Developer portal
Core concepts
Post-quantum readiness vocabulary — Assess, Monitor, Convert, and the signed evidence layer your auditors can verify.
Last updated: 2026-06-10
Assess → Monitor → Convert
Assess
Baseline scan, Mosca HNDL scoring, CycloneDX CBOM, signed PDF evidence.
Monitor
Scheduled re-scans, diff alerts, SIEM webhooks, remediation board.
Convert
Prioritized playbooks, workshops, automate remediation, re-scan verification.
HNDL and the Mosca timeline
HNDL
Harvest now, decrypt later (HNDL) means adversaries store ciphertext today to break with future quantum computers. Mosca's inequality — data shelf-life plus migration time must exceed time-to-Q-Day — is why inventory starts before algorithms break.
Cryptographic inventory & CBOM
CBOM
A Cryptography Bill of Materials lists algorithms, keys, and protocols in production. Qtangl exports CycloneDX CBOM from live TLS scans so procurement, GRC, and engineering share one artifact — not a one-time spreadsheet.
Signed evidence & verify
Evidence
Every assessment produces a content hash, ML-DSA-65 signature, and public verify link. Auditors recompute the hash offline — no dashboard login required. Optional transparency log inclusion adds append-only witness co-signing.
Drift & readiness index
Drift
One scan is a snapshot; Monitor compares successive scans and surfaces new RSA, ECC, or weak TLS configurations. The readiness index aggregates exposure, drift velocity, and remediation progress for board and regulator reporting.
Evidence pipeline
- Scan with
POST /pqc/scan— live TLS inventory or fixture mode for demos. - Export CBOM or PDF via
GET /pqc/report/{scan_id}. - Verify signatures at /verify or with the qtangl-verify CLI.
- Optional transparency log inclusion — see the transparency guide.
Method honesty
Readiness terms in product language
Exposure
quantum-vulnerable crypto in production today
Drift
new weak algorithms appearing between scans
Evidence
signed reports auditors can verify independently
Convert
prioritized remediation with proof of fix
Agility
readiness score that moves as standards and stacks change
HNDL
harvest now, decrypt later — Mosca timeline risk
CBOM
Cryptography Bill of Materials — CycloneDX export of algorithms and keys in scope
Verify
Independent signature and content-hash check at /verify or via qtangl-verify CLI
Found an issue? Report documentation feedback