Skip to content
Methodology

Methodology

How we do the work: inventory, sequencing, migration and credential practice, written so it generalises beyond us.

7 articles

Methodology

A field guide to post-quantum readiness, free and in the open

Most post-quantum material is one of two things: a vendor pitch that tells you to panic, or a standard that assumes you already have a doctorate. We built the part in between and put it online for free. The quantakrypto knowledge base is 11 collections, 49 topics, an 85-term glossary, and straight answers, with reading paths for employees, IT, and leadership.

3 min read
Methodology

You cannot migrate what you cannot see: build a CBOM with qScan

Every post-quantum migration plan starts with the same step, and almost everyone underestimates it: know exactly what cryptography you have. A cryptographic bill of materials (CBOM) is that inventory in a standard, machine-readable form. Here is how to produce one across your code and your infrastructure in about a minute, with qScan, and what to do with it once you have it.

3 min read
Methodology

A well-known URI for cryptographic posture: the crypto-agility manifest

A machine can already ask a site what to crawl (robots.txt) and who to email about a bug (security.txt). It cannot ask what cryptography the site runs or how far along its post-quantum migration is. We are proposing a small well-known file that answers exactly that, and shipping the emitter in qScan. It is a proposal, not a ratified standard.

4 min read
Methodology

A post-quantum readiness credential a machine keeps checking

Point-in-time certificates go stale the day after issuance, and buyers know it. Our attestation keeps the issuance proof but adds a machine that re-verifies the posture against live scans on a schedule; the public status degrades to re-verifying and then lapsed if the evidence drifts, and recovers on its own.

3 min read
Methodology

A post-quantum workflow for AI coding agents

AI coding agents are fluent in cryptography and blind to its expiry date. The quantakrypto MCP gives them the missing sense. Here is the workflow we actually use: what to delegate to the agent, and where a human still decides.

3 min read
Methodology

Passwords are an organizational problem: why policy and tooling beat "pick a better password"

Credential theft is the front door to most breaches, and the fix is not a sterner lecture about passwords. It is a system: modern policy grounded in NIST 800-63B, the tooling that makes the policy real, and scanning that catches secrets in code before they ship.

8 min read
Methodology

The crypto inventory: finding every place asymmetric crypto hides

“Add post-quantum” is not a single switch. The first deliverable of a serious migration is a cryptographic inventory: every place asymmetric cryptography is used, and what depends on it. Here is how national cyber agencies build one, and why it is the hard part.

5 min read
Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.