Leading the post-quantum shift.

PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.

PQCAT · COMMAND DECK SIMULATION · faithful replay of a real scan
assess CNSA 2.0
github.com:443 · TLS estate
0
READY
0 assets 0 vulnerable 0 transitional 0 quantum-safe
TOP FIX Hybrid ML-KEM key exchange (X25519MLKEM768) →
A faithful replay of a real PQCAT scan. Run the same scan on your own domain →
install the free Enclave edition
# Linux / macOS curl -sSL https://install.pqcat.io | sh # Windows irm https://install.pqcat.io/windows | iex

Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Seven patents pending.

See it work

The Pro Command Deck is built for one thing: get a security team from a target to a decision fast. No agents, no console training, no three-week onboarding.

01 · Start

One input covers your whole estate

Open the deck and type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. There is nothing to configure first.

PQCAT Command Deck: a single target input and an Assess button.
The Command Deck runs the whole assessment from a single field.
02 · See

The whole scan resolves to one score in seconds

The scan streams live, then resolves to a readiness score, the quantum-vulnerable / transitional / safe breakdown, and the full asset inventory. This is GitHub, assessed against CNSA 2.0 in about four seconds.

A completed assessment: readiness score dial, zone breakdown, and asset counts.
Score, zones, and one-click paths to the report and the fix.
03 · Fix

It shows you how to fix what it finds

Every finding rolls up into a remediation playbook: the problem in plain terms, the target algorithm, and the copy-paste config for your platform, with the standards citation next to it. Other scanners hand a CISO a dashboard of red. PQCAT hands their engineer the patch.

Remediation playbook with copy-paste nginx, Apache, and HAProxy configuration for hybrid post-quantum TLS.
Hybrid post-quantum TLS, ready to paste into nginx, Apache, or HAProxy.
04 · Prove

Hand over evidence a skeptic can re-verify

The evidence suite mints a portable Challenge Coin from any assessment. Hand it to an auditor and they re-derive the exact verdict offline, on their own machine, with no PQCAT and no trust in you. It fails closed the moment a byte is altered. The same tab carves firmware for the hardware-rooted Quantum X-Ray verdict. No other scanner ships proof you can re-check yourself.

PQCAT evidence suite: a minted Challenge Coin with a downloadable proof file, and the Quantum X-Ray firmware carve.
A minted Challenge Coin and the Quantum X-Ray firmware carve, verifiable anywhere.
Capabilities

Eleven scanner modules cover the estate. Five evidence instruments prove what they find. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and a remediation plan that names the fix.

Scan coverage11 modules · 4 surfaces
TLS · SSH · discovery

Network

Deep TLS assessment, SSH key audit, and CIDR discovery across the perimeter.

source · SBOM · containers

Code & supply chain

Source analysis in 40+ languages, SBOM scanning against 183 quantum-vulnerable library signatures, and container-image inspection.

config · PKI · SCAP · firmware

Infrastructure & firmware

Configuration analysis, PKI and X.509 estate inventory, SCAP compliance, and firmware carving that pulls certificates and keys straight out of UEFI capsules and flash dumps.

CSP scanning · HNDL

Cloud

AWS KMS, ACM, ELB, S3, Route 53, and IAM, with the patent-pending HNDL Risk Engine scoring each asset's harvest-now-decrypt-later exposure.

Evidence instrumentsproof a skeptic can re-run · fails closed
remediate

Closed-Loop Remediator Patent pendingfind · fix · prove

The finding is only half the job. pqcat remediate prove binds the before-state and after-state of the same asset under one post-quantum signature, and the finding closes only if verification passes.

disclose

PQCAT Provenance Passport Patent pendingselective disclosure

Prove your post-quantum posture while revealing only the part you choose. pqcat disclose commits the inventory under one root and opens exactly one asset class; everything else stays sealed.

xray

Quantum X-Ray Patent pendingfirmware · silicon

The most durable quantum-vulnerable cryptography lives below the operating system. pqcat xray binds a verdict to the exact excavated firmware bytes; a verifier re-dumps the region and the verdict re-derives from the hardware itself.

harvest

Harvest Clock Patent pendingexposure, quantified

Harvest-now-decrypt-later stops being a slogan. pqcat harvest puts a number on how many asset-years of your traffic an adversary can already have collected, and flags what is effectively already disclosed.

coin

Challenge Coin & Prove-It Kioskportable evidence

Hand an auditor one file. pqcat coin mints portable evidence they re-verify offline, on their own machine, and it fails closed the moment anything is altered. pqcat kiosk renders it as a placard for a booth screen or a secure facility. Or skip the install entirely: verify a coin in your browser, right now. Same math as the CLI, nothing uploaded.

Compliance

Eleven frameworks. One normalized score.

PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.

CNSA 2.0NIST SP 800-131ANSM-10FISMAFedRAMPPCI DSS 4.0SOXHIPAANYDFS 500SWIFT CSPCMMC
Confidential Compliance Engine

Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.

Asset anonymization
BLAKE2b-salted asset IDs · no raw hostnames
Aggregate-only reporting
Statistical summaries · never per-asset detail
Verifiable score
Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
On the horizon

Six of the eight capabilities we previewed here now ship in v2.9 and live under Capabilities above. Two remain ahead: names and intent only, the engineering follows.

01

PQCAT CryptoLedger Previewposture, over time

A durable, tamper-evident record of your compliance posture as it changes, so the story holds up long after any single scan.

02

Federated NORAD Exposure Grid Previewshared exposure view

A shared, cross-organization picture of quantum exposure across a mission, without any party surrendering its own inventory.

Where this stands. The evidence suite ships today: portable Challenge Coins, the Harvest Clock, firmware carving, and the hardware-rooted Quantum X-Ray verdict all run in the current release, in the CLI and the Pro dashboard, and any Challenge Coin can be re-verified in a browser with nothing installed. A few capabilities on this page are still in active development. Talk to Soqucoin Labs about early access for a federal or enterprise program.

Editions

Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.

Free & open source

Enclave

Air-gapped scanner · Apache 2.0
  • All ten scanner modules
  • Scoring across all 11 frameworks
  • PDF / HTML / JSON / CBOM outputs
  • Pure static binary, zero CGO
Federal & enterprise

Pro

The Command Deck platform
  • Command Deck, REST API & web dashboard
  • RBAC + SIEM forwarding
  • Remediation playbooks & executive reporting
  • Section 508 / WCAG 2.1 AA
Federal & enterprise

Cloud

GovCloud & CSP scanner
  • Deployable in AWS GovCloud / FedRAMP environments
  • AWS KMS, ACM, ELB, S3, Route 53, IAM
  • Patent-pending cloud assessment
  • Azure Key Vault & Front Door (roadmap)

Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are not sold self-serve; they are delivered and supported directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.

Run it

Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.