Quantum Readiness
You can't migrate what you can't see. Vigil discovers the cryptography across your estate — agentless — classifies every algorithm as quantum-safe, hybrid, or vulnerable, and hands you a prioritized post-quantum migration roadmap. A cryptographic inventory is the first step every regulator now asks for, and Vigil produces it in minutes.
Agentless discovery — no scanners to install
- External TLS sweep of your public endpoints — Vigil probes what your servers actually negotiate, including PQ-hybrid key exchange
- Certificate Transparency auto-discovery finds the subdomains and certificates you forgot you had, so nothing external goes unscanned
- AWS inventory — read-only ACM & KMS crypto material, no keys ever leave your account
- On-prem collector — a lightweight, read-only Node script for internal hosts that never touch the public internet
- CycloneDX import — already have a CBOM from another tool? Ingest it and Vigil normalizes and scores it alongside everything else
What you get
- A quantum-readiness grade (0–100) with a per-asset breakdown across your discovered cryptography
- A Cryptography Bill of Materials (CBOM) — every algorithm, key size, certificate and expiry, in one inventory
- Harvest-now-decrypt-later (HNDL) prioritization — the data an adversary can steal today and decrypt after Q-Day is ranked first
- An AI-generated migration roadmap phased Immediate → Short-term → Strategic, so you know what to fix and in what order
- Findings mapped to NIST FIPS 203–205, CNSA 2.0, OMB M-23-02 and PCI DSS 4.0 — audit- and board-ready
- CycloneDX 1.6 export — your CBOM in the open standard, portable to any downstream tool or auditor
Why now — the clock is already running
NIST finalized the first post-quantum standards (FIPS 203, 204, 205) in 2024, and the mandates are converging: the NSA's CNSA 2.0 timeline expects quantum-resistant algorithms across national-security systems, the EU has told member states to have national PQC strategies underway, and federal guidance points at a 2030–2035 migration window. The catch is harvest-now-decrypt-later: encrypted data exfiltrated today can be stored and broken once a quantum computer arrives — so anything with a long confidentiality lifetime is already exposed. Every credible migration starts with the same first step Vigil automates: a cryptographic inventory. Buying a “quantum-safe” product before you have one is buying blind.
Found something? We can close it.
Discovery is the easy half. Closing a quantum-vulnerable endpoint means enabling hybrid key exchange wherever TLS terminates — and if your platform terminates TLS for you (Fly, Vercel, Render, Heroku), that isn't a setting you have. Paliton Networks is a Cloudflare MSSP partner. We can scope and implement the mitigation across your estate, then re-scan so you hold dated, verified evidence the harvest-now-decrypt-later window is closed — not a promise that it is. Read the mitigation guide →
Related: Posture Assessments · Pricing · Security & Trust