PQCA

Post-Quantum Cryptography Analyzer

Flagship platform

Post-Quantum Cryptography Analyzer

Prove control of your cryptography before quantum breaks it.
PQCA discovers, inventories and quantum-risk-assesses the cryptography running across your entire estate — producing an evidence-based Cryptographic Bill of Materials, modeling harvest-now-decrypt-later exposure, pricing the risk in your own currency, and turning it all into a phased, quantum-resistant migration roadmap. It runs 100% on-premise and air-gapped, with zero outbound calls — the map of your cryptographic weaknesses never leaves your network.

What you get

The outcomes that matter

See every algorithm you run

Network, code, configuration, certificate and encrypted-file discovery — recorded as a machine-readable CBOM, so nothing in the estate stays a cryptographic blind spot.

A clock you can plan against

Every algorithm scored against the quantum threat, with harvest-now-decrypt-later exposure modeled against your data’s shelf life — so what must migrate first is precise, not guessed.

Board-ready, in money terms

Exposure quantified financially as well as technically, with one-click executive and board reports — risk conversations in the language the board understands.

Inside PQCA

Every module, end to end

PQCA runs the full quantum-readiness lifecycle in one sovereign platform → discover, inventory, assess, plan and prove. Each module below is part of one integrated platform.

Discover

Deep Cryptographic Discovery
Network scanning across TLS/HTTPS, STARTTLS, SSH, QUIC, IKE/IPsec and WireGuard; database engines; operational-technology and ICS protocols; and IoT and IP-camera protocols (RTSP, ONVIF).
Source Code & Configuration Scanning
Fingerprints the cryptography in your code and configuration — the algorithms a network scan alone can’t see.
Certificate & Encrypted-File Discovery
Finds the certificates and encrypted files across the estate and folds them into the same inventory.

Inventory

Cryptographic Bill of Materials (CBOM)
A complete, exportable inventory of every algorithm, key and certificate in CycloneDX 1.7 format (ECMA-424 2nd ed.; 1.6 selectable).
SBOM / CBOM Import
Import third-party SBOMs and CBOMs to fold your supply chain into the same picture.
Snapshots & Drift Diff
Snapshot the CBOM over time and diff snapshots to see exactly what changed as the estate evolves.

Assess

Quantum Risk Scoring
Every algorithm scored against classical attacks and against Shor’s and Grover’s algorithms.
HNDL Exposure Modeling
Harvest-now-decrypt-later exposure modeled against your data’s shelf life and a configurable quantum horizon — Mosca’s inequality made concrete.
Financial Risk Quantification
Exposure expressed not just in ratings but in monetary terms.
Crypto-Policy Engine
Flags every algorithm that breaches your organization’s cryptographic rules, continuously.

Plan & migrate

QRC Migration Roadmap
A phased, quantum-resistant-cryptography roadmap generated automatically from the discovered inventory — tasks, owners, budget, a Gantt view.
Remediation Playbooks
Per-finding playbooks that turn each weak algorithm into a concrete migration step.
Standards Conformance & Deadline Tracking
Continuous conformance scoring against FIPS 203/204/205 and CNSA 2.0, with a live regulatory-deadline countdown.

Prove & operate

Executive & Board Reporting
One-click executive and board PDFs, plus CSV/PDF exports carrying your organization branding.
Continuous Monitoring
Scheduled re-scans and drift detection catch new or weakened cryptography as the estate changes.
Offline AI Assistant
An air-gapped assistant running entirely inside your network — answers questions about post-quantum cryptography and your live platform data, and can act on your behalf.
Audit Log & SIEM Streaming
A tamper-evident audit log with CEF streaming into your SIEM.

How it works

From cryptographic blind spot to migration plan

  1. 01

    Discover

    Fingerprint the cryptography each service actually uses — network, code, configurations, certificates and encrypted files — and record it as a machine-readable CBOM (CycloneDX 1.7), folding in supply-chain SBOMs.
  2. 02

    Assess

    Score every algorithm against classical and quantum attack and model HNDL exposure over your data’s shelf life.
  3. 03

    QRC-Budget

    Quantify the risk per asset and org-wide in your own currency — technical severity becomes a budget line.
  4. 04

    Comply

    Score readiness against 15+ frameworks with per-control Met / Partial / Gap evidence and policy-as-code.
  5. 05

    Migrate

    Drive the phased, owner-assigned, budget-tracked roadmap and report conformance to auditors and the board — all on a tamper-evident log.

Coverage

Built around the frameworks that govern the transition

NIST FIPS 203 (ML-KEM)NIST FIPS 204 (ML-DSA)NIST FIPS 205 (SLH-DSA)NSA CNSA 2.0CycloneDX 1.7 (CBOM · ECMA-424)NIST IR 8547ISO/IEC 27001PCI DSS 4.0EU DORA · CRAUAE · Saudi NCACBJ roadmap

Harvest-now-decrypt-later risk is modeled on Mosca’s inequality against a quantum horizon you configure — so the migration deadline is your data’s, not a vendor’s.

Added value

The value it creates

Discovery and a CBOM are the mechanism. This is what proving control of your cryptography is worth to the business.

Quantum readiness

Provable crypto-agility

Turn “we think we’re fine” into a signed Cryptographic Bill of Materials and a readiness score you can put in front of a regulator or board.

Prioritised spend

Fix what matters first

HNDL and financial-exposure scoring rank every weak algorithm by real business risk, so migration budget lands on the data that will actually be harvested.

Audit evidence

Answer the mandate on demand

Export CBOM, quantum-risk findings and a phased roadmap as board-ready evidence — not a slide deck assembled the week before the audit.

Sovereignty

Air-gapped, owned by you

Runs fully on-premise and offline, so the most sensitive map of your estate — where its cryptography is weak — never leaves your control.

Regulatory fit

Where PQCA fits your obligations

The standards driving the post-quantum transition — and exactly how PQCA helps you satisfy each.

NIST FIPS 203 / 204 / 205International

Benchmarks every discovered algorithm against the finalised ML-KEM, ML-DSA and SLH-DSA standards and flags what must be replaced.

NSA CNSA 2.0USA · National security

Tracks progress toward the 2035 post-quantum mandate for national-security systems, algorithm by algorithm.

NIST IR 8547International

Applies the deprecation timeline — RSA and ECC deprecated after 2030, disallowed after 2035 — so legacy crypto is retired on schedule.

EU DORA · CRAEurope

Cryptographic-resilience evidence for financial entities under DORA, and product obligations under the Cyber Resilience Act.

ISO/IEC 27001:2022International

Feeds Annex A 8.24 (use of cryptography) with a live, evidenced view of control state across the estate.

UAE · Saudi NCA · CBJMENA

The UAE National Encryption Policy, Saudi NCA and the Central Bank of Jordan roadmap scored natively — with local-currency reporting.

UK NCSC · BSI · ANSSINational guidance

National transition guidance mapped as first-class frameworks — UK NCSC, Germany’s BSI TR-02102-1, France’s ANSSI, Canada’s CCCS ITSM.40.001 and Australia’s ASD ISM.

PCI-DSS v4.0International

Documents cryptographic protection of cardholder data and surfaces weak cipher suites (Requirement 4).

Risk mitigation

The risk it takes off the table

“Harvest now, decrypt later” is happening today. Here is what the quantum threat looks like without PQCA — and with it.

Without PQCAWith PQCA

No inventory of where cryptography actually runs — TLS, SSH, certificates, code and files are a blind spot.

A complete, deduplicated Cryptographic Bill of Materials across the estate, refreshed on every scan.

Long-life secrets are being captured now for decryption once a quantum computer exists.

HNDL exposure modelled per dataset, so the data with the longest shelf life is re-encrypted first.

Migration is an open-ended, unbudgeted scramble as deadlines approach.

A phased, costed roadmap prioritised by quantum risk and financial impact.

Regulators ask for crypto-agility evidence you cannot produce.

Signed CBOM, risk scores and roadmap exportable on demand.

The estate drifts — new weak algorithms creep back in unnoticed.

Snapshots and drift-diff flag every regression against the approved baseline.

Deployment & security

Yours to run, built to defend

Every Televestigo platform deploys inside your environment and stays under your control → hardened, directory-integrated, and audit-ready from day one.

On-premise & air-gapped

Runs entirely inside your network with no internet dependency — your cryptographic inventory never leaves your control.

Sovereign by design

Customer-owned, sovereign data — deployed inside your environment and owned by you.

Hardened by default

Directory-integrated sign-on, CA-signed TLS, strict security headers, and role-based access throughout.

Evidenced & exportable

A tamper-evident audit log with CEF streaming to your SIEM, and board-ready PDF / CSV evidence carrying your branding.

See PQCA in your environment

Start with evidence. Migrate on your terms. See your entire cryptographic estate, its quantum risk, and your migration path → in a platform that never leaves your network.

See PQCA in your environment.

Request a private briefing — bring a subnet or a packet capture and see real findings, real risk and a roadmap draft in 30 minutes. Nothing leaves your network.