QQShield

QSHIELD

Know exactly where quantum-breakable cryptography lives in your systems — before it becomes an emergency.

QShield discovers, classifies, and prioritizes every quantum-vulnerable use of cryptography across cloud infrastructure, source code, containers, certificates, and more — then turns that inventory into a signed, auditable migration plan.

WHAT IT IS

A cryptography inventory you can trust

Every major algorithm underneath today’s security — RSA, ECDSA, ECDH, Diffie-Hellman, DSA — will be breakable by a sufficiently large quantum computer using Shor’s algorithm. NIST finalized the first post-quantum replacement standards (ML-KEM, ML-DSA) in 2024, and “harvest now, decrypt later” means encrypted data being intercepted today is already exposed once that hardware exists — this isn’t a someday problem for long-lived data.

The hard part isn’t knowing PQC exists. It’s knowing where your own systems use vulnerable cryptography— across cloud accounts, source code, containers, certificates, VPNs, backups, and firmware that were built up over years by different teams. Most organizations don’t have a real answer to that question. QShield is built to produce one, with evidence attached to every claim it makes.

WHAT IT DOES

Discover. Classify. Prioritize. Prove it.

01

Discovers real infrastructure

Cloud accounts (AWS ACM, KMS, S3, RDS, ECR, load balancers, Lambda), live source repositories, container images, certificates, network endpoints, and more — eleven scanner modules, each reading directly from a live target.

02

Classifies deterministically

A single, unit-tested function decides whether an algorithm is quantum-vulnerable, and every scanner and the risk engine call that exact function.

03

Prioritizes with a real score

Findings are risk-scored from algorithm urgency, data longevity, sensitivity, criticality, and exposure, then sequenced into migration waves ordered by what needs attention first.

04

Shows the blast radius

A live dependency graph answers “what breaks if this changes” by traversing the relationships discovered during the assessment.

05

Scores crypto-agility

Eight evidence-grounded dimensions — discoverability, configurability, modularity, observability, vendor readiness, testability, recoverability, governance — each shown with the specific evidence behind its score.

06

Drafts the remediation, never files it

Generates a suggested code annotation, a Jira ticket draft, and a GitHub PR draft for a finding, precisely anchored to the flagged line and left for your team to review.

07

Tests real PQC interoperability

Measures ML-KEM-768 and ML-DSA-65 operations via liboqs against a classical RSA-2048 / ECDH-P256 baseline, with size and speed numbers taken from the run itself.

08

Proves it with a signed report

Every assessment can produce a tamper-evident, Ed25519-signed evidence bundle that anyone can independently verify with a hash-and-signature check.

HOW IT WORKS

Four steps, evidence at every one

  1. 1

    Connect

    Point QShield at an AWS account, a git repository, or a declared target — read-only, on your terms.

  2. 2

    Discover & classify

    Scanner modules run against real targets in parallel; every algorithm found is deterministically classified.

  3. 3

    Prioritize

    Findings are risk-scored and sequenced into a migration roadmap; the dependency graph shows what depends on what.

  4. 4

    Prove it

    Generate a signed evidence report that anyone — an auditor, a regulator, a customer — can independently verify.

SEE IT IN ACTION

Screens from the live product

Every screen below is an unedited capture, not a mockup.

Portfolio dashboard
Portfolio dashboardEvery client and project in one place, each with a live assessment status.
Project overview
Project overviewCoverage, evidence snapshot, quantum-exposure summary, and crypto-agility score for the project's latest assessment.
Cryptographic inventory
Cryptographic inventoryEvery discovered algorithm: purpose, confidence, and quantum-vulnerability status.
Crypto-agility score
Crypto-agility scoreEight dimensions of migration readiness, each with the real evidence behind the number.
Risk-prioritized findings
Risk-prioritized findingsEvery quantum-vulnerable use, ranked by a documented, reproducible risk score.
Generated migration change
Generated migration changeA suggested code annotation, Jira draft, and PR draft, ready for a human to review.
Dependency graph
Dependency graphDiscovered relationships between assets, algorithms, and systems.
Blast-radius view
Blast-radius view“What breaks if this changes?” — traced from a live graph traversal.
Migration roadmap
Migration roadmapOpen findings automatically sequenced into prioritized migration waves.
PQC interoperability lab
PQC interoperability labML-KEM-768 / ML-DSA-65 measurements against a classical RSA-2048 / ECDH-P256 baseline.
Live discovery in progress
Live discovery in progressQuerying ACM, KMS, S3, RDS, ECR, ELBv2, and Lambda in real time during an assessment.
Signed evidence report
Signed evidence reportA tamper-evident, Ed25519-signed bundle, independently verifiable after generation.

FOR YOUR TECHNICAL TEAM

Everything above, in engineering detail

Expand any section below. Nothing here contradicts the summary above — it’s the same platform, described precisely.

FAQ

Common questions