Features · Discovery, tracking and reporting

Every place cryptography lives, graded A to F and tracked over time.

A probe scans every protocol surface that negotiates cryptography—TLS, SSH, SMTP, IMAP, RDP, database protocols, healthcare protocols, message brokers, filesystem sharing. Over twenty protocols across roughly thirty port variations. Each scan is graded A through F against CNSA 2.0 compliance timelines, and every result feeds a temporal trajectory—IMPROVING, DEGRADING, or STABLE—so you always know whether your migration is on pace. Seven discovery methods feed one cryptographic inventory. Pick the one that fits your workflow, or use them all.

Discovery · seven methods, one inventory

Source code, dependencies, filesystems, networks, endpoints. Each method feeds the same inventory.

Every method feeds the same inventory, graded on the same A–F scale. Full protocol list →
Network

Find every cryptographic service on your network. 35 service types on 66 ports, 20 protocol scanners, graded A–F.

Web & Access
TLS/HTTPS, SSH, RDP
Email
SMTP, IMAP, POP3
Infrastructure
LDAP, SMB/NTLM, MySQL, PostgreSQL, MongoDB, Redis
Specialized
Kafka, RabbitMQ, XMPP, FHIR, HL7/MLLP, DICOM +60 more
Full protocol list →
Tracking

Every scan adds to the history. Trends emerge automatically.

Each host is marked IMPROVING, DEGRADING or STABLE from its trailing scans, and its rate of change is projected onto the deadlines it answers to.

Trending
See grades improve or regress across your inventory.
History
Full scan history for every asset, every method.
Diff
What changed between scans — new findings, resolved issues, grade shifts.
Prioritize
Focus on what matters most for your deadlines.
Project
At your current rate, will you hit CNSA 2027? 2030? 2035? Extrapolate compliance trajectory against real deadlines.
Reporting

Standards-based outputs. Fits into existing workflows.

Compliance
CNSA 2.0
2027 / 2030 / 2035
PCI DSS 4.0 / NIS2
gap analysis
BSI TR-02102 / FIPS 140
hybrid PQC
HIPAA / DORA / CISA
sector-specific
CBOM
CycloneDX 1.6
CSV / JSON
CMDB, SIEM export
Integration
Jira
issues, auto-close, reopen
GitHub / GitLab
SARIF, PR annotations
Microsoft Defender
MDE software inventory import
nmap
import existing scans
Database
SQLite or PostgreSQL
REST API
all scan data
Deployment · runs on your network

Single binary. Zero external dependencies. No data leaves your network.

Distribution Package

Tarball with binaries, systemd unit, config template, and step-by-step install guide. Extract, configure, start.

Auth Enforcement

Set PQPROBE_REQUIRE_AUTH to gate all non-public routes behind API key or OAuth. Bootstrap admin key generated on first run.

Docker

Container images for server, CLI, and static analyzer. Single-container deployment with embedded workers and SQLite.

Air-Gapped

No telemetry, no license server, no update checks. The only outbound connections are to the targets you scan.

See what's in your environment

We assess your cryptographic posture, deploy [PQ]probe on your infrastructure, and leave you with continuous monitoring that runs on your network.