Leading the post-quantum shift.
PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.
Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Eight patents pending.
From target to decision in four steps. No agents, no console training, no onboarding.
One input covers your whole estate
Type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. Nothing to configure.
One score in seconds
The scan streams live, resolves to a readiness score with the vulnerable / transitional / safe breakdown and full asset inventory. GitHub, assessed against CNSA 2.0 in four seconds.
Copy-paste the fix
Every finding produces a remediation playbook with the exact config for your platform and the standards citation. Other scanners hand a CISO red. PQCAT hands their engineer the patch.
Evidence a skeptic can re-verify
The Challenge Coin is portable proof an auditor re-derives offline with no PQCAT installed. It fails closed the moment a byte is altered. No other scanner ships proof you can re-check yourself.
Ten scanner modules cover the estate, eleven with cloud. Five evidence instruments prove what they find. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and a remediation plan that names the fix.
Network
Deep TLS assessment, SSH key audit, and CIDR discovery across the perimeter.
Code & supply chain
Source analysis in 40+ languages, SBOM scanning against 183 quantum-vulnerable library signatures, and container-image inspection.
Infrastructure & firmware
Configuration analysis, PKI and X.509 estate inventory, SCAP compliance, and firmware carving that pulls certificates and keys straight out of UEFI capsules and flash dumps.
Cloud
AWS KMS, ACM, ELB, S3, Route 53, and IAM, with the patent-pending HNDL Risk Engine scoring each asset's harvest-now-decrypt-later exposure.
Challenge Coin & Prove-It Kiosk
pqcat coin
Portable proof an auditor re-verifies offline, on their own machine. Fails closed the moment a byte changes. Verify one in your browser now — same math, nothing uploaded.
Harvest Clock Patent pending
pqcat harvest
Puts a number on how many asset-years of traffic an adversary can already have collected. HNDL stops being a slogan and becomes a measured exposure.
Quantum X-Ray Patent pending
pqcat xray
Binds a verdict to excavated firmware bytes. A verifier re-dumps the region and re-derives the verdict from the hardware itself. Below the OS, where most scanners stop.
Closed-Loop Remediator Patent pending
pqcat remediate prove
Binds before-state and after-state under one post-quantum signature. The finding closes only when verification passes. Find, fix, prove — in one command.
Provenance Passport Patent pending
pqcat disclose
Prove posture while revealing only what you choose. Commits the full inventory under one root, opens exactly one asset class; everything else stays sealed.
Eleven frameworks. One normalized score.
PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.
Four of the nine cannot be scanned. They don’t exist in your infrastructure.
Federal reporting asks for nine data items per system. Five describe cryptography. Four describe the system itself: FISMA ID, FIPS 199 impact, HVA status, hosting. No scanner can find those. GSA says no known tool captures all nine.
PQCAT ingests your system of record (eMASS, CSAM, Xacta, CSV) and binds every cryptographic asset to the system that owns it. Every cell records how it got its value: discovered by a scanner, imported from a named export (with its digest), or asserted by a named person on a date.
The provenance is sealed under one ML-DSA-44 signature. Change an impact level after the fact and it fails closed.
What PQCAT builds on that binding
Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.
- Asset anonymization
- BLAKE2b-salted asset IDs · no raw hostnames
- Aggregate-only reporting
- Statistical summaries · never per-asset detail
- Verifiable score
- Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
The evidence suite ships today. Challenge Coins, Harvest Clock, firmware carving, and Quantum X-Ray all run in the current release. Talk to us about early access.
Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime. Copy it, run it.
Enclave Apache 2.0
Air-gapped scanner · zero outbound network codego tool nm pqcat | grep 'http.(*Server)'
Returns nothing. There is no HTTP server in the binary — not disabled, absent.
Pro ML-DSA-65 Signed
The Command Deck platform · team complianceEverything in Enclave, plus:
Cloud New
GovCloud & CSP scanner · FedRAMP-ready AMIEverything in Pro, plus:
Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are delivered directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.
Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.