Know your quantum exposure before 2028 arrives
Most organisations still don't know which certificates, VPNs and signing keys break when quantum computing lands. Find them, score them, plan the switch to post-quantum cryptography, and prove it to your board and your regulator. Free.
AIML Labs Limited · Applied research for a quantum safe future
Public TLS still negotiates RSA-2048 key exchange on two endpoints.
- RSA-2048 key exchangeedge TLS · severity High
- ECDSA P-256 signaturecert chain · severity Medium
Illustrative preview
- Scan your public cryptography for quantum exposure
- Score readiness against NIST and NCSC guidance
- Build a classified inventory with per-asset risk
- Plan migrations against 2028, 2031 and 2035
- Sign off every change and export the evidence
The deadlines are fixed, and nobody has the full list of what breaks
- No one can name every certificate, VPN tunnel or signing key still using RSA or ECC
- Data stolen today can be decrypted later, and the clock already started
- NCSC expects discovery and planning done by 2028, priority migrations by 2031
- Board and regulator questions arrive faster than spreadsheets can be updated
From first scan to signed-off migration evidence
Scan a domain's public cryptography
Give it a domain and get a plain-language exposure summary: headline risk level, the algorithms still in use, and where they sit.
Score your readiness in minutes
Answer a short self-assessment and get a Quantum Readiness Score with sub-scores and the five actions worth doing first.
Build a cryptographic inventory
Upload certificate exports, PKI detail, configs or scan output and get every asset classified with its own quantum risk score.
Plan against NCSC milestones
Turn the inventory into a prioritised transition roadmap with actions mapped to 2028, 2031 and 2035.
Execute changes with sign-off
Each migration is proposed, approved by a named person, applied, verified and recorded with a before-and-after.
Produce board-ready reports
Generate a downloadable compliance report showing position against NIST FIPS 203/204/205 and UK NCSC obligations.
Track milestone progress
See inventory coverage, migrations completed and percent-complete against each milestone year in one view.
See harvest-now-decrypt-later risk
Understand which long-lived data is exposed to capture today and decryption tomorrow, and which assets to move first.
Keep an auditable trail
Every request, every step taken and every approval decision is recorded and reviewable after the fact.
Four steps to a defensible plan
- 1
Name your domain
Type a domain and watch the exposure summary come back with a headline risk level and the cryptography behind it.
- 2
Add what you know
Upload certificate exports, PKI notes, configs or scan output, or just describe your systems in plain words.
- 3
Get your inventory and roadmap
Assets are classified and risk-scored, then prioritised into migration actions against the 2028, 2031 and 2035 dates.
- 4
Approve, migrate, report
Approve each change by name, apply and verify it, then export the report your board or regulator asks for.
Who uses this every week
CISOs and Heads of Security
Get a single defensible position on quantum exposure, with the evidence to take into a board meeting.
Cryptography and PKI engineers
Turn certificate exports and config sprawl into a classified inventory with per-asset risk and named NIST targets.
Compliance and risk officers
Measure the organisation against NIST FIPS 203/204/205 and UK NCSC obligations and export the gaps in writing.
Change and platform approvers
Review each proposed cryptographic change, sign it off by name, and see the before-and-after that was recorded.
Standards-aligned, auditable, and yours to export
- Aligned to NIST FIPS 203 / 204 / 205
- Mapped to UK NCSC 2028 / 2031 / 2035 milestones
- Named human sign-off on every migration change
- Full audit trail of requests, steps and decisions
- Encrypted at rest and in transit
- SSO via Okta or Microsoft Entra ID
- Reports exportable as documents you keep
Start your quantum-safe transition today
Type one domain and you'll have an exposure summary before your coffee cools.
Questions people ask first
A domain name is enough for a first exposure summary. For a full inventory, upload certificate exports, PKI detail, configuration files or existing scan output, or simply describe your systems.
Your inventory, roadmap and approvals live in your workspace
Exposure summaries, cryptographic inventory, transition roadmaps, migration changes, readiness scores and compliance reports, all in one place.