Post-Quantum Migration · Early Access

Don't just find quantum-vulnerable cryptography. Migrate it.

CryptiQ inventories every cryptographic asset across your code, cloud, and vendors — then opens pull requests that move the safe-to-migrate parts to post-quantum algorithms. You review. You merge. Your next security review goes exactly as planned.

pull request · opened by CryptiQ green tier
Migrate ALB listener to hybrid post-quantum TLS
resource "aws_lb_listener" "https" {
port = 443
- ssl_policy = "ELBSecurityPolicy-TLS13-1-2-2021-06"
+ ssl_policy = "ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09"
}
terraform plan · no resources destroyed
handshake verified · X25519MLKEM768
rollback diff generated
awaiting your review CryptiQ never merges
First scan
In one afternoon
Migration
Arrives as a PR
Deployment
OAuth · No agents
Standards
FIPS 203 · 204 · 205
The Calendar

The deadlines are not theoretical.

Every quarter from here forward closes another door on RSA and elliptic-curve cryptography. Federal procurement, EU regulation, and customer security reviews are converging on the same expectation: a credible post-quantum migration plan, documented and current.

CryptiQ is built around this calendar.

September 21, 2026
FIPS 140-2 certificates move to Historical
Federal procurement requires FIPS 140-3 validated modules. Cascades down through every federal-adjacent buyer.
January 2027
CNSA 2.0 takes effect
NSA requires quantum-safe algorithms for new National Security System acquisitions. Defense Industrial Base contractors face cascading procurement pressure across their SaaS stack.
End of 2026
EU member states publish PQC strategies
Under the coordinated EU roadmap, national cryptographic inventories and pilot migrations begin. CRA brings cryptographic transparency into product compliance.
2030
RSA-2048 disallowed for federal systems
NIST sunsets 112-bit-equivalent algorithms. EU critical infrastructure targets full PQC by 2030.
2033 – 2035
Full migration deadlines arrive
NSS, operating systems, custom applications, and cloud infrastructure expected to be fully migrated. "Harvest now, decrypt later" timelines collapse.
What CryptiQ Delivers

Find it. Prove it. Track it. Migrate it.

Connect your code hosts, cloud accounts, certificate authority, and vendor list. Within a day you have a full inventory and a customer-ready report — and when an asset becomes safe to migrate, the change arrives as a pull request you review and merge.

i.

A Cryptography Bill of Materials, generated automatically

A complete inventory of every cryptographic primitive, key, certificate, and protocol across your code, your cloud, and your dependencies — in a standard, portable format your GRC platform can ingest.

cbom · main inventory
RSA-2048 · sha256WithRSA At risk
ECDH P-256 · TLS handshake At risk
AES-256-GCM · data-at-rest PQ-safe
ML-KEM-768 · key exchange PQ-safe
ECDSA P-384 · signing At risk
SHA-384 · MAC PQ-safe
DSA-1024 · legacy certificate At risk
ii.

A readiness report your customers can actually read

A branded, shareable artifact — the one you send when a prospect's security team asks "what's your post-quantum plan?" Generated as a PDF or an embeddable trust-page summary, aligned to recognized post-quantum maturity standards, and written in language a procurement team understands.

readiness · v2.4 · for share
PQCMM 3
Defined · Migrating
Critical assets
94% mapped
Vendor coverage
211 of 234
First migration
Q1 · 2027
Hybrid in prod
3 services
iii.

Continuous visibility into every vendor in your stack

Most of your migration won't be your own code — it'll be waiting on the vendors that quietly run your product. CryptiQ tracks each one continuously, with evidence, so you know exactly what's blocking your readiness and what's already done.

vendor matrix · top dependencies
Aaws.amazon.com
Ready · KMS
Ccloudflare.com
Ready · TLS
Gcloud.google.com
Ready · KMS
Sstripe.com
Roadmap · 2027
Ookta.com
Roadmap · 2026
Mmongodb.com
No plan filed
Ttwilio.com
No plan filed
iv.

The migration itself — delivered as a pull request

This is the part no one else does. When an asset becomes safe to migrate, CryptiQ opens a pull request in your repository with the exact change, the passing tests, and a generated rollback. Migration stops being a project and becomes something that simply arrives, the moment it's ready — and your team always holds the merge button.

migration engine · ambient
01
aws · us-east-1 ships hybrid TLS policy
Detected via the vendor readiness database
02
engine computes the Terraform diff
aws_lb_listener.ssl_policy → PQ-2025-09
03
PR opened · CI green · rollback ready
X25519MLKEM768 handshake verified in plan
04
your engineer reviews and merges
No CryptiQ hand on the merge button, ever
migrated — total human effort: one code review
How It Works

No agents. No professional services. No sprawl.

The fastest path from "we should look at PQC" to "the migration just merged."

01 · Connect

Authorize, don't install

OAuth into GitHub, AWS, GCP, Azure, your certificate authority, and your existing GRC platform. Read-only to start. No agents, no kernel modules, no production access.

02 · Scan

First CBOM in hours

Static analysis runs across your code. Cloud crypto surface is enumerated. Certificate Transparency logs are crawled. Your initial CycloneDX 1.6 CBOM is ready before the end of the day.

03 · Prove

Share the readiness report

Generate your branded readiness report as PDF, web link, or embedded into your SafeBase or Whistic trust page. When the security review email comes in, you reply with a URL.

04 · Migrate

Merge the pull request

Grant a narrowly-scoped write role, and migrations arrive as PRs — the exact change, your CI green, a rollback attached. You review it like any other pull request and merge.

The Automation Boundary

We automate only what's safe to automate — and we're honest about the rest.

Some cryptographic changes are routine and well-suited to automation. Others demand human judgment, and a tool that pretends otherwise is dangerous. CryptiQ proposes the safe-to-migrate work as reviewable pull requests, flags what needs a careful human eye, and tells you plainly where automation has no business going. That discipline is exactly why security teams trust the parts we do automate.

Built for the segment the giants skip

SandboxAQ and IBM report on your crypto. We migrate it.

Migration, not just inventory

Every other tool in this space stops at a report your engineers still have to act on. CryptiQ closes the loop: the safe-to-migrate work arrives as a pull request, already tested, already reversible.

Self-serve by design

Enterprise PQC platforms ship with six-week professional services engagements. CryptiQ is OAuth in, CBOM out, PR merged — built for a security team of two who do not have time for a kickoff call.

Honest about the boundary

We automate the 60–70% that's genuinely safe to automate and refuse to touch the rest. A tool that occasionally breaks production is worse than one that proposes and waits — so ours waits.

Vendor data, compounding

Our vendor readiness database gets richer with every customer — and it's what tells the migration engine the moment an asset is ready to move. Within a year, no enterprise-focused incumbent will have a database this current for the SaaS stack you actually run.

"Don't just find quantum-vulnerable cryptography. Migrate it — one code review at a time."
Built on the standards your auditors recognize
NIST FIPS 203 · ML-KEM NIST FIPS 204 · ML-DSA NIST FIPS 205 · SLH-DSA CycloneDX 1.6 CBOM NIST IR 8547 NSA CNSA 2.0 PKI Consortium PQCMM IETF Hybrid TLS
Get In Touch

We're taking on a few design partners.

We're early, and working closely with a small number of mid-market SaaS teams who feel the post-quantum deadline coming. If that's you — or you're an investor or engineer who wants to talk — we'd like to hear from you.

Response time
A human reply, usually within one business day
Who we're talking to
Design partners · investors · engineers
Your data
Used only to reply — never shared

We'll only use your details to schedule the conversation. No mailing list, no drip campaigns.

Thanks — we'll be in touch within one business day. Check your inbox for a calendar link.