[PQ]probe finds the cryptography in use across an organisation (source code, dependencies, filesystems, networks, captured traffic, endpoints, and device inventories) and grades every finding against post-quantum deadlines. It runs inside your environment, air-gapped, and nothing leaves your network.
Ottenheimer GmbH was founded in Berlin in 2026 to build it. We also turn the same scanner outward: we measure what vendors and regulated sectors actually negotiate on the public wire, and we publish what we find. We are not a vendor of post-quantum algorithms. We scan, we grade, we publish, and we run migrations.
What we publish
The PQC Vendor Scorecard, quarterly. Twenty-eight major technology vendors across eight product categories, from browsers and CDNs to databases and enterprise SaaS, checked against CISA's deployment framework and against what their endpoints negotiate. Free download, no gate. The Q1 and Q2 2026 editions are in [PQ]files; the next follows in October.
Sector cohorts, continuously. We maintain a scan population of regulated entities across NIS2 sectors (currently more than 1,200 classified hosts in eighteen sectors), graded A–F on every scan and tracked for trajectory: improving, degrading, or stable. Results are published as [PQ]monitor and in sector reports.
Method and analysis. Where measurement needs a method, we publish the method: how edge-delivered post-quantum key exchange is attributed to a CDN rather than to the organisation behind it, why widely cited adoption figures are a floor rather than a ceiling, and what a grade does and does not claim. Where a vendor announcement, a regulatory deadline, or a cryptanalytic paper changes the picture, we say what changed and what did not.
How the published measurements work
- Scans run from our own infrastructure with the same reach any client has. Nothing is inferred from questionnaires or vendor statements. A named algorithm can be probed; “quantum-safe architecture” cannot.
- More than twenty protocols are probed (TLS, SSH, SMTP, IMAP, RDP, database, healthcare, and messaging) across roughly thirty port variations.
- A host's grade is its worst probe. Averages hide the weak link.
- A probe that times out or resets is recorded as unknown, not as a failure. Grades are computed on known facts only.
- Published figures include only scheduled scans of the declared population. Public one-off scans are excluded.
- Operators can opt out by emailing abuse@pqprobe.com with a hostname or range.
Corrections are published in place. The Q2 Scorecard records two Q1 errors and what replaced them.
Working with us
The same seven discovery methods, on your own estate. Deployment is a single binary, on-premises or air-gapped.
- Free probe: check any host, repository, or dependency tree at pqprobe.com/app, with mapping to NIS2, CNSA 2.0, and PCI DSS.
- Guidance Mode: full [PQ]probe access for your team, with monthly expert hours and findings review, for organisations running their own migration.
- Project Mode: inventory, assessment, grading, and a sequenced roadmap with a dated trajectory, delivered by our team in your environment. Enterprise engagements are delivered with esatus AG.
- Research access: independent researchers, academics, and journalists can use [PQ]probe under a non-commercial licence, with version and checksums provided so results can be reproduced and published.
Team
Ottenheimer GmbH was founded by Davi Ottenheimer, who led security at Yahoo!, EMC, VMware, ArcSight, and MongoDB, including large, complex cryptographic migrations. He joined MongoDB to bring field-level encryption to document databases, creating the project and leading it through its first release, and established the company's CISO role.
“Here to help shrink the gap between what vendors say about your preparedness and what their products actually negotiate.”
Contact
hello@pqprobe.com: engagements, press, research, corrections, and everything else.
Ottenheimer GmbH · Berlin, Germany · Impressum