Live domain scan
TLS handshake inventory with algorithm and key-size classification.
Assess
Scan external-facing TLS, map algorithms to NSM-10 and NIST IR 8547, and export evidence your board can review.
Live in product — run a baseline below or connect your tenant key on Dashboard.
Loading assessment scanner…
How it works
Step 1
Pick scenario
Bank, government CMMC, or healthcare HNDL fixture.
Step 2
Set target
Use scenario domain or authorize a live external scan.
Step 3
Run baseline
External TLS, JWKS, SSH, and email discovery.
Step 4
Export evidence
PDF, CycloneDX CBOM, and public verify link.
What you get
TLS handshake inventory with algorithm and key-size classification.
Harvest-now-decrypt-later exposure scored against your data retention horizon.
Machine-readable crypto bill of materials for your CMDB and GRC tools.
Board-ready summary with an independent verify link.
Scenarios
Pre-loaded targets for banking, government, and healthcare readiness workflows.
Standards & frameworks
Every assessment maps your quantum-vulnerable findings to the frameworks driving your program — NSM-10, CNSA 2.0, NIST IR 8547, PCI-DSS 4.0, and CMMC — with control themes, deadlines, and a signed report your auditors can verify independently.
Sample artifact
Download a sample CycloneDX CBOM from a banking TLS scenario, verify a signed report, or run a live scan above to export your own.
Case study
Dogfood — we scan ourselves
Qtangl is enabling live self-scans of our own domains in production CI. Until live dogfood is configured, verify any scan at /verify or run your own assessment at /assess.
Loading latest self-scan…
FAQ
No account required for the public scanner. Request pilot access for production domains.
PCI-DSS 4.0 crypto agility
Cryptographic agility and key management requirements
Control mappings are an inventory aid to accelerate audit preparation — not a formal attestation. We say what we do and do not claim.