Monitor
Catch crypto drift before auditors do
Your command center for continuous PQC readiness — scheduled re-scans, drift diffs, SIEM alerts, and QBR-ready exports. Board meetings deserve trends, not point-in-time snapshots.
Live preview pulse
Financial services scenario · illustrative
Readiness
61.8
-4.2 vs prior scan
- New QV
- 2
- Certs
- 3
- Cadence
- Weekly
Assess → Monitor → Convert
You are on Monitor — continuous drift after your baseline.
Continuous drift diff
Scan-to-scan deltas for TLS, certs, host fleet, code, and CBOM — not a one-time snapshot.
Signed QBR exports
Executive digest and board PDF with verify links auditors can check independently.
SIEM-ready webhooks
qtangl-webhook-v2 payloads map to Slack, Teams, Splunk, and your GRC pipeline.
Honest inventory aid
Quantifies quantum-vulnerable exposure and drift — not certification or formal attestation.
Monitor loop
How continuous monitoring works
A five-step loop from scheduled re-scan to board-ready trends — click a step or watch the tour advance.
Five-step loop
Use the arrows, swipe the card, or click a step — each stage shows what Monitor does with illustrative fixture data.
Step 1 of 5: Schedule. Set cadence per target
1 / 5
Step 1 · Schedule
Set cadence per target
- Weekly or monthly re-scans across your portfolio
- Quota-aware job queue with next-run visibility
- Worker + scheduler required on deploy
Live preview · Financial services scenario
- Cadence
- Weekly
- Next run
- 2026-04-17T09:00:00Z
Illustrative — configure cadence in your Monitor deployment.

Platform
Owns cadence and scan targets
SecOps
Triage drift diffs and alerts
GRC
Export QBR trends and evidence
Command center
Your crypto readiness SOC — illustrative preview
Toggle industry scenarios to explore drift trends, multi-source deltas, and business-unit heatmaps. Connect your API key on the dashboard for live tenant data.
Illustrative preview — not your live data. See Dashboard for schedules, alerts, and remediation with your API key.
Readiness
61.8
Delta
-4.2
New Q-vuln
2
Certs ≤30d
3
Cadence
Weekly
Readiness trend + forecast
Drift by source (7d)
Latest scan diff
Two new quantum-vulnerable TLS endpoints and one RSA-2048 certificate downgrade detected since last week's scan.
- Readiness delta
- -4.2 (66 → 61.8)
- New Q-vulnerable
- 2
- Certs expiring ≤30d
- 3
New quantum-vulnerable assets
- api-v2.example.com:443 · high
- staging-jwks.example.com:443 · medium
Degraded algorithms
- payments.example.com: transitional → quantum_vulnerable
Drift root causes
- New external endpoint: 2
- Certificate rotation: 1
- Cipher suite downgrade: 1
Compared to scan scan_b7
Finding severity
- Critical: 2
- High: 5
- Medium: 8
- Low: 4
Algorithm exposure
Algorithm families from latest scheduled scan.
- RSA-204812
- ECDSA P-2568
- Ed255193
- ML-KEM (hybrid)2
Business unit readiness
Evidence freshness
- Last signed report
- 2 days ago
- Verify link
- Active
- Upload retention
- 24h for PEM uploads
- Next scheduled scan
- 4/17/2026, 9:00:00 AM
Scheduled monitoring
- Target
- api.example.com
- Cadence
- Weekly
- Next run
- 4/17/2026, 9:00:00 AM
- Alert on
- New quantum-vulnerable asset
Live today: Scheduled re-scans + drift diff · Slack + qtangl-webhook-v2 alerts · Executive digest + readiness trends
Drift theater
Scrub weeks, model schedules, route alerts
Walk through scheduled re-scans, estimate quota usage, and preview webhook payloads before you enable Monitor on your estate.
Drift timeline — scrub weekly scans
Use the slider or arrow keys to walk through 8 weeks of scheduled re-scans.
Two new quantum-vulnerable TLS endpoints and one RSA-2048 certificate downgrade detected since last week's scan.
- Readiness delta
- -4.2 (66 → 61.8)
- New Q-vulnerable
- 2
- Certs expiring ≤30d
- 3
New quantum-vulnerable assets
- api-v2.example.com:443 · high
- staging-jwks.example.com:443 · medium
Degraded algorithms
- payments.example.com: transitional → quantum_vulnerable
Drift root causes
- New external endpoint: 2
- Certificate rotation: 1
- Cipher suite downgrade: 1
Compared to scan scan_b7
Trend through Week 8
- Feb 2058
- Feb 2761
- Mar 664
- Mar 1366
- Mar 2063
- Mar 2765
- Apr 366
- Apr 1061.8
Schedule what-if
Estimate scan quota usage before enabling schedules on your tenant.
Cadence
12 targets
Alert rule
Projected usage
48
scans / month
Weekly × 12 targets = 48 scans/mo
Within Monitor quota (100/mo illustrative)
Alert: New quantum-vulnerable asset. Every 168h per target.
Alert preview — Monitor tier
When a scheduled scan completes, Qtangl posts to Slack/Teams webhooks and sends structured qtangl-webhook-v2 payloads for SIEM/GRC ingestion. Webhook docs →
Incoming webhook
Qtangl Monitor
Qtangl: 2 new quantum-vulnerable endpoints since last scan (scan scan_2026_04_08_bank)
api.example.com · score 61.8 · verify
Personas
Built for how your team works
Executive digest
Readiness regressed 4.2 pts — two new Q-vulnerable endpoints need owner assignment
Illustrative weekly digest — export real digests from your tenant dashboard.
Since last board review: readiness dropped from 66 → 61.8
Wins
- Treasury BU held steady at 71
- Hybrid TLS pilot verified on api.example.com
Risks
- api-v2.example.com:443 flagged high severity
- 3 certs expiring within 30 days
Next week
- Assign owner for api-v2 remediation
- Review cipher policy on payments LB
Board pack export
QBR-ready PDF with readiness trend, open critical items, framework mapping, and signed verify link — generated from your latest completed scan.
- Format
- PDF (board layout)
- Readiness
- 61.8
- Verify URL
- qtangl.com/verify?scanId=…
Illustrative preview — export real board packs from your tenant dashboard.
Peer benchmark (opt-in cohort)
Anonymized industry comparison when benchmark opt-in is enabled on your tenant. Illustrative fixture — not live cohort data.
Your score
61.8
Industry median
58
financial services
p25 – p75
52 – 67
n=847
You are above median for financial services (3.8 pts).
Enterprise proof
Built for board decks and MSSP rollups
Persona views, peer benchmarks, framework deadlines, and remediation velocity — the proof procurement and leadership teams expect.
Remediation velocity
Open vs closed findings over 8 weeks of scheduled monitoring.
Peer benchmark (opt-in cohort)
Anonymized industry comparison when benchmark opt-in is enabled on your tenant. Illustrative fixture — not live cohort data.
Your score
61.8
Industry median
58
financial services
p25 – p75
52 – 67
n=847
You are above median for financial services (3.8 pts).
Standards & frameworks
Track readiness against mandate deadlines
Monitor maps drift findings to NSM-10, CNSA 2.0, NIST IR 8547, and other frameworks — so remediation priorities align with the deadlines your auditors cite.
- Federal mandate2035
NSM-10 compliance guide
National Security Memorandum on post-quantum cryptography
- NSA suite2030–2033
CNSA 2.0 guide
Commercial National Security Algorithm Suite 2.0
- NIST transition2030
NIST IR 8547 primer
Transitioning to post-quantum cryptography standards
- Payments2025–ongoing
PCI-DSS 4.0 crypto agility
Cryptographic agility and key management requirements
- Defense2026–2030
CMMC crypto inventory
Federal contractor cryptographic inventory expectations
- FIPS 203Available 2024
ML-KEM migration guide
Module-Lattice-Based Key-Encapsulation Mechanism standard
- HealthcareRisk analysis ongoing
HIPAA & harvest-now-decrypt-later
HIPAA Security Rule and long data shelf-life
- BankingPCI-DSS 4.0 ongoing
Banking & harvest-now-decrypt-later
Financial data shelf-life and crypto agility
- Defense2035 (NSM-10)
Gov contractor & harvest-now-decrypt-later
CMMC inventory and federal HNDL exposure
- EnterprisePhased enforcement
EU CRA & post-quantum readiness
EU Cyber Resilience Act product security
Control mappings are an inventory aid to accelerate audit preparation — not a formal attestation. We say what we do and do not claim.
FIPS 203 / 204 / 205
Available now (2024)
ML-KEM, ML-DSA, and SLH-DSA standards published — migration can start.
PCI-DSS 4.0
2025–ongoing
Crypto agility and inventory expectations for payment environments.
CMMC 2.0
2026–2030
Defense contractors need crypto inventory evidence for Level 2 audits.
NIST IR 8547
2030
Transition guidance for federal and regulated-adjacent organizations.
CNSA 2.0
2030–2033
NSA suite migration tiers for national-security systems.
NSM-10
2035
Federal mandate to migrate away from quantum-vulnerable algorithms.
How it works
From baseline to QBR-ready trends
Step 1
Establish baseline
Run Assess on your domain portfolio — signed PDF and CBOM evidence your auditors can verify.
Step 2
Schedule re-scans
Weekly or monthly cadence per target. Worker + scheduler required on deploy.
Step 3
Detect drift
Scan-to-scan diffs surface new Q-vulnerable assets, cert expiry, and cipher downgrades.
Step 4
Export for QBR
Executive digest, readiness trends, and board PDF exports — metrics leadership expects.
Assess vs Monitor
One-time baseline vs continuous drift
Integrations
Alerts where your team already works
Monitor ROI estimate
Illustrative savings vs manual inventory refresh — adjust inputs for your program.
$46,000 / yr estimated gross savings
Estimate only — see /roi for full model.
Drift API
Programmatic drift for your SOC pipeline
Poll unified drift summaries, scope deltas, and webhook v2 payloads — same data that powers the dashboard command center.
{
"method": "GET",
"path": "/tenant/drift/summary?since_days=7",
"headers": {
"Authorization": "Bearer qtangl_live_..."
}
}{
"status": "success",
"sinceDays": 7,
"scopeCount": 4,
"totalAdded": 17,
"totalRemoved": 4,
"bySource": {
"external": {
"scopes": 2,
"added": 8,
"removed": 2
},
"host": {
"scopes": 1,
"added": 3,
"removed": 0
},
"code": {
"scopes": 1,
"added": 4,
"removed": 1
},
"cbom": {
"scopes": 1,
"added": 2,
"removed": 1
}
},
"snapshotCount": 45
}Why Monitor
Evidence, drift, and honest scope
Signed evidence
Every report ships with a content hash and signature — auditors verify at /verify without trusting Qtangl alone.
Continuous drift
Monitor diffs each scan against the last baseline so regressions surface before the next audit cycle.
Honest scope
Inventory aid and prioritization — not a formal attestation. We say what we do and do not claim.
Minutes, not months
Live fixture scan in under ten minutes. Compare that to spreadsheet programs that decay on first deploy.
Capabilities
Scheduled readiness (requires worker)
Continuous monitoring means scheduled re-scans via Redis worker + QTANGL_ENABLE_SCHEDULER — configure on deploy; not automatic on every hosting tier.

Diff alerts
New RSA-2048, deprecated curves, or cipher suite downgrades flagged immediately.

Remediation board
Prioritized backlog with owner, deadline, and re-scan verification status.
Standards tracking
NSM-10, CNSA 2.0, and NIST IR 8547 deadline tiers mapped to your inventory.
Dashboard
One view of readiness over time
Readiness score trends, open findings, and remediation velocity — the metrics your QBR needs.
Monitor FAQ
Assess is a one-time baseline inventory with signed evidence export. Monitor schedules re-scans, detects crypto drift between scans, fires alerts, and tracks readiness trends until you upgrade to Convert for remediation orchestration.
Upgrade from Assess to Monitor
Every assessment should pitch Monitor before delivery. Request a pilot for your domain portfolio.


