See the cryptography a quantum computer will break.

PQCAT inventories every key, certificate, cipher, and dependency across your estate, scores it against CNSA 2.0, NIST SP 800-131A, and 11 regulatory frameworks, then hands your engineers the exact fix for each finding.

PQCAT · COMMAND DECK SIMULATION · faithful replay of a real scan
assess CNSA 2.0
github.com:443 · TLS estate
0
READY
0 assets 0 vulnerable 0 transitional 0 quantum-safe
TOP FIX Hybrid ML-KEM key exchange (X25519MLKEM768) →
A faithful replay of a real PQCAT scan. Run the same scan on your own domain →
install the free Enclave edition
# Linux / macOS curl -sSL https://install.pqcat.io | sh # Windows irm https://install.pqcat.io/windows | iex

Built by the team behind the Halborn-audited Soqucoin post-quantum L1. Seven patents pending.

See it work

The Pro Command Deck is built for one thing: get a security team from a target to a decision fast. No agents, no console training, no three-week onboarding.

01 · Start

One input covers your whole estate

Open the deck and type a target. PQCAT auto-detects what to scan across TLS, SSH, source, SBOMs, and container images. There is nothing to configure first.

PQCAT Command Deck: a single target input and an Assess button.
The Command Deck runs the whole assessment from a single field.
02 · See

The whole scan resolves to one score in seconds

The scan streams live, then resolves to a readiness score, the quantum-vulnerable / transitional / safe breakdown, and the full asset inventory. This is GitHub, assessed against CNSA 2.0 in about four seconds.

A completed assessment: readiness score dial, zone breakdown, and asset counts.
Score, zones, and one-click paths to the report and the fix.
03 · Fix

It shows you how to fix what it finds

Every finding rolls up into a remediation playbook: the problem in plain terms, the target algorithm, and the copy-paste config for your platform, with the standards citation next to it. Other scanners hand a CISO a dashboard of red. PQCAT hands their engineer the patch.

Remediation playbook with copy-paste nginx, Apache, and HAProxy configuration for hybrid post-quantum TLS.
Hybrid post-quantum TLS, ready to paste into nginx, Apache, or HAProxy.
Capabilities

Ten scanner modules across four domains. Every scan produces a normalized 0–100 compliance score, a cryptographic bill of materials (CBOM), and an actionable remediation plan. New in v2.9: the verifiable evidence suite, offline-verifiable artifacts that fail closed on any tampering.

01

NetworkTLS · SSH · discovery

TLS deep scan (fast, fully-parallelized assessment), SSH key audit, and network/CIDR discovery across your perimeter.

02

Code & supply chainsource · SBOM · containers

Source analysis across 40+ languages, SBOM & supply-chain scanning against 183 quantum-vulnerable library signatures, and container-image inspection.

03

Infrastructureconfig · PKI · SCAP

Configuration analysis, full PKI & X.509 estate inventory, and SCAP compliance.

04

CloudCSP scanning · HNDL

AWS KMS, ACM, ELB, S3, Route 53, and IAM scanning, plus the patent-pending HNDL Risk Engine for per-asset harvest-now-decrypt-later exposure scoring.

05

Closed-Loop Remediator Patent pendingfind · fix · prove

The finding is only half the job. pqcat remediate prove binds the before-state and after-state of the same asset under one post-quantum signature, and the finding closes only if verification passes.

06

PQCAT Provenance Passport Patent pendingselective disclosure

Prove your post-quantum posture while revealing only the part you choose. pqcat disclose commits the inventory under one root and opens exactly one asset class; everything else stays sealed.

07

Quantum X-Ray Patent pendingfirmware · silicon

The most durable quantum-vulnerable cryptography lives below the operating system. pqcat xray binds a verdict to the exact excavated firmware bytes; a verifier re-dumps the region and the verdict re-derives from the hardware itself.

08

Harvest Clock Patent pendingexposure, quantified

Harvest-now-decrypt-later stops being a slogan. pqcat harvest puts a number on how many asset-years of your traffic an adversary can already have collected, and flags what is effectively already disclosed.

09

Challenge Coin & Prove-It Kioskportable evidence

Hand an auditor one file. pqcat coin mints portable evidence they re-verify offline, on their own machine, and it fails closed the moment anything is altered. pqcat kiosk renders it as a placard for a booth screen or a secure facility.

Compliance

Eleven frameworks. One normalized score.

PQCAT maps every finding to the frameworks regulators and auditors actually use, and rolls them into a single 0–100 readiness score, with the evidence to back it.

CNSA 2.0NIST SP 800-131ANSM-10FISMAFedRAMPPCI DSS 4.0SOXHIPAANYDFS 500SWIFT CSPCMMC
Confidential Compliance Engine

Prove compliance without revealing your infrastructure. The Confidential Compliance Engine (patent-pending) lets you run pqcat scan --confidential and produce a report that demonstrates readiness without exposing a single hostname.

Asset anonymization
BLAKE2b-salted asset IDs · no raw hostnames
Aggregate-only reporting
Statistical summaries · never per-asset detail
Verifiable score
Transparent hash-based proof (Merkle + Fiat-Shamir, no trusted setup)
On the horizon

Six of the eight capabilities we previewed here now ship in v2.9 and live under Capabilities above. Two remain ahead: names and intent only, the engineering follows.

01

PQCAT CryptoLedger Previewposture, over time

A durable, tamper-evident record of your compliance posture as it changes, so the story holds up long after any single scan.

02

Federated NORAD Exposure Grid Previewshared exposure view

A shared, cross-organization picture of quantum exposure across a mission, without any party surrendering its own inventory.

A preview, not a spec sheet. Some of these capabilities ship in the next release; others are in active development. Talk to Soqucoin Labs about early access for a federal or enterprise program.

Editions

Three editions, one engine. Single static binaries. No Docker, no Java, no Python runtime, no shared libraries. Copy it, run it.

Free & open source

Enclave

Air-gapped scanner · Apache 2.0
  • All ten scanner modules
  • Scoring across all 11 frameworks
  • PDF / HTML / JSON / CBOM outputs
  • Pure static binary, zero CGO
Federal & enterprise

Pro

The Command Deck platform
  • Command Deck, REST API & web dashboard
  • RBAC + SIEM forwarding
  • Remediation playbooks & executive reporting
  • Section 508 / WCAG 2.1 AA
Federal & enterprise

Cloud

GovCloud & CSP scanner
  • Deployable in AWS GovCloud / FedRAMP environments
  • AWS KMS, ACM, ELB, S3, Route 53, IAM
  • Patent-pending cloud assessment
  • Azure Key Vault & Front Door (roadmap)

Enclave is free and open source. Download it from GitHub or install it with the one-liner above. Pro and Cloud are not sold self-serve; they are delivered and supported directly for federal and enterprise programs. Talk to Soqucoin Labs about a pilot.

Run it

Try the live TLS server test in your browser, or install the scanner and run a full assessment against your own estate. Enclave is free and open source.