Sign InStart Free Trial

Quantum Readiness

You can't migrate what you can't see. Vigil discovers the cryptography across your estate — agentless — classifies every algorithm as quantum-safe, hybrid, or vulnerable, and hands you a prioritized post-quantum migration roadmap. A cryptographic inventory is the first step every regulator now asks for, and Vigil produces it in minutes.

How Vigil classifies every key & certificate
VulnerableClassical RSA / ECDSA / ECDH / DH — breakable by Shor's algorithm on a cryptographically-relevant quantum computer
HybridA classical group combined with a PQC group (e.g. X25519MLKEM768) — transitional, forward-secure today
Quantum-safeA NIST PQC algorithm — ML-KEM, ML-DSA, SLH-DSA (FIPS 203 / 204 / 205)
UnknownPosture can't be determined from the algorithm name — flagged for review

Agentless discovery — no scanners to install

  • External TLS sweep of your public endpoints — Vigil probes what your servers actually negotiate, including PQ-hybrid key exchange
  • Certificate Transparency auto-discovery finds the subdomains and certificates you forgot you had, so nothing external goes unscanned
  • AWS inventory — read-only ACM & KMS crypto material, no keys ever leave your account
  • On-prem collector — a lightweight, read-only Node script for internal hosts that never touch the public internet
  • CycloneDX import — already have a CBOM from another tool? Ingest it and Vigil normalizes and scores it alongside everything else

What you get

  • A quantum-readiness grade (0–100) with a per-asset breakdown across your discovered cryptography
  • A Cryptography Bill of Materials (CBOM) — every algorithm, key size, certificate and expiry, in one inventory
  • Harvest-now-decrypt-later (HNDL) prioritization — the data an adversary can steal today and decrypt after Q-Day is ranked first
  • An AI-generated migration roadmap phased Immediate → Short-term → Strategic, so you know what to fix and in what order
  • Findings mapped to NIST FIPS 203–205, CNSA 2.0, OMB M-23-02 and PCI DSS 4.0 — audit- and board-ready
  • CycloneDX 1.6 export — your CBOM in the open standard, portable to any downstream tool or auditor

Why now — the clock is already running

NIST finalized the first post-quantum standards (FIPS 203, 204, 205) in 2024, and the mandates are converging: the NSA's CNSA 2.0 timeline expects quantum-resistant algorithms across national-security systems, the EU has told member states to have national PQC strategies underway, and federal guidance points at a 2030–2035 migration window. The catch is harvest-now-decrypt-later: encrypted data exfiltrated today can be stored and broken once a quantum computer arrives — so anything with a long confidentiality lifetime is already exposed. Every credible migration starts with the same first step Vigil automates: a cryptographic inventory. Buying a “quantum-safe” product before you have one is buying blind.

Found something? We can close it.

Discovery is the easy half. Closing a quantum-vulnerable endpoint means enabling hybrid key exchange wherever TLS terminates — and if your platform terminates TLS for you (Fly, Vercel, Render, Heroku), that isn't a setting you have. Paliton Networks is a Cloudflare MSSP partner. We can scope and implement the mitigation across your estate, then re-scan so you hold dated, verified evidence the harvest-now-decrypt-later window is closed — not a promise that it is. Read the mitigation guide →

See your cryptographic exposure
Start a free trial and run your first sweep in minutes — or talk to us about a guided cryptographic inventory.

Related: Posture Assessments · Pricing · Security & Trust