Skip to content

Customer journey

From first scan to proof of fix

The vulnerability list is the hook. Monitor + evidence is the product. Convert is the high-value sticky tier.

Stage 1Inventory

First scan complete; findings in spreadsheet

Recommended tier: Assess

Explore Assess →
StageNameTierLink
0UnawareContent / free mini-assessOpen
1InventoryAssessOpen
2PrioritizedAssess + workshopOpen
3MonitoredMonitorOpen
4ConvertingConvertOpen
5AgileEnterpriseOpen
6OptimizingOptimize (expansion)Open

Core insight

Never sell Stage 6 to a Stage 0 buyer

Always propose the next maturity stage plus one. Optimization is expansion — only after PQC defense is proven.

Personas

CISO / VP Security

Trigger: Board asks: how much RSA/ECDSA before 2030?

Entry: /assess → Assessment → Monitor

Compliance / GRC lead

Trigger: CMMC, PCI-DSS 4.0, or HIPAA audit

Entry: Scenario packs → signed compliance pack

VP Engineering

Trigger: Assigned to execute PQC migration

Entry: CBOM → remediation board → re-scan verification

Touchpoints by channel

ChannelAssessMonitorConvert
Website/assess/monitor/convert
Self-serve/assess/access/access
DashboardScan historyDrift + schedulesRemediation board