Product Built around India's quantum-safe framework

The platform behind a quantum-safe migration

See the cryptography you run, find what's most exposed, get a phased plan to NIST PQC — and the board-ready evidence to prove it. Grounded in the DST National Quantum Mission roadmap and the regulators your auditors answer to: RBI, SEBI, IRDAI, CERT-In.

🔒 The free scan reads only what's publicly negotiated in a TLS handshake — no sign-in, nothing stored.

KavachQ · Cryptographic inventory
KavachQ console — cryptographic inventory dashboard: high-risk crypto objects, PQC-ready share, total assets, and algorithm families ranked by severity.
The working console — not a mockup. A real cryptographic-inventory view, captured on a demo tenant. Numbers are illustrative; real client estates never leave your environment. See more real screens ↓
Where KavachQ fits

Made for the way India regulates and runs

Global crypto-discovery tools map to someone else's regulator. KavachQ is shaped around India's framework, deadlines, and deployment constraints.

India's framework, natively

Grounded in the DST National Quantum Mission roadmap, its M1/M2/M3 milestones, and India's regulators — not a foreign mandate.

Runs in your environment

Managed scan, in-VPC, on-prem, or air-gapped self-hosted Docker. Your cryptographic inventory stays inside your boundary.

Open, portable evidence

The inventory is a signed CBOM in open CycloneDX 1.6 — evidence your own auditors can reproduce, and that travels with you. No lock-in.

Try before you talk to us

Start with a free public scan of any domain's TLS — no sign-in, results in seconds. See the product work before a conversation.

The flow

From your estate to a signed-off plan

One pipeline. Your cryptography goes in; a ranked plan and audit-ready evidence come out.

INPUT Public TLS + the certs / CBOM you supply
01

Discover

Build a Cryptographic Bill of Materials — certificates, algorithms, and the key parameters behind them — in CycloneDX 1.6.

OUT → signed CBOM
02

Score

Score every asset 0–100 and tier it T1–T4 — algorithm strength, internet exposure, criticality, cert expiry, harvest-now — worst-first.

OUT → risk register
03

Plan

A phased, impact-aware move to ML-KEM / ML-DSA / SLH-DSA — hybrid by default, with the apps each change touches mapped.

OUT → migration plan
04

Hand off

Export the phased roadmap to Jira (CSV) / your tracker. Your team executes — KavachQ never touches production.

OUT → Jira / tracker CSV
05

Prove

A board PDF + signed CBOM, every finding tagged to DST/NQM milestones and the relevant RBI / SEBI / CERT-In references.

OUT → board pack
OUTPUT Board pack + machine-readable CBOM

The free scan runs stages 01–02 on your public TLS, instantly. The rest unlocks in an engagement.

Discovery scope today — stated plainly

Shipping now: live public-TLS scanning; source and config scanning with a file path and line number behind every finding; cloud estate discovery from your own read-only AWS / Azure CLI exports (KMS, ACM, ELBv2, Key Vault keys and certificates — we ship no cloud SDK and hold no cloud credentials); PKCS#12 keystore enumeration when you supply the password; agentic machine-identity anchors; plus ingest of the certificates, SBOMs and CBOMs you supply (CSV, tarball, or CycloneDX 1.6). All of it serialises into one signed CBOM with a quantum-risk graph, exportable as CycloneDX 1.6 or SPDX 2.3. On the roadmap: agent-based internal discovery and CA/PKI chain walking — we read the chain a host or keystore presents, but do not yet walk issuers up to a root. We name the surfaces we cover, so the gaps are never implied away.

Where KavachQ sits

In your evidence path — never your control path

A CISO should never put a third party between their production traffic and their keys. KavachQ reads and advises; you stay in control of every change.

YOUR ENVIRONMENT

You stay in control

  • Your cryptographic estate & production keys
  • Your team makes every change
  • Deploy KavachQ in-VPC, on-prem, or air-gapped
  • Keys never leave your boundary
READ-ONLY ⇄ PLAN & EVIDENCE
KAVACHQ

Reads & advises

  • Discovers cryptography (read-only)
  • Scores quantum risk (0–100, T1–T4)
  • Plans the phased migration
  • Produces the CBOM & board evidence

Trust boundary — KavachQ does not hold, rotate, or enforce your production cryptography.

What you walk away with

Concrete artifacts your board and auditor accept

Not a dashboard you have to live in — portable deliverables you own.

01 · Inventory

A cryptographic inventory (CBOM)

Every certificate, algorithm, and key parameter we can see — a signed CycloneDX 1.6 CBOM your auditors can re-open.

02 · Risk

A ranked quantum-risk register

A 0–100 score and a T1–T4 tier per asset — algorithm strength, exposure, criticality, cert expiry, and harvest-now risk.

03 · Plan

A phased migration plan

A sequenced, impact-aware move to ML-KEM / ML-DSA / SLH-DSA your team can calendar — hybrid by default.

04 · Evidence

A board-ready report

A board PDF + signed CBOM — every finding tagged to DST/NQM milestones and RBI / SEBI / CERT-In references.

kavachq · board-pack.pdf
BOARD PACK · DST / NQMCBOM ✓ signed
T1 · Critical12
T2 · High34
T3 · Medium88
T4 · Low210
payments-api · RSA-204892
core-banking · 3DES88
vpn-gw · ECDH-P25664
archive · AES-25618
SCORED 0–100 · TIERED T1–T4 · HNDL-WEIGHTED

Illustrative output — not real customer data.

Inside the platform

Real screens from the working console

Not a rendered mockup — the actual KavachQ console, captured on a demo tenant. The numbers are illustrative, and real client estates never leave your environment.

KavachQ · CBOM map
KavachQ console — CBOM map plotting each estate asset as a node coloured by quantum risk: vulnerable, weakened, or quantum-safe.
The estate as a CBOM. Each asset plotted by quantum risk — vulnerable, weakened, or already quantum-safe.
KavachQ · Dependency graph
KavachQ console — crypto dependency graph linking application risk tiers to the vulnerable algorithm families they depend on.
Crypto dependency graph. Which applications, grouped by risk tier, lean on which quantum-vulnerable algorithm families.
KavachQ · Blast radius
KavachQ console — blast radius view showing every application and certificate that depends on a single quantum-vulnerable algorithm.
Blast radius. Every application and certificate that falls if one algorithm — here SHA-256-with-RSA — is broken. Client identifiers are blurred.

Captured from the working KavachQ console on a demo tenant · illustrative data · client identities blurred or omitted.

How an engagement starts

Start small, prove value, then scale

A low-commitment path — see it work before you widen the scope.

1

Free public scan

Run it on any domain today. See Discover + Score on your public TLS in seconds — no sign-in, nothing stored.

NOW · SELF-SERVE
2

Scoped assessment

A scoped engagement on a slice of your estate — supply your certs / CBOM and get a real signed CBOM, a ranked risk register, and a first plan.

SCOPED ENGAGEMENT
3

Deploy in your environment

Run KavachQ where your regulated data lives — in-VPC, on-prem, or air-gapped self-hosted Docker — with no key custody.

IN YOUR VPC
Fits your workflow

Hands off to the tools you already run

KavachQ produces portable artifacts, so the plan lands where your team already works.

Shipping today

Export to Jira (CSV)

The phased roadmap exports as a Jira-ready CSV — alongside the signed CycloneDX 1.6 CBOM and a JSON risk graph that drop into any system you run.

On the roadmap

Direct connectors

Two-way connectors are planned, not shipped — shown greyed so nothing is implied as live.

cloud · AWS / Azure CA / PKI HSM / key store GitHub / GitLab ServiceNow
Understand it first

We'd rather you learn than be sold to

Free, open material on the quantum threat and India's response — the understanding our team works from.

What you can verify today

Proof you can check yourself

Free public scan

Run it on any domain. The product works in front of you, before any sales call.

Signed CycloneDX 1.6

A standard, machine-readable CBOM — reproducible, portable, no lock-in.

Air-gap-ready

Self-hosted Docker (incl. air-gapped) keeps sensitive estates inside your boundary.

Vendor-neutral

We summarise official DST and NIST sources plainly; no pay-for-placement.

Get started

See your exposure in seconds

Run a free scan, then bring KavachQ to your whole estate — discovery, scoring, planning, and proof, aligned to India's framework.