Skip to content

Monitor

Catch crypto drift before auditors do

Your command center for continuous PQC readiness — scheduled re-scans, drift diffs, SIEM alerts, and QBR-ready exports. Board meetings deserve trends, not point-in-time snapshots.

Live preview pulse

Financial services scenario · illustrative

Readiness

61.8

-4.2 vs prior scan

New QV
2
Certs
3
Cadence
Weekly

Continuous drift diff

Scan-to-scan deltas for TLS, certs, host fleet, code, and CBOM — not a one-time snapshot.

Signed QBR exports

Executive digest and board PDF with verify links auditors can check independently.

SIEM-ready webhooks

qtangl-webhook-v2 payloads map to Slack, Teams, Splunk, and your GRC pipeline.

Honest inventory aid

Quantifies quantum-vulnerable exposure and drift — not certification or formal attestation.

Monitor loop

How continuous monitoring works

A five-step loop from scheduled re-scan to board-ready trends — click a step or watch the tour advance.

Five-step loop

Use the arrows, swipe the card, or click a step — each stage shows what Monitor does with illustrative fixture data.

Step 1 of 5: Schedule. Set cadence per target

1 / 5

Step 1 · Schedule

Set cadence per target

  • Weekly or monthly re-scans across your portfolio
  • Quota-aware job queue with next-run visibility
  • Worker + scheduler required on deploy

Live preview · Financial services scenario

Cadence
Weekly
Next run
2026-04-17T09:00:00Z
Read the guide →

Illustrative — configure cadence in your Monitor deployment.

Calendar grid with scan pulses across a domain portfolio.

Platform

Owns cadence and scan targets

SecOps

Triage drift diffs and alerts

GRC

Export QBR trends and evidence

Command center

Your crypto readiness SOC — illustrative preview

Toggle industry scenarios to explore drift trends, multi-source deltas, and business-unit heatmaps. Connect your API key on the dashboard for live tenant data.

Illustrative preview — not your live data. See Dashboard for schedules, alerts, and remediation with your API key.

Scheduler healthyLast scan 2h ago2 unread alertsSimulated — illustrative preview

Readiness

61.8

Delta

-4.2

New Q-vuln

2

Certs ≤30d

3

Cadence

Weekly

Readiness trend + forecast

Drift by source (7d)

Latest scan diff

Two new quantum-vulnerable TLS endpoints and one RSA-2048 certificate downgrade detected since last week's scan.

Readiness delta
-4.2 (66 → 61.8)
New Q-vulnerable
2
Certs expiring ≤30d
3

New quantum-vulnerable assets

  • api-v2.example.com:443 · high
  • staging-jwks.example.com:443 · medium

Degraded algorithms

  • payments.example.com: transitional → quantum_vulnerable

Drift root causes

  • New external endpoint: 2
  • Certificate rotation: 1
  • Cipher suite downgrade: 1

Compared to scan scan_b7

Finding severity

  • Critical: 2
  • High: 5
  • Medium: 8
  • Low: 4

Algorithm exposure

Algorithm families from latest scheduled scan.

  • RSA-204812
  • ECDSA P-2568
  • Ed255193
  • ML-KEM (hybrid)2

Business unit readiness

Evidence freshness

Last signed report
2 days ago
Verify link
Active
Upload retention
24h for PEM uploads
Next scheduled scan
4/17/2026, 9:00:00 AM

Scheduled monitoring

Target
api.example.com
Cadence
Weekly
Next run
4/17/2026, 9:00:00 AM
Alert on
New quantum-vulnerable asset

Live today: Scheduled re-scans + drift diff · Slack + qtangl-webhook-v2 alerts · Executive digest + readiness trends

Drift theater

Scrub weeks, model schedules, route alerts

Walk through scheduled re-scans, estimate quota usage, and preview webhook payloads before you enable Monitor on your estate.

Drift timeline — scrub weekly scans

Use the slider or arrow keys to walk through 8 weeks of scheduled re-scans.

Week 1Week 8 · Score 61.8Week 8

Two new quantum-vulnerable TLS endpoints and one RSA-2048 certificate downgrade detected since last week's scan.

Readiness delta
-4.2 (66 → 61.8)
New Q-vulnerable
2
Certs expiring ≤30d
3

New quantum-vulnerable assets

  • api-v2.example.com:443 · high
  • staging-jwks.example.com:443 · medium

Degraded algorithms

  • payments.example.com: transitional → quantum_vulnerable

Drift root causes

  • New external endpoint: 2
  • Certificate rotation: 1
  • Cipher suite downgrade: 1

Compared to scan scan_b7

Trend through Week 8

  • Feb 2058
  • Feb 2761
  • Mar 664
  • Mar 1366
  • Mar 2063
  • Mar 2765
  • Apr 366
  • Apr 1061.8

Schedule what-if

Estimate scan quota usage before enabling schedules on your tenant.

Cadence

12 targets

Alert rule

Projected usage

48

scans / month

Weekly × 12 targets = 48 scans/mo

Within Monitor quota (100/mo illustrative)

Alert: New quantum-vulnerable asset. Every 168h per target.

Alert preview — Monitor tier

When a scheduled scan completes, Qtangl posts to Slack/Teams webhooks and sends structured qtangl-webhook-v2 payloads for SIEM/GRC ingestion. Webhook docs →

Incoming webhook

Qtangl Monitor

Qtangl: 2 new quantum-vulnerable endpoints since last scan (scan scan_2026_04_08_bank)

highmedium

api.example.com · score 61.8 · verify

Personas

Built for how your team works

Executive digest

Readiness regressed 4.2 pts — two new Q-vulnerable endpoints need owner assignment

Illustrative weekly digest — export real digests from your tenant dashboard.

Since last board review: readiness dropped from 66 → 61.8

Wins

  • Treasury BU held steady at 71
  • Hybrid TLS pilot verified on api.example.com

Risks

  • api-v2.example.com:443 flagged high severity
  • 3 certs expiring within 30 days

Next week

  • Assign owner for api-v2 remediation
  • Review cipher policy on payments LB

Board pack export

QBR-ready PDF with readiness trend, open critical items, framework mapping, and signed verify link — generated from your latest completed scan.

Format
PDF (board layout)
Readiness
61.8
Verify URL
qtangl.com/verify?scanId=…

Illustrative preview — export real board packs from your tenant dashboard.

Peer benchmark (opt-in cohort)

Anonymized industry comparison when benchmark opt-in is enabled on your tenant. Illustrative fixture — not live cohort data.

Your score

61.8

Industry median

58

financial services

p25 – p75

52 – 67

n=847

You are above median for financial services (3.8 pts).

Enterprise proof

Built for board decks and MSSP rollups

Persona views, peer benchmarks, framework deadlines, and remediation velocity — the proof procurement and leadership teams expect.

Remediation velocity

Open vs closed findings over 8 weeks of scheduled monitoring.

Peer benchmark (opt-in cohort)

Anonymized industry comparison when benchmark opt-in is enabled on your tenant. Illustrative fixture — not live cohort data.

Your score

61.8

Industry median

58

financial services

p25 – p75

52 – 67

n=847

You are above median for financial services (3.8 pts).

Standards & frameworks

Track readiness against mandate deadlines

Monitor maps drift findings to NSM-10, CNSA 2.0, NIST IR 8547, and other frameworks — so remediation priorities align with the deadlines your auditors cite.

Control mappings are an inventory aid to accelerate audit preparation — not a formal attestation. We say what we do and do not claim.

FIPS 203 / 204 / 205

Available now (2024)

ML-KEM, ML-DSA, and SLH-DSA standards published — migration can start.

PCI-DSS 4.0

2025–ongoing

Crypto agility and inventory expectations for payment environments.

CMMC 2.0

2026–2030

Defense contractors need crypto inventory evidence for Level 2 audits.

NIST IR 8547

2030

Transition guidance for federal and regulated-adjacent organizations.

CNSA 2.0

2030–2033

NSA suite migration tiers for national-security systems.

NSM-10

2035

Federal mandate to migrate away from quantum-vulnerable algorithms.

How it works

From baseline to QBR-ready trends

  1. Step 1

    Establish baseline

    Run Assess on your domain portfolio — signed PDF and CBOM evidence your auditors can verify.

  2. Step 2

    Schedule re-scans

    Weekly or monthly cadence per target. Worker + scheduler required on deploy.

  3. Step 3

    Detect drift

    Scan-to-scan diffs surface new Q-vulnerable assets, cert expiry, and cipher downgrades.

  4. Step 4

    Export for QBR

    Executive digest, readiness trends, and board PDF exports — metrics leadership expects.

Assess vs Monitor

One-time baseline vs continuous drift

Assess

  • ·Single-session inventory
  • ·Signed baseline evidence
  • ·Framework mapping
Run baseline →

Monitor

  • ·Scheduled re-scans
  • ·Drift diff + alerts
  • ·Trend + QBR exports
Open dashboard →

Compare continuous drift vs point-in-time competitors →

Integrations

Alerts where your team already works

Monitor ROI estimate

Illustrative savings vs manual inventory refresh — adjust inputs for your program.

$46,000 / yr estimated gross savings

Estimate only — see /roi for full model.

Drift API

Programmatic drift for your SOC pipeline

Poll unified drift summaries, scope deltas, and webhook v2 payloads — same data that powers the dashboard command center.

Request

{
  "method": "GET",
  "path": "/tenant/drift/summary?since_days=7",
  "headers": {
    "Authorization": "Bearer qtangl_live_..."
  }
}
Response

{
  "status": "success",
  "sinceDays": 7,
  "scopeCount": 4,
  "totalAdded": 17,
  "totalRemoved": 4,
  "bySource": {
    "external": {
      "scopes": 2,
      "added": 8,
      "removed": 2
    },
    "host": {
      "scopes": 1,
      "added": 3,
      "removed": 0
    },
    "code": {
      "scopes": 1,
      "added": 4,
      "removed": 1
    },
    "cbom": {
      "scopes": 1,
      "added": 2,
      "removed": 1
    }
  },
  "snapshotCount": 45
}
PQC API guide →

Why Monitor

Evidence, drift, and honest scope

Signed evidence

Every report ships with a content hash and signature — auditors verify at /verify without trusting Qtangl alone.

Continuous drift

Monitor diffs each scan against the last baseline so regressions surface before the next audit cycle.

Honest scope

Inventory aid and prioritization — not a formal attestation. We say what we do and do not claim.

Minutes, not months

Live fixture scan in under ten minutes. Compare that to spreadsheet programs that decay on first deploy.

Capabilities

Scheduled readiness (requires worker)

Continuous monitoring means scheduled re-scans via Redis worker + QTANGL_ENABLE_SCHEDULER — configure on deploy; not automatic on every hosting tier.

Black and white before-and-after TLS config bars highlighting a downgrade delta.

Diff alerts

New RSA-2048, deprecated curves, or cipher suite downgrades flagged immediately.

Read the guide →

Black and white kanban board with owner dots and deadline markers.

Remediation board

Prioritized backlog with owner, deadline, and re-scan verification status.

Read the guide →

Black and white checklist grid mapped to tiered compliance deadline rungs.

Standards tracking

NSM-10, CNSA 2.0, and NIST IR 8547 deadline tiers mapped to your inventory.

Read the guide →

Dashboard

One view of readiness over time

Readiness score trends, open findings, and remediation velocity — the metrics your QBR needs.

Monitor FAQ

Assess is a one-time baseline inventory with signed evidence export. Monitor schedules re-scans, detects crypto drift between scans, fires alerts, and tracks readiness trends until you upgrade to Convert for remediation orchestration.

Upgrade from Assess to Monitor

Every assessment should pitch Monitor before delivery. Request a pilot for your domain portfolio.