NetworkTLS · SSH · discovery
TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.
PQCAT scans your infrastructure for quantum-vulnerable cryptography, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks — then proves it with evidence your auditors will accept.
Ten scanner modules across four domains. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and an actionable remediation plan.
TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.
Source analysis across 40+ languages, SBOM & supply-chain scanning against 183 quantum-vulnerable library signatures, and container-image inspection.
Configuration analysis, full PKI & X.509 estate inventory, and SCAP compliance.
AWS KMS, ACM, ELB, S3, Route 53, and IAM scanning, plus the patent-pending HNDL Risk Engine for per-asset harvest-now-decrypt-later exposure scoring.
Eleven frameworks. One normalized score.
PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score — with the evidence to back it.
Prove compliance without revealing your infrastructure. The Confidential Compliance Engine — patent-pending — lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.
Three editions, one engine. Single static binaries — no Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.
Enclave is free and open source — download it and run it today. Pro and Cloud are available through Soqucoin Labs: contact us for a pilot or a license.
Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.