending HNDL Risk Engine for per-asset harvest-now-decrypt-later exposure scoring.

Compliance

Eleven frameworks. One normalized score.

PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.

CNSA 2.0NIST SP 800-131ANSM-10FISMAFedRAMPPCI DSS 4.0SOXHIPAANYDFS 500SWIFT CSPCMMC
Confidential Compliance Engine

Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.

Asset anonymization
BLAKE2b-salted asset IDs · no raw hostnames
Aggregate-only reporting
Statistical summaries · never per-asset detail
Verifiable score
Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
On the horizon

A preview of what is coming to PQCAT: a battery of capabilities that reach past the scan into proof, disclosure, and evidence you can hand to anyone. Four are now patent pending with the USPTO, and the engineering lands with the next release.

01

Closed-Loop Remediator Patent pendingfind · fix · prove

The finding is only half the job. The Closed-Loop Remediator carries each fix through to proof that the change actually landed, and in the right order, ready to put in front of an auditor.

02

PQCAT Provenance Passport Patent pendingselective disclosure

Prove your post-quantum posture to a regulator while revealing only the part you choose. Everything else stays sealed under the same published commitment.

03

Quantum X-Ray Scanner Patent pendingfirmware · silicon

The most durable quantum-vulnerable cryptography lives below the operating system. The Quantum X-Ray Scanner brings firmware and silicon into the inventory, with a verdict that re-derives from the hardware itself.

04

Harvest Clock with T0 Patent pendingexposure, quantified

Harvest-now-decrypt-later stops being a slogan. The Harvest Clock puts a number on how much of your traffic an adversary can already collect, counting from the earliest interception time.

05

PQCAT CryptoLedger Previewposture, over time

A durable, tamper-evident record of your compliance posture as it changes, so the story holds up long after any single scan.

06

Prove-It Kiosk Previewverify it yourself

Put verifiable proof on a screen at a booth or in a secure facility. Anyone walking by can check it for themselves. No trust required.

07

PQCAT Challenge Coin Previewportable evidence

Hand an auditor a single file. They re-verify your evidence offline, on their own machine, and it fails closed the moment anything is altered.

08

Federated NORAD Exposure Grid Previewshared exposure view

A shared, cross-organization picture of quantum exposure across a mission, without any party surrendering its own inventory.

A preview, not a spec sheet. Some of these capabilities ship in the next release; others are in active development. Talk to Soqucoin Labs about early access for a federal or enterprise program.

Editions

Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.

Free & open source

Enclave

Air-gapped scanner · Apache 2.0
  • All ten scanner modules
  • Scoring across all 11 frameworks
  • PDF / HTML / JSON / CBOM outputs
  • Pure static binary, zero CGO
Federal & enterprise

Pro

The Command Deck platform
  • Command Deck, REST API & web dashboard
  • RBAC + SIEM forwarding
  • Remediation playbooks & executive reporting
  • Section 508 / WCAG 2.1 AA
Federal & enterprise

Cloud

GovCloud & CSP scanner
  • Deployable in AWS GovCloud / FedRAMP environments
  • AWS KMS, ACM, ELB, S3, Route 53, IAM
  • Patent-pending cloud assessment
  • Azure Key Vault & Front Door (roadmap)

Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are not sold self-serve; they are delivered and supported directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.

Run it

Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.