PQCA

Post-Quantum Cryptographic Analyzer

Flagship platform

Post-Quantum Cryptographic Analyzer

Prove control of your cryptography before quantum breaks it.
PQCA discovers, inventories and quantum-risk-assesses the cryptography running across your entire estate — producing an evidence-based Cryptographic Bill of Materials, modeling harvest-now-decrypt-later exposure, pricing the risk in your own currency, and turning it all into a phased, quantum-resistant migration roadmap. It runs on-premise and air-gapped: its only vendor-chosen outbound call is an optional, admin-triggered exchange-rate refresh you can replace with manual rates, and every other connection goes only to hosts you configure — the map of your cryptographic weaknesses never leaves your network.

What you get

The outcomes that matter

See every algorithm you run

Network, code, configuration, certificate and encrypted-file discovery — recorded as a machine-readable CBOM, so nothing in the estate stays a cryptographic blind spot.

A clock you can plan against

Every algorithm scored against the quantum threat, with harvest-now-decrypt-later exposure modeled against your data’s shelf life — so what must migrate first is precise, not guessed.

Board-ready, in money terms

Exposure quantified financially as well as technically, with one-click executive and board reports — risk conversations in the language the board understands.

Inside PQCA

Every module, end to end

PQCA runs the full quantum-readiness lifecycle in one sovereign platform → discover, inventory, assess, plan and prove. Each module below is part of one integrated platform.

Discover

Deep Cryptographic Discovery
114 probes per host on every default scan — 101 TCP ports plus 13 UDP probes (QUIC, IKEv2, WireGuard, ONVIF, DTLS and OpenVPN) — across TLS/HTTPS, STARTTLS, SSH, IKE/IPsec; database engines; operational-technology and ICS protocols; and IoT and IP-camera protocols (RTSP, ONVIF). Beyond the catalogue, a full TCP 1–65535 sweep and a bounded UDP sweep are available per host, and admins can add custom ports to the standing catalogue.
PQC Readiness Probe
Sends a TLS 1.3 ClientHello advertising the IANA hybrid and pure ML-KEM groups and records what the server actually picks — hybrid, pure ML-KEM, or classical. That answer, not the current cipher, is what sequences a migration and puts pressure on a vendor.
Endpoint Traffic Sensor
A lightweight collector for Windows and Linux that finds the cryptography no network scan reaches: outbound connections from behind NAT, short-lived sessions, and hosts your scanner has no route to.
Source Code & Configuration Scanning
Fingerprints the cryptography in your code and configuration — the algorithms a network scan alone can’t see. Hardcoded-secret detection flags cloud keys, private-key material and credentials — values always masked in evidence. Parameter-aware analysis ties key sizes to the algorithms they configure across Java, C#, Python and JavaScript — initialize(1024) weakens the RSA it initialises, with the evidence citing both lines.
Certificate & Encrypted-File Discovery
Finds the certificates and encrypted files across the estate and folds them into the same inventory.

Inventory

Cryptographic Bill of Materials (CBOM)
An exportable inventory of the algorithms, keys and certificates discovered across the estate, in CycloneDX 1.7 format, 1.6 selectable.
SBOM / CBOM Import
Import third-party SBOMs and CBOMs to fold your supply chain into the same picture. HSM/KMS key lists are analysed as exports and graded — there is no live connector holding credentials into your Luna, CloudHSM or Key Vault, and nothing from the list is persisted.
Snapshots & Drift Diff
A CBOM is a photograph; a regulator wants a film. PQCA takes point-in-time CBOM snapshots and diffs any two of them, so you can show what changed, what appeared, and which hosts dropped a vulnerable algorithm while others still run it. That diff is what evidences that a migration is actually happening.
Per-Record Change History
“Who marked this system high-impact, and when?” is a question auditors ask about the data driving the risk model, not just about the findings. PQCA answers it per asset, application and certificate, and distinguishes a scan-driven change from a human one.
Tags
One label across assets, applications and certificates — applied once and inherited, so a business service can be filtered, scored and reported as a unit.

Assess

Quantum Risk Scoring
Every algorithm scored against classical attacks and against Shor’s and Grover’s algorithms.
HNDL Exposure Modeling
Harvest-now-decrypt-later exposure modeled against your data’s shelf life and a configurable quantum horizon — Mosca’s inequality made concrete.
Financial Risk Quantification
Exposure expressed not just in ratings but in monetary terms.
Crypto-Policy Engine
Flags every algorithm that breaches your organization’s cryptographic rules, continuously.
Policy Rules View
Read the cryptographic policy rule by rule — the structured policy-as-code shown as the individual rules it enforces, not just as a document.

Plan & migrate

QRC Migration Roadmap
A phased, quantum-resistant-cryptography roadmap generated automatically from the discovered inventory — tasks, owners, budget, a Gantt view.
Remediation Playbooks
Per-finding playbooks that turn each weak algorithm into a concrete migration step.
Standards Conformance & Deadline Tracking
Continuous conformance scoring against FIPS 203/204/205 and CNSA 2.0, with a live regulatory-deadline countdown.

Prove & operate

Executive & Board Reporting
One-click executive and board PDFs, plus CSV/PDF exports carrying your organization branding.
Arabic Reporting
Board reports in Arabic, correctly typeset — contextual letter shaping, the lam-alef ligature and right-to-left reordering, with the font bundled so it renders identically on an air-gapped server.
Continuous Monitoring
Scheduled re-scans and drift detection catch new or weakened cryptography as the estate changes. Event-driven alert digests — expiring certificates, new critical findings, licence expiry and inventory-sync failures — arrive over email or your ITSM connector, and risk rolls up by department and business unit.
Report Builder & Scheduled Delivery
Your quarterly risk committee, your internal audit team and your regulator all want different documents from the same estate. PQCA composes them from 21 report sections and 41 filters, with presets to start from, and delivers them on a schedule by email — timestamped in the recipient’s own timezone, with no one logging in.
Audit Log & Live SIEM Forwarding
Complete audit trail — every mutation and sensitive download recorded, automation attributed by name — written to a log the application only ever appends to, with the acting user, the timestamp and the before-and-after state. It is not hash-chained, and a full platform restore replaces it. Events forward continuously to Splunk, QRadar or any syslog collector over UDP, TCP or TLS as CEF, with resumable cursors so a collector outage does not lose events — the place to hold tamper-evidence outside the platform.

How it works

From cryptographic blind spot to migration plan

  1. 01

    Discover

    Fingerprint the cryptography each service actually uses — network, code, configurations, certificates and encrypted files. Network and certificate discovery are recorded as a machine-readable CBOM (CycloneDX 1.7), folding in supply-chain SBOMs; code and file analysis catch what never crosses the wire.
  2. 02

    Assess

    Score every algorithm against classical and quantum attack and model HNDL exposure over your data’s shelf life.
  3. 03

    QRC-Budget

    Quantify the risk per asset and org-wide in your own currency — technical severity becomes a budget line.
  4. 04

    Comply

    Score your reported progress against 21 frameworks and 78 controls with per-control Met / Partial / Gap evidence and policy-as-code.
  5. 05

    Plan the migration

    Drive the phased, owner-assigned, budget-tracked roadmap and report conformance to auditors and the board — on a complete audit trail: every mutation and sensitive download recorded, automation attributed by name, exportable as CEF for your SIEM.

Coverage

Built around the frameworks that govern the transition

NIST FIPS 203 (ML-KEM)NIST FIPS 204 (ML-DSA)NIST FIPS 205 (SLH-DSA)NSA CNSA 2.0CycloneDX 1.7 / 1.6 (CBOM)NIST IR 8547ISO/IEC 18033-2 Amd 2 · IETF TLS hybrid draftsPCI DSS 4.0EU DORA · CRACCCS ITSM.40.001 (Canada)UAE National Encryption PolicySaudi NCASAMA (Saudi Central Bank)CBJ roadmapFIPS 140-3 / CMVP module transition (tracking)

Harvest-now-decrypt-later risk is modeled on Mosca’s inequality against a quantum horizon you configure — so the migration deadline is your data’s, not a vendor’s.

21 regulatory frameworks · 78 individually scored controls · 41 dated milestones on the live clock. ISO/IEC and IETF coverage is ISO/IEC 18033-2 Amendment 2 (FrodoKEM, Classic McEliece, ML-KEM) and the IETF TLS hybrid key-exchange drafts, including the X25519MLKEM768 codepoint PQCA probes for on the wire. For FIPS 140-3 specifically, PQCA tracks your plan to move onto CMVP-certified modules. It does not validate modules, and it is not a substitute for CMVP.

Integrations & automation

Plugged into the estate you already run

Inventory flows in from the systems that already know your assets; findings flow out to the queues your teams already work; and the same scanner gates code before it ships. No new silo, no swivel-chair.

Inventory

Enterprise inventory sync — CMDB

PQCA stays in step with your asset inventory. Pull connectors for ServiceNow CMDB, NetBox/Nautobot, Qualys, Nessus and Active Directory; a watched-folder CSV channel for air-gapped estates — your CMDB exports, PQCA imports and archives; and scoped API keys for push automation, where the importer role can call exactly one endpoint and nothing else. Existing asset records are never overwritten unless you opt in.

Ticketing

Two-way ITSM ticketing

Findings become ServiceNow or Jira tickets carrying full remediation playbooks. Ticket status syncs back onto the finding every 15 minutes, and — opt-in — a genuinely resolved ticket closes its finding. Dismissed tickets (Won’t Do, Cancelled) never count as remediation, and a person’s closure is never overwritten. Status sync-back is ServiceNow and Jira only — Slack and generic webhooks are push-only notifications.

Shift left

Developer CLI

The same scanner, in your pipeline: a zero-dependency pip package, a single-file pqca.pyz for locked-down endpoints, or a standalone executable. SARIF output annotates pull requests; a --fail-on gate blocks quantum-broken cryptography at build time. Fully offline — no server, no network.

Group reporting · multi-entity

One group, every entity

Banking groups and regional holdings answer for several licensed entities at once. A Master PQCA links each subsidiary, reads its posture on a schedule and reports the group side by side — while every subsidiary’s data stays in its own install. This is federation — many separate installs reporting upward to a parent — not multi-tenant isolation inside one install.

Master PQCA

Link every subsidiary

A Master PQCA links each subsidiary and reads its posture on a schedule, so the group view is current without a quarterly collection exercise.

Group view

The group, side by side

Group exposure, mean readiness, the weakest entity and the soonest mandate — every entity reported side by side, so the board sees where the group stands and which subsidiary sets the pace.

Two ways in

Live, or from a CBOM

A subsidiary is read live from its own PQCA, or from a CBOM it uploads — either way it takes its place in the same group view.

Sovereignty

Data stays in its own install

Every subsidiary’s data stays in its own install, sovereign to its jurisdiction and data-residency rules — the Master reads posture and reports the group.

Licensed per number of linked subsidiaries.

Maker-checker governance

Four eyes on everything that matters

PQCA is a system of record, so the changes that move a risk position do not take effect because one person clicked save. On eight governed surfaces a Maker proposes and a Checker decides, and the proposal, the decision, the decider and the before-and-after state are all recorded.

The eight governed surfaces

Propose, decide, record

Risk acceptances · the QRC migration roadmap · the quantum horizon · the financial risk-exposure model · applied frameworks and jurisdictions · cryptographic policy · algorithm risk overrides · platform restore. Segregation of duties over cryptographic policy and risk acceptance is what an internal audit function tests for, and what turns a scanner into evidence.

Risk-acceptance records

The exception file an examiner asks for

Every bank carries findings it cannot remediate this year. What supervision tests is whether the exception was authorised, by whom, with what compensating control, and when it expires. PQCA records that as a first-class object with attachments and an expiry date — proposed by a Maker, approved by a Checker, and surfaced again when it lapses.

Endpoint traffic sensor · Windows + Linux

The crypto your scanner cannot reach

A network scan sees what it can route to. It misses outbound connections from behind NAT, sessions too short to catch, and every host on a segment it has no path into. PQCA ships a lightweight endpoint sensor for Windows and Linux that closes that gap — and it is built to pass a change advisory board, not to fight one.

How it observes

No packet capture. No driver. No kernel module.

It samples the operating system’s own connection table on an interval, attributes each flow to the owning process, and posts flow metadata to the platform. Nothing else — no payload data ever leaves the endpoint.

Install

A Scheduled Task, or a systemd service

On Windows it installs as a Scheduled Task from a single .exe (or PowerShell); on Linux as a systemd service from one shell command. Estates enforcing application control (WDAC, Smart App Control) allow-list the unsigned executable or sign it with their own certificate — see Deployment below.

Least privilege

A key that can only submit

It authenticates with a scoped service key that can call exactly one endpoint and nothing else — so a compromised sensor cannot read your inventory.

Retention

Capped at 60 days

Traffic records are capped at 60 days and purged automatically — a rolling window of what talks to what, not a permanent flow archive.

Added value

The value it creates

Discovery and a CBOM are the mechanism. This is what proving control of your cryptography is worth to the business.

Quantum readiness

Provable crypto-agility

Turn “we think we’re fine” into a signed Cryptographic Bill of Materials and a readiness score you can put in front of a regulator or board.

Prioritized spend

Fix what matters first

HNDL and financial-exposure scoring rank every weak algorithm by real business risk, so migration budget lands on the data that will actually be harvested.

Audit evidence

Answer the mandate on demand

Export CBOM, quantum-risk findings and a phased roadmap as board-ready evidence — not a slide deck assembled the week before the audit.

Sovereignty

Air-gapped, owned by you

Runs fully on-premise and offline, so the most sensitive map of your estate — where its cryptography is weak — never leaves your control.

Regulatory fit

Where PQCA fits your obligations

21 regulatory frameworks · 78 individually scored controls · 41 dated milestones on the live clock. The standards driving the post-quantum transition — and exactly how PQCA tracks and evidences your progress against each.

NIST FIPS 203 / 204 / 205International

Benchmarks every discovered algorithm against the finalised ML-KEM, ML-DSA and SLH-DSA standards and flags what must be replaced.

NSA CNSA 2.0USA · National security

Tracks progress toward the 2035 post-quantum mandate for national-security systems, algorithm by algorithm.

EO 14412 · OMB M-26-15USA · Federal civilian

Federal civilian agencies move sooner than NSS: key establishment quantum-safe by end-2030 and digital signatures by end-2031, with agency migration plans due to OMB in October 2026. M-26-15 expressly excludes national-security systems.

NIST IR 8547International

Applies the deprecation timeline — RSA and ECC deprecated after 2030, disallowed after 2035 — so legacy crypto is retired on schedule.

EU DORA · CRAEurope

Cryptographic-resilience evidence for financial entities under DORA, and product obligations under the Cyber Resilience Act.

ISO/IEC 18033-2 · IETF TLSInternational standards

ISO/IEC 18033-2 Amendment 2 (FrodoKEM, Classic McEliece, ML-KEM) and the IETF TLS hybrid key-exchange drafts, including the X25519MLKEM768 codepoint PQCA probes for on the wire. PQCA produces cryptographic-inventory evidence that supports an ISO 27001 control set; it does not assess or certify an ISMS.

SAMA · Saudi NCA · UAE · CBJ · CBKMENA

SAMA’s binding milestones — cryptographic inventory and classification complete by 31 Dec 2026, institution-level quantum risk assessment by 31 Mar 2027 — alongside the UAE National Encryption Policy, Saudi NCA, Kuwait’s CBK resilience framework and the Central Bank of Jordan roadmap to 2035, scored natively with local-currency reporting. Saudi NCA is scored as general cryptographic-hygiene controls — NCA has published no post-quantum mandate; the Kingdom’s dated PQC milestones are SAMA’s.

UK NCSC · BSI · ANSSINational guidance

National transition guidance mapped as first-class frameworks — UK NCSC, Germany’s BSI TR-02102-1, France’s ANSSI, Canada’s CCCS ITSM.40.001, the mandatory Treasury Board SPIN, OSFI’s quantum-readiness expectations for financial institutions, and Australia’s ASD ISM.

PCI-DSS v4.0International

Documents cryptographic protection of cardholder data and surfaces weak cipher suites (Requirement 4).

PCI PTS HSMGlobal · Payments

HSM approvals tracked against the PTS timeline — v4 new-device approvals end mid-2027, and v5 is the first PTS revision to carry post-quantum requirements.

Measured vs tracked

We tell you which numbers we measured

Most of PQCA’s compliance scoring tracks the progress you report against your own migration roadmap. Two things are different: they are computed from what your services actually negotiated on the wire, not from anything anyone attested. CNSA 2.0 suite conformance is measured estate-wide from real findings. Hybrid-versus-pure key-exchange verdicts are measured per endpoint and judged against the jurisdiction you selected — because ANSSI, BSI, ASD and CNSA 2.0 genuinely disagree about whether a hybrid construction is acceptable, and a single global verdict would be wrong for someone. Everything else on the compliance screen is a tracking view of self-attested roadmap progress, and the platform says so on the screen itself.

Evidence discipline

“We could not look” is never scored as “it was fixed”

A scanner that quietly retires a service it failed to reach manufactures compliance progress. PQCA distinguishes not vulnerable from not observed, and an unreachable target is recorded as unreachable — never as resolved. In a regulated institution the difference is a reportable control failure.

Risk mitigation

The risk it takes off the table

“Harvest now, decrypt later” is happening today. Here is what the quantum threat looks like without PQCA — and with it.

Without PQCAWith PQCA

No inventory of where cryptography actually runs — TLS, SSH, certificates, code and files are a blind spot.

A complete, deduplicated Cryptographic Bill of Materials across the estate, refreshed on every scan.

Long-life secrets are being captured now for decryption once a quantum computer exists.

HNDL exposure modelled per dataset, so the data with the longest shelf life is re-encrypted first.

Migration is an open-ended, unbudgeted scramble as deadlines approach.

A phased, budgeted roadmap prioritized by quantum risk and financial impact.

Regulators ask for crypto-agility evidence you cannot produce.

Signed CBOM, risk scores and roadmap exportable on demand.

The estate drifts — new weak algorithms creep back in unnoticed.

Snapshots and drift-diff flag every regression against the approved baseline.

Deployment & security

Yours to run, built to defend

Every Terashield platform deploys inside your environment and stays under your control → hardened, directory-integrated, and audit-ready from day one.

On-premise & air-gapped

Runs entirely inside your network with no internet dependency — your cryptographic inventory never leaves your control.

Sovereign by design

Customer-owned, sovereign data — deployed inside your environment and owned by you.

Hardened by default

Directory-integrated sign-on, CA-signed TLS, strict security headers, and role-based access throughout — four user roles (Administrator, Checker, Maker, Read Only) plus least-privilege service keys for importer, sensor and federation.

Evidenced & exportable

A complete audit log exported for SIEM ingestion — CEF, CSV, STIX 2.1, SARIF 2.1.0 — plus board-ready PDF evidence carrying your branding.
Availability

Single process, single scheduler

PQCA runs as one process with one scheduler. There is no clustering, high availability or failover; recovery is a restore from your last backup, so set RTO and RPO expectations around your backup cadence. A bank asks this early — a straight answer builds more trust than a gap.

Backup & restore

From the admin console, not a database shell

Backup and restore run from the admin console — which matters in air-gapped sites where the application team is not granted a database shell. A restore is itself a governed, four-eyes change.

Licensing

Offline and signed

No activation server, no phone-home, no evaluation timer. A licence is an Ed25519-signed file bound to the machine and renewed by email attachment.

Audit trail

Complete, application-level, not hash-chained

Every scan, score, export and decision is written to an audit trail the application only ever appends to, with the acting user, the timestamp and the before-and-after state. It is not hash-chained, and a full platform restore replaces it along with the rest of the data — so treat it as a complete application-level record, and forward it to your SIEM if you need tamper-evidence held outside the platform.

Endpoint sensors: the Windows sensor .exe ships unsigned. An endpoint estate enforcing application control — WDAC or Smart App Control — must allow-list it, or sign it with the customer’s own code-signing certificate before rollout. Plan for this before a pilot, not during one.

See PQCA in your environment

Start with evidence. Migrate on your terms. See your entire cryptographic estate, its quantum risk, and your migration path → in a platform that never leaves your network.

See PQCA in your environment.

Request a private briefing — bring a subnet or a packet capture and see real findings, real risk and a roadmap draft in 30 minutes. Nothing leaves your network.