Skip to content
Theos Quantum TQ globe markTHEOS QUANTUM

The AutoPQC platform

The Discovery Engine runs today. Mapping, prioritisation and performance evaluation are planned modules, described below as planned.

Five connected disciplines

Readiness, in motion.

A connected view of post-quantum readiness. Explore each area to see how it fits.

READINESS FIELD / 01
Explore the framework
Find the starting point

Identify cryptographic assets across the environment.

This is a readiness framework, not a list of shipping modules. AutoPQC’s Discovery Engine is available today; mapping, prioritisation and performance evaluation are planned.

Explore current capabilities

Module 01

Discovery Engine — available

The Discovery Engine reads Java, Python, C#, Kotlin, Go and JavaScript/TypeScript source and dependency manifests, certificate and key files on disk, and TLS settings written in code. It produces a CycloneDX cryptographic inventory. Every finding carries its evidence, and an algorithm that cannot be resolved is reported as unknown. Live TLS endpoints and wider infrastructure discovery are planned.

TLS configuration parsing: announced (roadmap).

  • Source repositories (Java, Python, C#, Kotlin, Go, JavaScript/TypeScript) and dependency manifests — In development (Q1 2027)
  • Certificate files — In development. PEM and DER certificate files; PKCS#12 and Java key stores are recorded but not opened.
  • TLS settings written in code
  • CycloneDX inventory with finding-level evidence
AST analysisJCA patternsX.509CBOM
Python ASTJava JCAX.509CBOM

Module 02

Migration Mapping Engine — planned

Mapping is planned. The intended capability will match discovered assets to post-quantum successors according to the role they perform, with the relevant standard cited. Key establishment and digital signatures require different choices. The current Discovery Engine does not perform this mapping.

  • Planned: mapping by cryptographic role
  • Planned: key-establishment mapping under FIPS 203
  • Planned: signature mapping under FIPS 204 and 205
  • Planned: a cited standard for each mapping
PlannedKey establishmentDigital signaturesStandards cited
CBOM assetRole classifierNIST catalogPQC target

Module 03

Prioritisation — planned

Prioritisation is planned. The intended capability will order migration work using factors such as reachability, data confidentiality life and published deadlines. Each recommendation is intended to carry its reasoning. We are not presenting the earlier synthetic classifier evaluation as evidence of customer accuracy, or committing this roadmap to a particular model architecture.

  • Planned: migration ordering by risk and urgency
  • Planned: consideration of data confidentiality life
  • Planned: consideration of reachability and published deadlines
  • Planned: reasoning for each recommendation
PlannedRisk and urgencyData confidentiality lifeReasoning per asset
Asset evidencePlanned prioritisationProposed orderReasoning

Module 04

Performance Evaluation — planned

Performance evaluation is planned. The intended capability will compare classical and post-quantum algorithms on customer workloads, including latency and key and signature sizes. It is not part of the current Discovery Engine release. Published algorithm parameters shown elsewhere on this site are not measurements from this planned module.

  • Planned: classical and post-quantum comparison
  • Planned: latency measurement
  • Planned: key and signature size comparison
  • Planned: evaluation on customer workloads
PlannedLatencyKey sizesSignature sizes
Classical baselinePQC candidateBenchmarkReport

Reference algorithm sizes

Published sizes. Performance evaluation is planned.

The chart shows reference key and signature sizes. These are not AutoPQC workload measurements. The planned performance module is not available today.

Key establishment — public key size (bytes)

RSA-2048
256
ML-KEM-768
1,184

Digital signatures — signature size (bytes)

ECDSA-P256
64
FALCON-512
666
ML-DSA-65
3,309
SLH-DSA-128s
7,856

Bars use a square-root scale for readability. AutoPQC benchmarks key-generation and signing latency the same way on your own hardware profile, so the migration cost is measured — not estimated.

What's next — research

Our science moat.

AutoPQC is backed by ongoing doctoral research and peer-reviewed publications. Three directions are moving from the lab into the platform.

R&D 01

Constraint-aware migration sequencing

Planning an estate-wide migration as a constrained optimization problem — respecting dependencies, maintenance windows, and business risk simultaneously.

R&D 02

Calibrated confidence for every recommendation

Statistically trustworthy AI: every recommendation carries a confidence measure you can act on, not just a score.

R&D 03

Governed execution with automatic rollback

Safe, self-correcting deployment — migrations that monitor themselves and reverse automatically when the estate pushes back.

Theos Quantum TQ globe mark

See AutoPQC on your estate.

A demo takes forty-five minutes. The cryptographic inventory it shows you lasts your whole migration.