The AutoPQC platform
Secure Your Data
For The Quantum Era.
AutoPQC finds cryptography in source code, certificate files and dependency manifests. Every finding carries evidence; unresolved algorithms are marked unknown.
- Languages
- JavaPythonC#KotlinGoJavaScript/TypeScript
- Status
- AutoPQC Discovery is in development.
- Roadmap
- Mapping, prioritisation and performance evaluation.
Quantum Clock
——
—— : —— : ——
days · hrs : min : sec
To RSA & ECC deprecation
Every ring is arithmetic on a published date. The window is 39% elapsed.
Counting to NIST IR 8547 · 2030-12-31
Live estate scan
Watch an estate resolve, asset by asset.
Console: Announced (roadmap). This is a roadmap illustration. AutoPQC Discovery is a command-line tool in development. It runs inside your environment and works fully offline.
AutoPQC · roadmap illustration
scanning- RSA-2048
api-gateway
TLS key exchange
- ECDSA-P256
payments-svc
JWT signing
- ECDSA-P256
firmware-sign
Code signing
- RSA-4096
vault-archive
Data at rest
- RSA-2048
ca-root
Certificate authority
Post-quantum standards: ML-KEM · ML-DSA · SLH-DSA — NIST FIPS 203 · 204 · 205
Coverage we track · from the Compatibility Reference
Captured today.
Encrypted traffic can be copied and stored.
Future scenario, not a live decryption or a capability of today’s hardware. Read the NIST explanation
Quantum security · Threat intelligence
Quantum computing is not a future problem. It is a security problem already.
Encrypted traffic captured today can be stored and decrypted the day a cryptographically relevant quantum computer exists — so data with a long confidentiality life is exposed now, not at some future date. The replacement standards are already final: NIST published FIPS 203, 204 and 205 in August 2024. What most organisations lack is not an algorithm but visibility — an inventory of where RSA and ECC actually live in their estate, and a migration sequence that starts with the data that must stay secret longest. Post-quantum readiness is that visibility, planned — and it is buildable today.
The threat is already operational
“Harvest now, decrypt later” is not a future problem.
If your data must stay confidential longer than your migration will take, the deadline has already passed. That inequality — not the arrival date of a quantum computer — is the number that matters.
Today
Your encrypted data is exfiltrated
Adversaries don't need to break RSA or ECC now. They record encrypted traffic and archives — and wait.
The wait
The data sits in an adversary's vault
Medical records, financial contracts, state secrets, IP — anything whose value outlives the encryption protecting it.
Q-Day
A cryptographically relevant quantum computer arrives
Shor's algorithm makes RSA-2048 and ECDSA-P256 tractable. Every harvested archive becomes readable.
After
Yesterday's secrets are decrypted
The breach happened years earlier — it only becomes visible now, when nothing can be done about it.
The Quantum Window
39% of the published PQC migration window has already elapsed.
Both ends of this bar represent published dates: the day the standards were finalized and the year in which the draft transition guidance deprecates RSA-2048 and ECDSA P-256 for federal use. It measures a policy schedule. It is not a prediction of when quantum hardware will arrive, nor is it a statement about what has happened to your data.
The regulatory clock is explicit
2024
NIST finalizes FIPS 203 / 204 / 205
2027
CNSA 2.0 — PQC preferred for new systems
2030
RSA & ECC deprecated (NIST IR 8547 draft)
2035
Classical public-key crypto disallowed
Public signal
What was disclosed this week.
The same two feeds Exposure Signals runs on, unedited: the CISA Known Exploited Vulnerabilities catalogue and GitHub Security Advisories.
Read this for what it is. These are public disclosures about software other people run. It is not a scan of your estate, it tells you nothing about whether any of it reaches you, and it is not evidence about our own systems — that lives in the Assurance Center.
Full radarGlobal PQC readiness · 2024 — 2035
The global quantum transition.
Post-quantum readiness is moving at different speeds across markets. Track the standards, policies and migration signals shaping the transition — every node a published instrument, and markets whose programmes carry no dated mandate shown as tracking, never guessed.
United States
2024 · READINESS
FIPS 203 · 204 · 205 final
NIST publishes the post-quantum standards the world migrates to. The reference point every other lane on this graph works from.
NIST, 13 Aug 2024
2030 · MIGRATION
RSA & ECC deprecated (draft)
NIST's drafted transition timeline discourages classical public-key algorithms after 2030.
NIST IR 8547 (initial public draft)
2033 · URGENCY
CNSA 2.0 transition target
NSA's stated target for quantum-resistant algorithms across national-security systems.
NSA CNSA 2.0
2035 · URGENCY
Disallowed (draft) · NSM-10 goal
The same NIST draft disallows RSA and ECC entirely; NSM-10 set 2035 as the federal migration goal back in 2022.
NIST IR 8547 (draft) · NSM-10
European Union
2024 · EARLY SIGNAL
Coordinated PQC roadmap recommended
The European Commission recommends member states build a coordinated post-quantum implementation roadmap.
EC Recommendation, Apr 2024
2025 · READINESS
DORA applies
The operational-resilience regime applies to financial entities — ICT risk management a cryptographic inventory feeds directly.
EU 2022/2554, from 17 Jan 2025
2030 · MIGRATION
High-risk systems quantum-safe
The EU's coordinated roadmap work targets quantum-safe protection for high-risk use cases by the end of 2030.
EU coordinated PQC roadmap, 2025
2035 · URGENCY
Broad transition horizon
The wider transition target for remaining systems.
EU coordinated PQC roadmap, 2025
United Kingdom
2025 · EARLY SIGNAL
NCSC migration timeline published
The NCSC lays out the national migration path: discover, then migrate by priority.
NCSC PQC migration guidance, Mar 2025
2028 · READINESS
Discovery complete
NCSC's timeline: organisations should have their cryptographic estate identified and migration planned by 2028.
NCSC guidance, Mar 2025
2031 · MIGRATION
High-priority migration done
The most important systems migrated.
NCSC guidance, Mar 2025
2035 · URGENCY
Migration complete
NCSC's end-date for the transition.
NCSC guidance, Mar 2025
Singapore
2024 · EARLY SIGNAL
MAS quantum advisory
The regulator advises financial institutions to inventory cryptography and plan the transition.
MAS/TCRS/2024/01, Feb 2024
2026 · READINESS
Quantum-Safe Handbook + readiness index
CSA, GovTech and IMDA publish practical migration guidance and a self-assessment index for CII owners and agencies.
CSA / GovTech / IMDA, 16 Jul 2026
No national end-date published — guidance says start now; migration called a multi-year effort.
India
2025 · EARLY SIGNAL
National PQC transition whitepaper
MeitY and CERT-In publish a whitepaper on transitioning to post-quantum cryptography — roadmap thinking begins in public.
MeitY / CERT-In, 2025
No dated national mandate published yet.
Canada
2025 · EARLY SIGNAL
Federal migration roadmap
Canada publishes its plan for migrating federal systems to post-quantum cryptography.
Government of Canada / Cyber Centre, 2025
2031 · MIGRATION
High-priority systems migrated
The roadmap's target for the most important federal systems.
GC PQC roadmap, 2025
2035 · URGENCY
Remaining systems migrated
The roadmap's end-date for the rest.
GC PQC roadmap, 2025
Australia
2024 · EARLY SIGNAL
ASD PQC planning guidance
The Australian Signals Directorate publishes planning guidance for the post-quantum transition.
ASD/ACSC guidance
Cryptographic requirements evolving through ASD's ISM updates.
JapanTracking
CRYPTREC runs active PQC monitoring and guidance; no dated national mandate published.
South KoreaTracking
The national KpqC standardisation programme is under way; no dated mandate published.
Nodes marked “(draft)” come from NIST IR 8547, an initial public draft — a proposed timeline, not a final rule. Every other node is a published standard, regulation, advisory, roadmap or stated target of the body named on its card. TRACKING marks a real national programme with no dated public mandate — we would rather show the gap than invent the date.
The AutoPQC platform
Discovery today. Three modules planned.
The Discovery Engine is available. Mapping, prioritisation and performance evaluation are planned, with their intended scope described below.
Module 01
Discovery Engine — available
Discovers cryptography in supported Java, Python, C#, Kotlin, Go and JavaScript/TypeScript source and dependency manifests, certificate and key files, and TLS settings written in code. Produces a CycloneDX inventory with evidence.
Module 02
Migration Mapping Engine — planned
Planned: match discovered assets to post-quantum successors according to their cryptographic role. Not available today.
Module 03
Prioritisation — planned
Planned: order migration work by risk and urgency, with the reasoning behind each recommendation. Not available today.
Module 04
Performance Evaluation — planned
Planned: compare classical and post-quantum performance on customer workloads before migration. Not available today.
What every finding carries
File and line, or certificate field — the evidence, not a summary of it
The detection rule and the method version that produced it, so any report can be reproduced
An honest unknown where the algorithm cannot be resolved — the scanner never guesses
CycloneDX 1.7 (ECMA-424) output, readable by any standards-based tool
It runs inside your environment. Your source code never leaves it.
We measured Bitcoin’s quantum exposure against the public ledger — and published the mistake we made doing it. Read how
How it works
Discovery today. The roadmap ahead.
The Discovery Engine runs today. Mapping, prioritisation and performance evaluation are planned capabilities; they are not part of the current release.
Step 1
Discover — available
Read Java, Python, C#, Kotlin, Go and JavaScript/TypeScript source and dependency manifests, certificate and key files, and TLS settings written in code. Produce a CycloneDX inventory with evidence and explicit unknowns. Live TLS endpoint discovery is planned.
Step 2
Map — planned
Planned: match discovered assets, by cryptographic role, to successors under the NIST post-quantum standards. This capability is not available today.
Step 3
Prioritise — planned
Planned: order migration work by risk and urgency, with the reasoning behind each recommendation. This capability is not available today.
Step 4
Evaluate — planned
Planned: compare classical and post-quantum performance on customer workloads before a change. This capability is not available today.
Three different jobs
Nobody owns this problem alone.
Post-quantum migration lands on three desks at once, and each one is asking a different question. Pick yours — the answer is not the same answer with a different heading.
You have to find it first
Where is the cryptography, actually?
Discovery reads what is actually there: source code (Java, Python, C#, Kotlin, Go and JavaScript/TypeScript) and dependency manifests and certificate files, with every observation tied to a file and line or a certificate field. TLS endpoints, key stores and signing pipelines are on the roadmap and are labelled as such on the How discovery works page.
Every asset gets a primitive, an observed-or-declared marker per input, and an evidence trail. When a finding is contested you can see which dimension moved the score and whether the number came from an observation, a declaration or a derivation.
The scope limits are written down before you start, not discovered afterwards. What the detectors cannot see is documented as plainly as what they can.
See AutoPQC in action
From unknown exposure to a provable plan — in five steps.
This walkthrough shows output for the synthetic reference estate — illustrative, not customer data. Console: Announced (roadmap).
AutoPQC · illustrative walkthrough
1. Discover
$ autopqc scan ./repository
✓ src/payments/crypto_utils.py
✓ auth-service/SignatureVerifier.java
✓ edge/tls/gateway.example.com.crt
✓ vault/kms-policy.json
✓ ci/signing/release_sign.py
AST · JCA patterns · X.509/TLS …
Every finding carries its evidence: file, line, rule and method version
CBOM generated ✓
No assistant
We did not build a chatbot. We published the document instead.
Every vendor in this category is shipping an assistant right now. We thought about it and decided against it, and it is worth saying why out loud rather than quietly.
An assistant that paraphrases a document you cannot open is a worse artifact than the document. It sounds more helpful and it is less checkable. When the answer matters — a tier boundary, a retention window, what a detector actually observes — a confident paraphrase is the last thing you want between you and the source.
So we published the source. 45 articles, 164 defined terms, every scoring rule, every tier boundary, every limit we know about. Then we put a real index over it. No answer on this site is generated when you read it: everything you find was written, reviewed and versioned before you arrived.
It is also cheaper to be honest about. The index is fetched the first time you open search rather than shipped inside every page, so the corpus costs you nothing until you ask for it.
The limit, plainly: search finds what we have written. There is no model behind it that will guess, extrapolate, or fill a gap to seem useful. If it returns nothing, we have not written it yet — and the honest next steps are the Help Desk or asking us directly.
- harvest now decrypt later/knowledge/harvest-now-decrypt-laterKnowledge article
- exposure score/knowledge/exposure-scoreKnowledge article
- fips 203/knowledge/fips-203-204-205Knowledge article
- what we refuse to claim/knowledge/threat-claims-we-avoidKnowledge article
- retention/knowledge/retention-and-deletionKnowledge article
- verify an attestation/attestTool
Six real queries. Every one resolves to a page that exists.
Or press / anywhere on the site.
Open by default
We cannot show you customer logos. We can show you our work.
A claim you cannot open is not evidence, it is a sentence. So nothing below sits behind a form — no email gate, no account, no demo required. Open it, disagree with it, and tell us where we are wrong.
/methodology
The scoring method
Five dimensions, their fixed weights, the four tier boundaries, the fragility floor override, and the estate roll-up worked through arithmetically.
Inspect the published scoring method and its worked example.
Open it/knowledge
45 knowledge articles
How discovery works, what the detectors observe, where the scope ends, what we hold, how long we hold it, and the claims we refuse to make.
No form, no account, no sales call between you and any of it.
Open it/knowledge/lexicon
164 defined terms
Every piece of post-quantum vocabulary this site uses, defined once, in one place, with the aliases people actually search for.
If we use a word here that is not defined there, that is our bug.
Open it/assurance
33 controls, 22 unconfirmed
Our security posture across eight domains, each control marked Implemented, Partial, Planned, Not applicable — or Unconfirmed.
Most vendors show you the eight that pass. The 22 Unconfirmed are the reason to read ours.
Open it/attest
Attestation lookup
The full field layout of a Posture Attestation, with a working lookup tool. The example reference is labelled illustrative because it is illustrative — no real customer document exists to show.
Read the fields before anyone hands you one to sign off.
Open it/.well-known/security.txt
security.txt
Our disclosure contact and policy at the standard location. The Encryption field is deliberately absent: no public key is published yet, and we would rather omit the field than fake it.
Fetch it yourself. It is a text file at a fixed path.
Open it
None of this is a third-party audit. We do not have one, we are not going to imply we have one, and no amount of publishing substitutes for it. What it is: enough detail for you to judge the method yourself before you judge us.
Why Theos Quantum
Built on rock, not on sand.
Migration to post-quantum cryptography is inevitable. Doing it blind is optional.
Discovery with evidence
AutoPQC reads the supported source and certificate files. Each finding records the file, line or certificate field, detection rule and method version that produced it.
Published classification
Each asset's post-quantum verdict follows a published, versioned classification table with its sources cited. An unresolved algorithm is reported as unknown.
A clearly labelled roadmap
Mapping, prioritisation and performance evaluation are planned. Their descriptions explain the intended direction; they are not claims about the current release.
A research moat, not a wrapper
Built on ongoing doctoral research and peer-reviewed work in constraint-aware sequencing, calibrated confidence, and governed execution — science that compounds.
Not yet
What we have not done.
This is the section where most vendors put testimonials. We have no customers to quote and we are not going to write ourselves some. Here is the list we would rather you found from us than from a procurement questionnaire.
22 of our 33 controls are Unconfirmed.
Eight are Implemented, one Partial, one Planned, one Not applicable. The remaining 22 are marked Unconfirmed because we have not verified them to a standard we would defend, and we would rather publish the word Unconfirmed 22 times than round it up to green.
Read the control listWe hold no third-party audit.
No SOC 2 report, no ISO 27001 certificate, no external penetration-test attestation. Publishing our method in full is not a substitute for one and we are not going to present it as though it were.
The attestation example is illustrative.
The Posture Attestation format on this site is real and the lookup tool works. The example document is labelled illustrative because no real customer attestation exists yet to show you.
See the formatWe do not run a paid bug bounty.
Our safe-harbour commitment is real and we will work with anyone who reports in good faith. We cannot currently pay for findings, so we say so on the disclosure page rather than letting researchers discover it after the work.
The disclosure policyNo public key is published.
Our security.txt omits the Encryption field entirely. An empty field is honest; a key URL that resolves to nothing is worse than no key at all. It goes in when a real one exists.
Our live feeds fall back to a snapshot.
Exposure Signals and Sector Pulse fetch CISA KEV and GitHub Security Advisories hourly. When a fetch fails we serve a committed set of real historical advisories and label it SNAPSHOT rather than LIVE. If you see that badge, the badge is telling you the truth.
Check the badge
None of this is an apology and none of it is a roadmap promise. It is the current state, and the current state changes — which is why it is written down in two places that stay current rather than in a paragraph nobody edits again.

