Loading…
Loading…
How we do the work: inventory, sequencing, migration and credential practice, written so it generalises beyond us.
7 articles
Most post-quantum material is one of two things: a vendor pitch that tells you to panic, or a standard that assumes you already have a doctorate. We built the part in between and put it online for free. The quantakrypto knowledge base is 11 collections, 49 topics, an 85-term glossary, and straight answers, with reading paths for employees, IT, and leadership.
Every post-quantum migration plan starts with the same step, and almost everyone underestimates it: know exactly what cryptography you have. A cryptographic bill of materials (CBOM) is that inventory in a standard, machine-readable form. Here is how to produce one across your code and your infrastructure in about a minute, with qScan, and what to do with it once you have it.
A machine can already ask a site what to crawl (robots.txt) and who to email about a bug (security.txt). It cannot ask what cryptography the site runs or how far along its post-quantum migration is. We are proposing a small well-known file that answers exactly that, and shipping the emitter in qScan. It is a proposal, not a ratified standard.
Point-in-time certificates go stale the day after issuance, and buyers know it. Our attestation keeps the issuance proof but adds a machine that re-verifies the posture against live scans on a schedule; the public status degrades to re-verifying and then lapsed if the evidence drifts, and recovers on its own.
AI coding agents are fluent in cryptography and blind to its expiry date. The quantakrypto MCP gives them the missing sense. Here is the workflow we actually use: what to delegate to the agent, and where a human still decides.
Credential theft is the front door to most breaches, and the fix is not a sterner lecture about passwords. It is a system: modern policy grounded in NIST 800-63B, the tooling that makes the policy real, and scanning that catches secrets in code before they ship.
“Add post-quantum” is not a single switch. The first deliverable of a serious migration is a cryptographic inventory: every place asymmetric cryptography is used, and what depends on it. Here is how national cyber agencies build one, and why it is the hard part.
Book a discovery call and get an indicative scope and pricing for your organisation.