See the cryptography a quantum computer will break.

PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.

PQCAT · COMMAND DECK SIMULATION · faithful replay of a real scan
assess CNSA 2.0
github.com:443 · TLS estate
0
READY
0 assets 0 vulnerable 0 transitional 0 quantum-safe
TOP FIX Hybrid ML-KEM key exchange (X25519MLKEM768) →
A faithful replay of a real PQCAT scan. Run the same scan on your own domain →
install the free Enclave edition
# Linux / macOS curl -sSL https://install.pqcat.io | sh # Windows irm https://install.pqcat.io/windows | iex

Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Two patents pending.

See it work

The Pro Command Deck is built for one thing: get a security team from a target to a decision fast. No agents, no console training, no three-week onboarding.

01 · Start

One input covers your whole estate

Open the deck and type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. There is nothing to configure first.

PQCAT Command Deck: a single target input and an Assess button.
The Command Deck runs the whole assessment from a single field.
02 · See

The whole scan resolves to one score in seconds

The scan streams live, then resolves to a readiness score, the quantum-vulnerable / transitional / safe breakdown, and the full asset inventory. This is GitHub, assessed against CNSA 2.0 in about four seconds.

A completed assessment: readiness score dial, zone breakdown, and asset counts.
Score, zones, and one-click paths to the report and the fix.
03 · Fix

It shows you how to fix what it finds

Every finding rolls up into a remediation playbook: the problem in plain terms, the target algorithm, and the copy-paste config for your platform, with the standards citation next to it. Other scanners hand a CISO a dashboard of red. PQCAT hands their engineer the patch.

Remediation playbook with copy-paste nginx, Apache, and HAProxy configuration for hybrid post-quantum TLS.
Hybrid post-quantum TLS, ready to paste into nginx, Apache, or HAProxy.
Capabilities

Ten scanner modules across four domains. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and an actionable remediation plan.

01

NetworkTLS · SSH · discovery

TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.

02

Code & supply chainsource · SBOM · containers

Source analysis across 40+ languages, SBOM & supply-chain scanning against 183 quantum-vulnerable library signatures, and container-image inspection.

03

Infrastructureconfig · PKI · SCAP

Configuration analysis, full PKI & X.509 estate inventory, and SCAP compliance.

04

CloudCSP scanning · HNDL

AWS KMS, ACM, ELB, S3, Route 53, and IAM scanning, plus the patent-pending HNDL Risk Engine for per-asset harvest-now-decrypt-later exposure scoring.

Compliance

Eleven frameworks. One normalized score.

PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.

CNSA 2.0NIST SP 800-131ANSM-10FISMAFedRAMPPCI DSS 4.0SOXHIPAANYDFS 500SWIFT CSPCMMC
Confidential Compliance Engine

Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.

Asset anonymization
BLAKE2b-salted asset IDs · no raw hostnames
Aggregate-only reporting
Statistical summaries · never per-asset detail
Verifiable score
Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
Editions

Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.

Free & open source

Enclave

Air-gapped scanner · Apache 2.0
  • All ten scanner modules
  • Scoring across all 11 frameworks
  • PDF / HTML / JSON / CBOM outputs
  • Pure static binary, zero CGO
Federal & enterprise

Pro

The Command Deck platform
  • Command Deck, REST API & web dashboard
  • RBAC + SIEM forwarding
  • Remediation playbooks & executive reporting
  • Section 508 / WCAG 2.1 AA
Federal & enterprise

Cloud

GovCloud & CSP scanner
  • Deployable in AWS GovCloud / FedRAMP environments
  • AWS KMS, ACM, ELB, S3, Route 53, IAM
  • Patent-pending cloud assessment
  • Azure Key Vault & Front Door (roadmap)

Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are not sold self-serve; they are delivered and supported directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.

Run it

Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.