VPQ Audit · Post-quantum readiness assessment

You cannot migrate cryptography you cannot see.

Everyone else is selling a platform to manage the migration. We do the part that has to happen first: read what is actually on the wire, and hand back an inventory you can act on. One capture in, one report out. Nothing is installed anywhere.

HNDL scoring · how the risk is composed
V × S × R × EHNDL risk
“Endpoint uses RSA, therefore HIGH” is not a score.
702
Automated tests passing in the Enterprise build. Counted 08 Sep 2026 by running the suite.
203 / 204 / 205
NIST standards covered — ML-KEM, ML-DSA and SLH-DSA — plus hybrid X25519MLKEM768 and CNSA 2.0.
CycloneDX 1.7
CBOM output, with SARIF for the pipelines that want findings instead of a document.
V × S × R × E
Harvest-now-decrypt-later scoring: vulnerability, data sensitivity, retention period, exposure.
What it reads

Three things
a spreadsheet
cannot tell you.

HNDL Radar

Reads a packet capture, parses the handshakes and scores what an adversary recording today could decrypt later. "Endpoint uses RSA, therefore HIGH" is a crude answer — risk is the vulnerability multiplied by how sensitive the data is, how long you are legally required to keep it, and how exposed the path is.

PKI hierarchy reconstruction

Rebuilds the trust chain from root through intermediates to leaf certificates and ranks the migration impact of each node. Migrating a mid-tier CA while the leaves below it stay classical is the failure nobody plans for, because nobody drew the tree first.

Benchmarks on your hardware

Classical against hybrid against pure post-quantum, measured on the machines you actually run, so the latency and key-size trade-off is a number in your environment rather than a claim in a vendor deck.


Evidence

Half the migration
has not started.

One handshake, forty front doors

On 1 September 2026 we ran a single TLS handshake against 40 public web front doors and read both sides of it. 31 of the 40 negotiated hybrid post-quantum key exchange. None of the 40 presented a post-quantum signature at any position in the chain.

The control group is the argument

Twelve of those hosts were chosen to be as unfavourable to a "they are simply behind" reading as we could make them — organisations whose public identity is built on getting cryptography right, including three projects that maintain the libraries implementers use to run this very measurement. Eight of the twelve had already moved their key exchange. All twelve were still at zero on signatures.

Why the asymmetry

Key exchange you can switch on by yourself. A signature has to be issued to you. At the time of measurement no publicly trusted CA issued certificates carrying post-quantum signatures, so no subscriber could obtain one however much they wanted to. This is why "our TLS already negotiates X25519MLKEM768" reads correct and still leaves half the question open.

The limits, stated here rather than in a footnote

n = 40 hosts across 37 organisations, one point in time, one vantage point. Where the client did not report a group we counted it as not observed, never as declining post-quantum key exchange — the first figure is "31 confirmed", not "9 refused". The host list and the raw per-host output are published rather than available on request, so every number above is recomputable.

Position paper · The 40 hosts, by group · Raw per-host result


For consultancies and auditors

We are the instrument,
you keep the client.

You run the readiness engagement. We produce the on-wire inventory inside it — nothing installed at your client, and the relationship stays yours.

Post-quantum readiness is being written into mandates faster than the tooling layer can staff for it. Advisory firms are winning the engagements and then discovering that the inventory step needs instrumentation nobody on the team owns. That step is what we do, as a subcontracted measurement, delivered under your report.

What stays open, what stays closed

Open, because you have to be able to check it: what we measure — the standards covered, the scoring formula, the output fields, the protocols parsed. Closed, because it is the only thing we cannot hire twice: how the analysis engine is built.


Scope

What this is not.

Not an offensive tool

VPQ Audit is defensive and compliance-oriented — the same category as an SBOM scanner. It reads configuration and traffic you already own. It does not break, harvest or exploit anything.

It does not scan everything

Network, transport, certificates, PKI and source are covered. Endpoint binaries, mainframe, infrastructure-as-code and cloud KMS are not — we would rather name the gap than let you find it halfway through an engagement.

Not certified

We are not TCVN-certified and we do not claim to be. Community edition v0.4.0 is public under MIT; Enterprise is in pilot and pre-production.

Regulatory context, not regulatory advice

The output is built to sit inside work governed by NIST, CNSA 2.0 and, in Vietnam, TCVN 11930, NHNN 09/2020 and Decree 85/2016. Interpreting those for your institution remains your counsel's job.


Start with one capture.

Send a representative capture or point us at one segment. You get the inventory, the HNDL scoring and the CBOM back as a report you can put in front of a client or a regulator — under your name if that is the arrangement.