Find quantum-vulnerable cryptography inside codebases.
The Developer Copilot scans repositories for classical cryptography that may require post-quantum migration, while also detecting early PQC adoption signals such as ML-KEM, ML-DSA, SLH-DSA, liboqs, oqs-provider, OpenSSL 3.5, and hybrid TLS groups.
Scan GitHub repos for risky crypto and PQC maturity.
Detect RSA, ECDSA, ECDH, hardcoded keys, weak TLS settings, weak JWT signing, old OpenSSL references, and real PQC migration signals such as ML-KEM, ML-DSA, SLH-DSA, liboqs, oqs-provider, OpenSSL 3.5, Cloudflare CIRCL, and X25519MLKEM768.
Why code scanning matters
Most organizations do not know where RSA, ECDSA, ECDH, weak JWT signing, old TLS configurations, or hardcoded keys exist across their repositories.
What PQC maturity means
PQC maturity does not mean a repo is quantum-safe. It means the repo contains signs of migration planning, PQC libraries, PQC algorithms, or hybrid TLS configuration.
Repo-to-runtime gap
A repo may mention PQC, but the production endpoint may not negotiate PQC. Pair this page with the Website Scanner for live endpoint verification.