Convert
Prove the fix with signed evidence
Migration program on top of Monitor — prioritized playbooks, verify-fix loops, and auditor packs in the product. Workshops and partner orchestration via Qtangl services.
Live in dashboard todayReadiness score
61.8
Backlog items
4
Projected delta
+12.4
Velocity
2.3/wk
After verify-fix
74.2
In product today
- Remediation board with owners + target dates
- Verify-fix API across scans
- Jira push + status sync when configured
Services / roadmap
- Executive + engineering workshop cadence
- HSM, PKI, and SI partner introductions
- Self-serve partner portal (roadmap)
Illustrative preview — not your live data. See Dashboard for schedules, alerts, and remediation with your API key.
Live preview — Convert tier
InteractivePrioritized backlog with what-if projection. Toggle items to model readiness lift — full workflow on the tenant dashboard with your API key.
2 of 4 in what-if
Current score
61.8
Projected (what-if)
75.8
+14.0Completion
25%
Velocity
2.3/wk
Select backlog items to simulate projected readiness after remediation. Estimate only — assumes successful re-scan verification.
Remediation board
Click cards to include in projectionIn what-if
2 items· +14 pts
Open
2In progress
1Done
1Program analytics
Peer benchmark
Opt-in cohortYou're 3.8 pts above median for your cohort.
- P25
- 52
- Median
- 58
- You
- 61.8
- P75
- 67
Illustrative financial services cohort (opt-in benchmark)
Live today: Remediation board with owners + target dates · Verify-fix across scans · Live status in PDF/board exports
Evidence
Auditor packs your GRC team can defend
Signed before/after reports, CBOM diffs, and verify links — not slide decks. Verification confirms report integrity and signing — not complete estate coverage.
Readiness after verify-fix (illustrative)
61.8→75.8(target 74.2 after full wave)
Verify-fix loop
Click a step to preview the corresponding evidence artifact.
Loop back to Monitor for continuous drift detection after proof is attached.
Evidence preview — Convert tier
Before/after scan diffs, signed auditor packs, and verify links your GRC team exports after verify-fix.
Hybrid TLS enabled on api.example.com; JWKS rotation in progress. Two high-severity findings resolved since last scan.
- Readiness delta
- +12.4 (61.8 → 74.2)
- New Q-vulnerable
- 0
- Certs expiring ≤30d
- 3
New quantum-vulnerable assets
- api-v2.example.com:443 · high
- staging-jwks.example.com:443 · medium
Degraded algorithms
- payments.example.com: transitional → quantum_vulnerable
Drift root causes
- New external endpoint: 2
- Certificate rotation: 1
- Cipher suite downgrade: 1
Compared to scan scan_b7
Migration path
Reduce HNDL exposure with a phased program — inventory, hybrid pilot, signed proof.
Before
- RSA / ECDH everywhere
- Unknown inventory
- Ciphertext harvestable
Previously harvested ciphertext cannot be un-copied; migration protects new data.
GRC
Export auditor pack
Platform
Hybrid TLS pilot
Security
Verify-fix loop
Illustrative signed report metadata and verify URL for GRC review.
Playbooks ranked by Mosca exposure + mandate deadline
Harvest-now-decrypt-later is a planning problem — not a broken-crypto alarm. Convert connects HNDL urgency to prioritized migration waves without Q-Day prediction.
Loading Mosca calculator…
Data shelf-life by vertical
Typical confidentiality horizon (X in Mosca's inequality) by industry.
| Industry | Typical years | Range |
|---|---|---|
| Healthcare / payers | 35 | 30–50 years |
| Banking / finance | 15 | 7–25 years |
| Government / defense | 25 | 15–50 years |
| SaaS / tech | 3 | 1–7 years |
Standards & frameworks
Mapped to the mandates your auditors cite
Every playbook maps to the mandate driving your audit cycle — ranked by deadline pressure and Mosca exposure.
- Federal mandate2035
NSM-10 compliance guide
National Security Memorandum on post-quantum cryptography
- NSA suite2030–2033
CNSA 2.0 guide
Commercial National Security Algorithm Suite 2.0
- NIST transition2030
NIST IR 8547 primer
Transitioning to post-quantum cryptography standards
- Payments2025–ongoing
PCI-DSS 4.0 crypto agility
Cryptographic agility and key management requirements
- Defense2026–2030
CMMC crypto inventory
Federal contractor cryptographic inventory expectations
- FIPS 203Available 2024
ML-KEM migration guide
Module-Lattice-Based Key-Encapsulation Mechanism standard
- HealthcareRisk analysis ongoing
HIPAA & harvest-now-decrypt-later
HIPAA Security Rule and long data shelf-life
- BankingPCI-DSS 4.0 ongoing
Banking & harvest-now-decrypt-later
Financial data shelf-life and crypto agility
- Defense2035 (NSM-10)
Gov contractor & harvest-now-decrypt-later
CMMC inventory and federal HNDL exposure
- EnterprisePhased enforcement
EU CRA & post-quantum readiness
EU Cyber Resilience Act product security
Control mappings are an inventory aid to accelerate audit preparation — not a formal attestation. We say what we do and do not claim.
What to expect — Convert path
Typical effort bands for quantum-vulnerable findings. Convert adds verify-fix loops, program tracking, and orchestration at scale.
TLS certificate rotation · Days
Coordinate with PKI team; re-scan to verify post-quantum readiness.
JWKS / API signing keys · 1–2 weeks
Inventory dependents, staged rollout, verify-fix on critical endpoints.
HSM / KMS migration · Months
Vendor roadmap alignment; program board tracks waves and owners.
Application-layer crypto · Varies
Prioritize by Mosca HNDL score and exposure in latest scan backlog.
At maturity stage 3 (Monitored), next step is verify-fix on a critical finding → stage 4 Converting. Contact sales for Convert tier orchestration.
How it works
Four steps to proof of fix
Step 1
Prioritize
Rank backlog by exposure, Mosca score, and mandate deadlines.
Step 2
Assign
Owners, target dates, and migration waves on the program board.
Step 3
Re-scan
Verify-fix attaches post-remediation scan proof to each item.
Step 4
Export proof
Auditor packs with signed before/after evidence and verify links.
Who it's for
Built for security, GRC, and engineering leaders
CISO / VP Security
Trigger: Board asks: how much RSA/ECDSA before 2030?
- Program velocity and completion metrics for QBRs
- Peer benchmark context (opt-in on dashboard)
- Board-ready signed evidence exports
Stage 4 — Converting
Active migration sprints; re-scan proof per item
Recommended tier: Convert
Migration waves
- 1. Hybrid TLS on public APIs
- 2. JWKS ML-DSA cutover plan
- 3. Re-scan verification
Checkpoint: Public APIs ≥ transitional band
Program delivery
Convert tier capabilities

Wave-ranked backlog
Prioritized playbooks
Algorithm-specific remediation paths ranked by exposure and deadline pressure.

Services add-on
Workshop cadence
Executive, engineering, and GRC sessions — delivered as a services add-on.

CS-coordinated
Partner introductions
HSM, PKI, and SI partner referrals coordinated by Qtangl CS.

Verify-fix loop
Re-scan verification
Post-remediation scans with signed proof that weak crypto is gone.
Partner orchestration
HSM, PKI, and SI introductions coordinated by Qtangl CS — not a self-serve marketplace yet.
Coordinate PQ-capable HSM evaluations with your existing contracts.
Enterprise
Procurement-ready evidence and honest scope
Why Convert
Evidence, velocity, and honest scope
Verify-fix loop
Attach re-scan proof to each remediation item. Export live workflowStatus in PDF and board packs.
Auditor-ready packs
Signed before/after reports, CBOM diffs, and public verify links — not slide decks.
Deadline-ranked backlog
Playbooks prioritized by Mosca exposure and mandate pressure — NSM-10, CNSA 2.0, NIST IR 8547.
Honest scope
Inventory aid and migration program tracking — not formal attestation or certification.
Product vs services
What's in the dashboard vs what's delivered with Convert engagements
| Capability | In product today | Services / roadmap |
|---|---|---|
| Prioritized playbooks | ✓ | — |
| Verify-fix + re-scan proof | ✓ | — |
| Jira push + status sync | ✓ | — |
| Executive workshop cadence | — | ✓ |
| Partner introductions (HSM, PKI, SI) | — | ✓ |
| Self-serve partner portal | — | Roadmap |
Dogfood — we scan ourselves
Qtangl runs daily live PQC scans of qtangl.com, www.qtangl.com, and api.qtangl.com in CI. Signed reports are publicly verifiable — we hold ourselves to the standard we sell.
Loading latest self-scan…
Developer API
Verify-fix and what-if from your CI pipeline
Simulate projected readiness after remediation, queue verify-fix jobs, and export signed evidence programmatically.
{
"method": "POST",
"path": "/tenant/remediation/what-if",
"body": {
"scanId": "scan_2026_04_08_bank",
"remediationIds": [
"rem_001",
"rem_002"
]
}
}{
"status": "success",
"projection": {
"currentScore": 61.8,
"projectedScore": 74.2,
"delta": 12.4,
"itemsSelected": 2
}
}Convert tier
Q-Day Convert
+$50K–$100K/yr
Migration program on top of Monitor.
- ✓Everything in Monitor
- ✓Prioritized remediation playbooks
- ✓Workshop cadence + partner orchestration
- ✓Re-scan verification + auditor packs
Live today: Remediation board · Verify-fix API · Jira push + status pull

What your InfoSec team asks
Procurement
Compare tiers
Monitor baseline vs Convert program
Monitor
- ·Scheduled re-scans and drift alerts
- ·Remediation board with owners
- ·Webhook v2 for SIEM/GRC
Convert adds
- ·Prioritized playbooks + migration waves
- ·Verify-fix loops with signed proof
- ·Auditor packs and program velocity
Program ROI
Spreadsheet inventory programs decay on first deploy. Convert attaches verify-fix proof to each remediation sprint — compare manual refresh cost vs a continuous migration program.
Estimate savings with the ROI calculator
Open ROI calculator →FAQ
Convert tier questions
Monitor delivers scheduled re-scans, drift alerts, and a remediation board. Convert adds prioritized playbooks, verify-fix loops, program velocity reporting, and auditor packs — plus optional services-led workshops and partner introductions.
Convert tier
Ready to prove the fix?
Convert builds on Monitor. Start with an assessment if you haven't baselined yet — or request a pilot for your migration program.


