Post-quantum preparedness scanner

Your TLS used to get an A grade.
Against harvest it's a C at best.

[PQ]probe inventories the cryptography actually inside and connected to your environment: networks, code, dependencies, keys on disk, Windows endpoints, passive traffic. It grades it A to F for post-quantum preparedness, maps it to CNSA 2.0, NIS2 and BSI TR-02102, then tracks whether you're getting better or worse.

Try:

Free external probe · no sign-up · deploy on-prem for the full inventory

Why a different grade

Where you came from is not where you have to go.

Classical scanners grade TLS against past attacks. [PQ]probe grades it against the quantum threat ahead. The same server can honestly earn both an A and a C.

Classical scanner
A−
  • TLS 1.3 ✓
  • AES-256-GCM ✓
  • ECDHE X25519 ✓
  • RSA-2048 cert ✓
[PQ]probe
C
  • No PQ KEX ✗
  • Harvest-now risk ✗
  • RSA signature ✗
  • CNSA 2.0 2027 ✗
Trajectory, not snapshots

Will you hit 2030 at your current pace?

Every scan adds to the history. [PQ]probe marks each host IMPROVING, DEGRADING, STABLE or OSCILLATING and projects your rate of change onto the CNSA 2.0 deadlines, so you see a miss years before it happens.

IMPROVING DEGRADING STABLE
NIS2 cohort · PQ key exchange
n = 1,240 endpoints, same set throughout
IMPROVING
100% 50% 0% CNSA 2.0 · 2030 //
2026-07-04today · 41.1%projected

30-day change: +2.0 pts. At this pace the panel reaches 100% in 2028, ahead of the 2030 deadline. NIS2 Monitor

Seven discovery methods · one inventory

Find every place cryptography lives, not just your website.

Network
Grade every service that negotiates crypto.
35 service types · 66 ports · 20 protocol scanners: TLS, SSH, SMTP, RDP, LDAP, databases
Passive
Assess OT and medical devices without touching them.
pcap / pcapng · 13 protocols incl. HL7, DICOM
Code
Block weak crypto in CI before it ships.
14 languages · 176 patterns · SARIF, CBOM
Dependencies
Know which libraries hold you back, and the first version with PQC support.
9 ecosystems incl. npm, PyPI, Maven, Cargo · transitive via lockfiles
Filesystem
Find every certificate and key sitting on disk.
PEM, DER, PKCS#12, JKS, SSH, GPG · Linux, macOS, Windows
Endpoints
Find NTLM still allowed and still used on Windows.
LmCompatibilityLevel registry · event 4624 NTLMv1/v2 logons
Defender import
Census crypto libraries across your fleet, with no agent to deploy.
Microsoft Defender for Endpoint · software inventory and certificate tables
Every method feeds the same inventory.
See every protocol
Compliance mapping

Mapped to the frameworks you answer to.

CNSA 2.0 NIS2 DORA BSI TR-02102-1 PCI DSS 4.0 FIPS 140-2/140-3 HIPAA CISA PQC CBOM CycloneDX 1.6

Exports to Jira, SARIF 2.1.0 for GitHub and GitLab code scanning, CSV and JSON for SIEM and CMDB import, and a REST API.

Runs on your network

Your inventory never leaves your network.

Single binary
Pure Go, no external dependencies. Tarball, systemd unit or Docker.
Air-gapped
No telemetry, license server or update checks.
Outbound
Only to the targets you scan, plus GitHub or Jira if you connect them.
Auth
API key or OAuth on every non-public route with --require-auth.

Recent public probes

Private probes are never listed.

Loading...

Built by someone who's done this before
“Here to help shrink the gap between what vendors say about your preparedness and what their products actually negotiate.”
Davi Ottenheimer · Founder

See your whole environment, not one domain.

We assess your posture, deploy [PQ]probe on your infrastructure, and leave you with continuous monitoring you own.