NetworkTLS · SSH · discovery
TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.
PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.
Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Seven patents pending.
The Pro Command Deck is built for one thing: get a security team from a target to a decision fast. No agents, no console training, no three-week onboarding.
Open the deck and type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. There is nothing to configure first.
The scan streams live, then resolves to a readiness score, the quantum-vulnerable / transitional / safe breakdown, and the full asset inventory. This is GitHub, assessed against CNSA 2.0 in about four seconds.
Every finding rolls up into a remediation playbook: the problem in plain terms, the target algorithm, and the copy-paste config for your platform, with the standards citation next to it. Other scanners hand a CISO a dashboard of red. PQCAT hands their engineer the patch.
Ten scanner modules across four domains. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and an actionable remediation plan.
TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.
Source analysis across 40+ languages, SBOM & supply-chain scanning against 183 quantum-vulnerable library signatures, and container-image inspection.
Configuration analysis, full PKI & X.509 estate inventory, and SCAP compliance.
AWS KMS, ACM, ELB, S3, Route 53, and IAM scanning, plus the patent-pending HNDL Risk Engine for per-asset harvest-now-decrypt-later exposure scoring.
Eleven frameworks. One normalized score.
PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.
Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.
A preview of what is coming to PQCAT: a battery of capabilities that reach past the scan into proof, disclosure, and evidence you can hand to anyone. Four are now patent pending with the USPTO, and the engineering lands with the next release.
The finding is only half the job. The Closed-Loop Remediator carries each fix through to proof that the change actually landed, and in the right order, ready to put in front of an auditor.
Prove your post-quantum posture to a regulator while revealing only the part you choose. Everything else stays sealed under the same published commitment.
The most durable quantum-vulnerable cryptography lives below the operating system. The Quantum X-Ray Scanner brings firmware and silicon into the inventory, with a verdict that re-derives from the hardware itself.
Harvest-now-decrypt-later stops being a slogan. The Harvest Clock puts a number on how much of your traffic an adversary can already collect, counting from the earliest interception time.
A durable, tamper-evident record of your compliance posture as it changes, so the story holds up long after any single scan.
Put verifiable proof on a screen at a booth or in a secure facility. Anyone walking by can check it for themselves. No trust required.
Hand an auditor a single file. They re-verify your evidence offline, on their own machine, and it fails closed the moment anything is altered.
A shared, cross-organization picture of quantum exposure across a mission, without any party surrendering its own inventory.
A preview, not a spec sheet. Some of these capabilities ship in the next release; others are in active development. Talk to Soqucoin Labs about early access for a federal or enterprise program.
Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.
Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are not sold self-serve; they are delivered and supported directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.
Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.