Website PQC Readiness Scanner

Verify whether public endpoints support Level 3 PQC.

Scan domains for TLS posture, certificate health, DNS email security, security headers, and real Level 3 hybrid PQC TLS negotiation using X25519MLKEM768 / ML-KEM-768.

Live MVP scanner

Know your quantum risk before attackers do.

Scan public domains for TLS readiness, certificate posture, security headers, DNS email security, and real Level 3 post-quantum TLS negotiation.

/api/scan
Domain Scanner
External cryptographic assessment
Readiness
75/100
Risk
Low
TLS
TLSv1.3
PQC Level 3
Demo / not tested

Real PQC Level 3

Not Configured

Unknown
Offered groupX25519MLKEM768
AlgorithmML-KEM-768
NIST category3
Negotiated groupNot observed

QuantumShield attempts a TLS 1.3 handshake while offering X25519MLKEM768 as the Level 3 hybrid PQC group.

75
/100
Quantum Readiness
Low Risk

Executive Summary

stripe.com

This public scan gives a first-pass view of TLS, certificates, security headers, email DNS security, and post-quantum migration signals. It does not prove complete internal quantum safety; it helps prioritize the migration conversation.

Low risk
TLS
TLSv1.3
Cipher
TLS_AES_256_GCM_SHA384
Cert issuer
Google Trust Services
Cert expiry
218 days

Checks

HTTPS available
pass

The domain responds on HTTPS port 443.

15/15 points

TLS 1.3 baseline
pass

TLS 1.3 is active.

20/20 points

Certificate validity
pass

Certificate is valid for about 218 days.

15/15 points

HSTS enabled
pass

Strict-Transport-Security header is present.

10/10 points

Security headers
pass

3/4 supporting security headers detected.

10/10 points

Email DNS security
warning

SPF: yes, DMARC: no.

5/10 points

PQC public signal
fail

No public post-quantum TLS signal was detected by this MVP scan.

0/20 points

Recommendations
  • Add SPF and DMARC to improve email-domain security posture.
  • Evaluate a PQC-ready CDN, edge provider, or TLS termination layer.
  • Inventory RSA/ECC certificates, SSH keys, VPNs, S/MIME, and code-signing keys.
  • Prioritize long-lived sensitive data for harvest-now-decrypt-later risk review.
  • Create a crypto-agility migration roadmap aligned to NIST-standardized PQC algorithms.
30 / 60 / 90 day roadmap

Next 30 days

  • Create a public-domain and certificate inventory.
  • Identify owners for TLS, VPN, SSH, email, and code-signing systems.
  • Fix missing TLS 1.3, HSTS, SPF, and DMARC basics.

Next 60 days

  • Classify long-lived confidential data exposed to harvest-now-decrypt-later risk.
  • Evaluate PQC-ready edge/CDN options and hybrid TLS support.
  • Start vendor questionnaire for PQC migration readiness.

Next 90 days

  • Pilot hybrid PQC TLS on one non-critical service.
  • Define crypto-agility policy for new systems and vendors.
  • Prepare board-level migration budget and ownership plan.

What the scanner verifies

The scanner tests public-facing security posture and attempts a real Level 3 hybrid PQC TLS handshake through your PQC backend.

What it does not prove

It does not prove the entire company is quantum-safe. It only verifies observable posture on the scanned public endpoint.

Best use case

Use it for first-pass domain assessment, vendor due diligence, board-ready reporting, and migration prioritization.