Skip to content
Theos Quantum TQ globe markTHEOS QUANTUM

The AutoPQC platform

Secure Your Data For The Quantum Era.

AutoPQC finds cryptography in source code, certificate files and dependency manifests. Every finding carries evidence; unresolved algorithms are marked unknown.

Languages
JavaPythonC#KotlinGoJavaScript/TypeScript
Status
AutoPQC Discovery is in development.
Roadmap
Mapping, prioritisation and performance evaluation.
ML-KEM · FIPS 203ML-DSA · FIPS 204SLH-DSA · FIPS 205FALCON

Quantum Clock

——

—— : —— : ——

days · hrs : min : sec

To RSA & ECC deprecation

Every ring is arithmetic on a published date. The window is 39% elapsed.

Counting to NIST IR 8547 · 2030-12-31

UTC—
Local—
Date—
Plotted records23 · sourced
StandardsFIPS 203 · 204 · 205 final

Live estate scan

Watch an estate resolve, asset by asset.

Console: Announced (roadmap). This is a roadmap illustration. AutoPQC Discovery is a command-line tool in development. It runs inside your environment and works fully offline.

AutoPQC · roadmap illustration

scanning
  • api-gateway

    TLS key exchange

    RSA-2048
  • payments-svc

    JWT signing

    ECDSA-P256
  • firmware-sign

    Code signing

    ECDSA-P256
  • vault-archive

    Data at rest

    RSA-4096
  • ca-root

    Certificate authority

    RSA-2048
0/5 illustrative mappings · planned capabilityExample only

Captured today.

Encrypted traffic can be copied and stored.

Future scenario, not a live decryption or a capability of today’s hardware. Read the NIST explanation

Quantum security · Threat intelligence

Quantum computing is not a future problem. It is a security problem already.

Encrypted traffic captured today can be stored and decrypted the day a cryptographically relevant quantum computer exists — so data with a long confidentiality life is exposed now, not at some future date. The replacement standards are already final: NIST published FIPS 203, 204 and 205 in August 2024. What most organisations lack is not an algorithm but visibility — an inventory of where RSA and ECC actually live in their estate, and a migration sequence that starts with the data that must stay secret longest. Post-quantum readiness is that visibility, planned — and it is buildable today.

The threat is already operational

“Harvest now, decrypt later” is not a future problem.

If your data must stay confidential longer than your migration will take, the deadline has already passed. That inequality — not the arrival date of a quantum computer — is the number that matters.

  1. Today

    Your encrypted data is exfiltrated

    Adversaries don't need to break RSA or ECC now. They record encrypted traffic and archives — and wait.

  2. The wait

    The data sits in an adversary's vault

    Medical records, financial contracts, state secrets, IP — anything whose value outlives the encryption protecting it.

  3. Q-Day

    A cryptographically relevant quantum computer arrives

    Shor's algorithm makes RSA-2048 and ECDSA-P256 tractable. Every harvested archive becomes readable.

  4. After

    Yesterday's secrets are decrypted

    The breach happened years earlier — it only becomes visible now, when nothing can be done about it.

The Quantum Window

39% of the published PQC migration window has already elapsed.

YOU ARE HERE
2024 · NIST PQC standards final2030 · RSA & ECC deprecated

Both ends of this bar represent published dates: the day the standards were finalized and the year in which the draft transition guidance deprecates RSA-2048 and ECDSA P-256 for federal use. It measures a policy schedule. It is not a prediction of when quantum hardware will arrive, nor is it a statement about what has happened to your data.

The regulatory clock is explicit

  1. 2024

    NIST finalizes FIPS 203 / 204 / 205

  2. 2027

    CNSA 2.0 — PQC preferred for new systems

  3. 2030

    RSA & ECC deprecated (NIST IR 8547 draft)

  4. 2035

    Classical public-key crypto disallowed

Public signal

What was disclosed this week.

The same two feeds Exposure Signals runs on, unedited: the CISA Known Exploited Vulnerabilities catalogue and GitHub Security Advisories.

LIVE · HOURLY
  • CISA KEV

    CVE-2026-87902

    WordPress Core Remote File Inclusion Vulnerability

    2026-09-25Source
  • GHSAhigh

    GHSA-q986-4x7x-gx39

    SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests

    2026-09-25Source
  • CISA KEV

    CVE-2026-65660

    Microsoft SharePoint Code Injection Vulnerability

    2026-09-25Source
  • GHSAhigh

    GHSA-vj8p-hp9x-gh47

    mpp vulnerable to Gas Draining with low gas limit

    2026-09-25Source
  • CISA KEV

    CVE-2026-67279

    Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

    2026-09-25Source
  • GHSAmedium

    GHSA-qpxh-ff8m-c62v

    mpp vulnerable to Gas Draining with access list

    2026-09-25Source

Read this for what it is. These are public disclosures about software other people run. It is not a scan of your estate, it tells you nothing about whether any of it reaches you, and it is not evidence about our own systems — that lives in the Assurance Center.

Full radar

Global PQC readiness · 2024 — 2035

The global quantum transition.

Post-quantum readiness is moving at different speeds across markets. Track the standards, policies and migration signals shaping the transition — every node a published instrument, and markets whose programmes carry no dated mandate shown as tracking, never guessed.

United States

  • 2024 · READINESS

    FIPS 203 · 204 · 205 final

    NIST publishes the post-quantum standards the world migrates to. The reference point every other lane on this graph works from.

    NIST, 13 Aug 2024

  • 2030 · MIGRATION

    RSA & ECC deprecated (draft)

    NIST's drafted transition timeline discourages classical public-key algorithms after 2030.

    NIST IR 8547 (initial public draft)

  • 2033 · URGENCY

    CNSA 2.0 transition target

    NSA's stated target for quantum-resistant algorithms across national-security systems.

    NSA CNSA 2.0

  • 2035 · URGENCY

    Disallowed (draft) · NSM-10 goal

    The same NIST draft disallows RSA and ECC entirely; NSM-10 set 2035 as the federal migration goal back in 2022.

    NIST IR 8547 (draft) · NSM-10

European Union

  • 2024 · EARLY SIGNAL

    Coordinated PQC roadmap recommended

    The European Commission recommends member states build a coordinated post-quantum implementation roadmap.

    EC Recommendation, Apr 2024

  • 2025 · READINESS

    DORA applies

    The operational-resilience regime applies to financial entities — ICT risk management a cryptographic inventory feeds directly.

    EU 2022/2554, from 17 Jan 2025

  • 2030 · MIGRATION

    High-risk systems quantum-safe

    The EU's coordinated roadmap work targets quantum-safe protection for high-risk use cases by the end of 2030.

    EU coordinated PQC roadmap, 2025

  • 2035 · URGENCY

    Broad transition horizon

    The wider transition target for remaining systems.

    EU coordinated PQC roadmap, 2025

United Kingdom

  • 2025 · EARLY SIGNAL

    NCSC migration timeline published

    The NCSC lays out the national migration path: discover, then migrate by priority.

    NCSC PQC migration guidance, Mar 2025

  • 2028 · READINESS

    Discovery complete

    NCSC's timeline: organisations should have their cryptographic estate identified and migration planned by 2028.

    NCSC guidance, Mar 2025

  • 2031 · MIGRATION

    High-priority migration done

    The most important systems migrated.

    NCSC guidance, Mar 2025

  • 2035 · URGENCY

    Migration complete

    NCSC's end-date for the transition.

    NCSC guidance, Mar 2025

Singapore

  • 2024 · EARLY SIGNAL

    MAS quantum advisory

    The regulator advises financial institutions to inventory cryptography and plan the transition.

    MAS/TCRS/2024/01, Feb 2024

  • 2026 · READINESS

    Quantum-Safe Handbook + readiness index

    CSA, GovTech and IMDA publish practical migration guidance and a self-assessment index for CII owners and agencies.

    CSA / GovTech / IMDA, 16 Jul 2026

No national end-date published — guidance says start now; migration called a multi-year effort.

India

  • 2025 · EARLY SIGNAL

    National PQC transition whitepaper

    MeitY and CERT-In publish a whitepaper on transitioning to post-quantum cryptography — roadmap thinking begins in public.

    MeitY / CERT-In, 2025

No dated national mandate published yet.

Canada

  • 2025 · EARLY SIGNAL

    Federal migration roadmap

    Canada publishes its plan for migrating federal systems to post-quantum cryptography.

    Government of Canada / Cyber Centre, 2025

  • 2031 · MIGRATION

    High-priority systems migrated

    The roadmap's target for the most important federal systems.

    GC PQC roadmap, 2025

  • 2035 · URGENCY

    Remaining systems migrated

    The roadmap's end-date for the rest.

    GC PQC roadmap, 2025

Australia

  • 2024 · EARLY SIGNAL

    ASD PQC planning guidance

    The Australian Signals Directorate publishes planning guidance for the post-quantum transition.

    ASD/ACSC guidance

Cryptographic requirements evolving through ASD's ISM updates.

JapanTracking

CRYPTREC runs active PQC monitoring and guidance; no dated national mandate published.

South KoreaTracking

The national KpqC standardisation programme is under way; no dated mandate published.

Nodes marked “(draft)” come from NIST IR 8547, an initial public draft — a proposed timeline, not a final rule. Every other node is a published standard, regulation, advisory, roadmap or stated target of the body named on its card. TRACKING marks a real national programme with no dated public mandate — we would rather show the gap than invent the date.

The AutoPQC platform

Discovery today. Three modules planned.

The Discovery Engine is available. Mapping, prioritisation and performance evaluation are planned, with their intended scope described below.

Module 01

Discovery Engine — available

Discovers cryptography in supported Java, Python, C#, Kotlin, Go and JavaScript/TypeScript source and dependency manifests, certificate and key files, and TLS settings written in code. Produces a CycloneDX inventory with evidence.

AST analysisJCA patternsX.509CBOM
Explore the module

Module 02

Migration Mapping Engine — planned

Planned: match discovered assets to post-quantum successors according to their cryptographic role. Not available today.

PlannedKey establishmentDigital signaturesStandards cited
Explore the module

Module 03

Prioritisation — planned

Planned: order migration work by risk and urgency, with the reasoning behind each recommendation. Not available today.

PlannedRisk and urgencyData confidentiality lifeReasoning per asset
Explore the module

Module 04

Performance Evaluation — planned

Planned: compare classical and post-quantum performance on customer workloads before migration. Not available today.

PlannedLatencyKey sizesSignature sizes
Explore the module

What every finding carries

File and line, or certificate field — the evidence, not a summary of it

The detection rule and the method version that produced it, so any report can be reproduced

An honest unknown where the algorithm cannot be resolved — the scanner never guesses

CycloneDX 1.7 (ECMA-424) output, readable by any standards-based tool

It runs inside your environment. Your source code never leaves it.

We measured Bitcoin’s quantum exposure against the public ledger — and published the mistake we made doing it. Read how

How it works

Discovery today. The roadmap ahead.

The Discovery Engine runs today. Mapping, prioritisation and performance evaluation are planned capabilities; they are not part of the current release.

Step 1

Discover — available

Read Java, Python, C#, Kotlin, Go and JavaScript/TypeScript source and dependency manifests, certificate and key files, and TLS settings written in code. Produce a CycloneDX inventory with evidence and explicit unknowns. Live TLS endpoint discovery is planned.

Step 2

Map — planned

Planned: match discovered assets, by cryptographic role, to successors under the NIST post-quantum standards. This capability is not available today.

Step 3

Prioritise — planned

Planned: order migration work by risk and urgency, with the reasoning behind each recommendation. This capability is not available today.

Step 4

Evaluate — planned

Planned: compare classical and post-quantum performance on customer workloads before a change. This capability is not available today.

Three different jobs

Nobody owns this problem alone.

Post-quantum migration lands on three desks at once, and each one is asking a different question. Pick yours — the answer is not the same answer with a different heading.

You have to find it first

Where is the cryptography, actually?

  1. Discovery reads what is actually there: source code (Java, Python, C#, Kotlin, Go and JavaScript/TypeScript) and dependency manifests and certificate files, with every observation tied to a file and line or a certificate field. TLS endpoints, key stores and signing pipelines are on the roadmap and are labelled as such on the How discovery works page.

  2. Every asset gets a primitive, an observed-or-declared marker per input, and an evidence trail. When a finding is contested you can see which dimension moved the score and whether the number came from an observation, a declaration or a derivation.

  3. The scope limits are written down before you start, not discovered afterwards. What the detectors cannot see is documented as plainly as what they can.

See AutoPQC in action

From unknown exposure to a provable plan — in five steps.

This walkthrough shows output for the synthetic reference estate — illustrative, not customer data. Console: Announced (roadmap).

AutoPQC · illustrative walkthrough

1. Discover

$ autopqc scan ./repository

✓ src/payments/crypto_utils.py

✓ auth-service/SignatureVerifier.java

✓ edge/tls/gateway.example.com.crt

✓ vault/kms-policy.json

✓ ci/signing/release_sign.py

AST · JCA patterns · X.509/TLS …

Every finding carries its evidence: file, line, rule and method version

CBOM generated ✓

No assistant

We did not build a chatbot. We published the document instead.

Every vendor in this category is shipping an assistant right now. We thought about it and decided against it, and it is worth saying why out loud rather than quietly.

An assistant that paraphrases a document you cannot open is a worse artifact than the document. It sounds more helpful and it is less checkable. When the answer matters — a tier boundary, a retention window, what a detector actually observes — a confident paraphrase is the last thing you want between you and the source.

So we published the source. 45 articles, 164 defined terms, every scoring rule, every tier boundary, every limit we know about. Then we put a real index over it. No answer on this site is generated when you read it: everything you find was written, reviewed and versioned before you arrived.

It is also cheaper to be honest about. The index is fetched the first time you open search rather than shipped inside every page, so the corpus costs you nothing until you ask for it.

The limit, plainly: search finds what we have written. There is no model behind it that will guess, extrapolate, or fill a gap to seem useful. If it returns nothing, we have not written it yet — and the honest next steps are the Help Desk or asking us directly.

Open by default

We cannot show you customer logos. We can show you our work.

A claim you cannot open is not evidence, it is a sentence. So nothing below sits behind a form — no email gate, no account, no demo required. Open it, disagree with it, and tell us where we are wrong.

None of this is a third-party audit. We do not have one, we are not going to imply we have one, and no amount of publishing substitutes for it. What it is: enough detail for you to judge the method yourself before you judge us.

Why Theos Quantum

Built on rock, not on sand.

Migration to post-quantum cryptography is inevitable. Doing it blind is optional.

Discovery with evidence

AutoPQC reads the supported source and certificate files. Each finding records the file, line or certificate field, detection rule and method version that produced it.

Published classification

Each asset's post-quantum verdict follows a published, versioned classification table with its sources cited. An unresolved algorithm is reported as unknown.

A clearly labelled roadmap

Mapping, prioritisation and performance evaluation are planned. Their descriptions explain the intended direction; they are not claims about the current release.

A research moat, not a wrapper

Built on ongoing doctoral research and peer-reviewed work in constraint-aware sequencing, calibrated confidence, and governed execution — science that compounds.

Not yet

What we have not done.

This is the section where most vendors put testimonials. We have no customers to quote and we are not going to write ourselves some. Here is the list we would rather you found from us than from a procurement questionnaire.

  • 22 of our 33 controls are Unconfirmed.

    Eight are Implemented, one Partial, one Planned, one Not applicable. The remaining 22 are marked Unconfirmed because we have not verified them to a standard we would defend, and we would rather publish the word Unconfirmed 22 times than round it up to green.

    Read the control list
  • We hold no third-party audit.

    No SOC 2 report, no ISO 27001 certificate, no external penetration-test attestation. Publishing our method in full is not a substitute for one and we are not going to present it as though it were.

  • The attestation example is illustrative.

    The Posture Attestation format on this site is real and the lookup tool works. The example document is labelled illustrative because no real customer attestation exists yet to show you.

    See the format
  • We do not run a paid bug bounty.

    Our safe-harbour commitment is real and we will work with anyone who reports in good faith. We cannot currently pay for findings, so we say so on the disclosure page rather than letting researchers discover it after the work.

    The disclosure policy
  • No public key is published.

    Our security.txt omits the Encryption field entirely. An empty field is honest; a key URL that resolves to nothing is worse than no key at all. It goes in when a real one exists.

  • Our live feeds fall back to a snapshot.

    Exposure Signals and Sector Pulse fetch CISA KEV and GitHub Security Advisories hourly. When a fetch fails we serve a committed set of real historical advisories and label it SNAPSHOT rather than LIVE. If you see that badge, the badge is telling you the truth.

    Check the badge

None of this is an apology and none of it is a roadmap promise. It is the current state, and the current state changes — which is why it is written down in two places that stay current rather than in a paragraph nobody edits again.

Theos Quantum — Building trust for the quantum era.

Theos Quantum. Building trust for the quantum era. Discover, innovate, enable, trust, a safer world.