- Articles
- 41
- Sections
- 9
- Read time
- 288 min
Knowledge Base
The whole method, written down
Nothing here is a teaser. Every scoring rule, every discovery boundary, every standard we claim to implement is documented in full — because a security vendor that will not show its work is asking for faith, not a decision.
Start here
What AutoPQC is, what a first engagement looks like, and how to read what comes back.
5 articlesDiscovery
How we find cryptography across an estate — and the boundaries we never cross.
5 articlesRisk & scoring
How exposure becomes a number, what the tiers mean, and why a given asset was flagged.
5 articlesMigration
Sequencing the rollout, proving performance, and keeping the ability to change your mind.
4 articlesStandards & compliance
FIPS 203/204/205, CNSA 2.0, DORA, and the Indian regulatory picture — mapped to output.
5 articlesThe threat
Harvest-now-decrypt-later, the migration window, and the arithmetic behind the deadline.
4 articlesPlatform & access
Roles, single sign-on, automation surfaces, and where alerts land.
6 articlesData & privacy
What we hold, for how long, under whose keys, and who processes it on our behalf.
4 articlesThe Theos Method
The published scoring method, how it is versioned, and the shared vocabulary.
3 articlesStart here
5- What AutoPQC actually doesAutoPQC inventories the cryptography in an enterprise estate, scores its quantum exposure, maps it to NIST standards, and measures the cost of change6 min
- Who this is for, and who it is notAutoPQC suits organisations with a large, mixed, poorly documented cryptographic estate. If that is not you, this page says so before you spend a meeting on it7 min
- What to have ready before we startThe access, scope decisions, documents and people to line up before a Baseline Assessment begins, and the one category of data we ask you never to send6 min
- What the first thirty days look likeA week-by-week account of a Baseline Assessment: scope and access, discovery, scoring review, and the sequencing readout at the end6 min
- How to read your first exposure reportA worked read of a real pilot report — 42 assets, 36 vulnerable, 75/100 — and what each figure does and does not tell you8 min
Discovery
5- How discovery finds cryptographyThe surfaces an estate presents, the difference between passive and authenticated collection, and why we ask for the smallest credential that still yields evidence7 min
- What counts as an assetThe unit behind every number we publish: how one cryptographic asset is defined, how duplicates collapse, and why a count legitimately changes between runs6 min
- The detector catalogueEvery detector we run, what it reads, what it emits, and the confidence it can honestly claim — because a detector reports evidence, not a verdict7 min
- What discovery will not doThe boundaries of a discovery run, stated plainly: no exploitation, no key extraction, no cryptanalysis, and no pretence of reaching systems we cannot reach7 min
- Cryptographic bills of materialWhat a CBOM is, how it relates to an SBOM and CycloneDX-style tooling, and what the artefact is actually good for once you have one7 min
Risk & scoring
5- How the exposure score is builtThe five weighted dimensions, the arithmetic that combines them, and the same arithmetic run over our pilot estate until it produces 758 min
- The inputs, the weights, and where they come fromEvery input to the exposure score, the anchor rubric that turns it into a number, its provenance class, and how the five weights were set8 min
- What the risk tiers meanFour tiers, four score bands with no gaps and no overlaps, and the action each one is expected to trigger7 min
- Why a specific asset was flaggedWhat a finding record contains, the evidence chain from detector output to tier, how to contest a finding, and how an override is recorded7 min
- Accuracy, false positives, and how we report errorThe two metrics we publish, what they do and do not tell you, why accuracy alone is the wrong measure here, and where a human must review8 min
Migration
4- Sequencing a migrationOrder the work by how long your data must stay secret and how much breaks if a change goes wrong, not by how many assets a team owns9 min
- Hybrid modes and keeping your rollbackCombining a classical exchange with ML-KEM is the sane default during transition, provided you design the way back before you need it7 min
- Proving the performance impactMeasure the cost of a cryptographic change on a representative system before you commit to it, then report the comparison honestly7 min
- Designing for crypto-agilityThe goal is not one swap to ML-KEM. It is the ability to change cryptographic algorithms again, cheaply, without another multi-year programme7 min
Standards & compliance
5- FIPS 203, 204 and 205, mapped to outputWhat ML-KEM, ML-DSA and SLH-DSA each specify, where the trade-offs sit, and which piece of AutoPQC output cites which standard8 min
- CNSA 2.0 and the federal timelineWhat the NSA's algorithm suite selects, who it binds, which transition dates are actually published, and why a non-US enterprise ends up answering for it anyway7 min
- DORA and financial-sector obligationsHow the EU Digital Operational Resilience Act reaches cryptography without naming a single post-quantum algorithm, and what an inventory is genuinely good for8 min
- The Indian regulatory pictureWhat the DPDP Act, RBI and CERT-In expectations ask of cryptography, written conservatively, with the parts that were still moving marked as gaps8 min
- What to hand an auditorWhat a reviewer actually asks for, which artefacts answer it, and the difference between an inventory, an attestation and an audit opinion8 min
The threat
4- Harvest now, decrypt laterThe mechanic behind capturing ciphertext today to read it later, why it is rational for a well-resourced adversary, and which data it actually puts at risk8 min
- What a quantum computer actually breaksShor’s algorithm ends RSA, finite-field Diffie–Hellman and elliptic curves; Grover’s algorithm does much less than the headlines suggest7 min
- The migration window, with the arithmeticThe Mosca inequality, defined term by term, with worked examples you can substitute your own numbers into — and no Q-Day date7 min
- Claims we refuse to makeThe assertions we will not put in our marketing, our reports or our sales conversations, with the reason for each and what we say instead7 min
Platform & access
6- Workspaces, teams and projectsThe container model behind AutoPQC: how an organisation, its workspaces and its projects divide an estate, and how findings roll up6 min
- Roles and permissionsFive roles, one matrix, and a clear statement of which actions are irreversible and which are written to the activity log5 min
- Single sign-onSAML 2.0 and OIDC federation for AutoPQC: the claims we require, group-to-role mapping, just-in-time provisioning, and enforcing SSO-only sign-in6 min
- API and automation surfacesContinuum, our programmatic surface — the intended shape, scoped credentials, rate limits, idempotency and signed webhooks, marked honestly as roadmap6 min
- Where alerts landWhat is worth waking someone for, what belongs in a digest, how severity routes to a destination, and why an alert nobody acts on should be deleted6 min
- Integrations, and where we fitWhere AutoPQC sits next to a CMDB, a vulnerability scanner, an SIEM, a certificate lifecycle manager and CI — and what we refuse to duplicate6 min
Data & privacy
4- What we hold, and what we never takeDiscovery records the existence and configuration of cryptography, not the secrets it protects — here is every category we hold, and the lines we do not cross8 min
- Encryption and key handlingHow data is protected in transit and at rest, how tenants are separated, how scoped discovery credentials are held, and where customer-managed keys sit7 min
- Retention and deletionThe full lifecycle from collection to deletion: what we keep per category, why backup expiry differs from deletion, and how a deletion request is confirmed7 min
- Subprocessors and data locationThe categories of third party that process data on our behalf, the diligence before one is added, how you are notified of a change, and where data sits6 min
The Theos Method
3- The Theos Method, in outlineThe eight stages AutoPQC follows to turn an estate into a ranked migration plan, what each stage produces, and where a person decides instead of a model7 min
- How the method is versionedA scoring method that changes silently is useless for comparison over time, so ours is semantically versioned, notice-bound and recorded in an append-only ledger7 min
- Reproducing our numbersWhat each published pilot figure actually measures, the boundary conditions attached to it, and where it stops being transferable to your estate9 min