NetworkTLS · SSH · discovery
TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.
PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.
Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Seven patents pending.
The Pro Command Deck is built for one thing: get a security team from a target to a decision fast. No agents, no console training, no three-week onboarding.
Open the deck and type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. There is nothing to configure first.
The scan streams live, then resolves to a readiness score, the quantum-vulnerable / transitional / safe breakdown, and the full asset inventory. This is GitHub, assessed against CNSA 2.0 in about four seconds.
Every finding rolls up into a remediation playbook: the problem in plain terms, the target algorithm, and the copy-paste config for your platform, with the standards citation next to it. Other scanners hand a CISO a dashboard of red. PQCAT hands their engineer the patch.
Ten scanner modules across four domains. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and an actionable remediation plan. New in v2.9: the verifiable evidence suite, offline-verifiable artifacts that fail closed on any tampering.
TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.
Source analysis across 40+ languages, SBOM & supply-chain scanning against 183 quantum-vulnerable library signatures, and container-image inspection.
Configuration analysis, full PKI & X.509 estate inventory, and SCAP compliance.
AWS KMS, ACM, ELB, S3, Route 53, and IAM scanning, plus the patent-pending HNDL Risk Engine for per-asset harvest-now-decrypt-later exposure scoring.
The finding is only half the job. pqcat remediate prove binds the before-state and after-state of the same asset under one post-quantum signature, and the finding closes only if verification passes.
Prove your post-quantum posture while revealing only the part you choose. pqcat disclose commits the inventory under one root and opens exactly one asset class; everything else stays sealed.
The most durable quantum-vulnerable cryptography lives below the operating system. pqcat xray binds a verdict to the exact excavated firmware bytes; a verifier re-dumps the region and the verdict re-derives from the hardware itself.
Harvest-now-decrypt-later stops being a slogan. pqcat harvest puts a number on how many asset-years of your traffic an adversary can already have collected, and flags what is effectively already disclosed.
Hand an auditor one file. pqcat coin mints portable evidence they re-verify offline, on their own machine, and it fails closed the moment anything is altered. pqcat kiosk renders it as a placard for a booth screen or a secure facility.
Eleven frameworks. One normalized score.
PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.
Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.
Six of the eight capabilities we previewed here now ship in v2.9 and live under Capabilities above. Two remain ahead: names and intent only, the engineering follows.
A durable, tamper-evident record of your compliance posture as it changes, so the story holds up long after any single scan.
A shared, cross-organization picture of quantum exposure across a mission, without any party surrendering its own inventory.
A preview, not a spec sheet. Some of these capabilities ship in the next release; others are in active development. Talk to Soqucoin Labs about early access for a federal or enterprise program.
Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.
Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are not sold self-serve; they are delivered and supported directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.
Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.