Everyone else is selling a platform to manage the migration. We do the part that has to happen first: read what is actually on the wire, and hand back an inventory you can act on. One capture in, one report out. Nothing is installed anywhere.
Reads a packet capture, parses the handshakes and scores what an adversary recording today could decrypt later. "Endpoint uses RSA, therefore HIGH" is a crude answer — risk is the vulnerability multiplied by how sensitive the data is, how long you are legally required to keep it, and how exposed the path is.
Rebuilds the trust chain from root through intermediates to leaf certificates and ranks the migration impact of each node. Migrating a mid-tier CA while the leaves below it stay classical is the failure nobody plans for, because nobody drew the tree first.
Classical against hybrid against pure post-quantum, measured on the machines you actually run, so the latency and key-size trade-off is a number in your environment rather than a claim in a vendor deck.
On 1 September 2026 we ran a single TLS handshake against 40 public web front doors and read both sides of it. 31 of the 40 negotiated hybrid post-quantum key exchange. None of the 40 presented a post-quantum signature at any position in the chain.
Twelve of those hosts were chosen to be as unfavourable to a "they are simply behind" reading as we could make them — organisations whose public identity is built on getting cryptography right, including three projects that maintain the libraries implementers use to run this very measurement. Eight of the twelve had already moved their key exchange. All twelve were still at zero on signatures.
Key exchange you can switch on by yourself. A signature has to be issued to you. At the time of measurement no publicly trusted CA issued certificates carrying post-quantum signatures, so no subscriber could obtain one however much they wanted to. This is why "our TLS already negotiates X25519MLKEM768" reads correct and still leaves half the question open.
n = 40 hosts across 37 organisations, one point in time, one vantage point. Where the client did not report a group we counted it as not observed, never as declining post-quantum key exchange — the first figure is "31 confirmed", not "9 refused". The host list and the raw per-host output are published rather than available on request, so every number above is recomputable.
Position paper · The 40 hosts, by group · Raw per-host result
You run the readiness engagement. We produce the on-wire inventory inside it — nothing installed at your client, and the relationship stays yours.
Post-quantum readiness is being written into mandates faster than the tooling layer can staff for it. Advisory firms are winning the engagements and then discovering that the inventory step needs instrumentation nobody on the team owns. That step is what we do, as a subcontracted measurement, delivered under your report.
Open, because you have to be able to check it: what we measure — the standards covered, the scoring formula, the output fields, the protocols parsed. Closed, because it is the only thing we cannot hire twice: how the analysis engine is built.
VPQ Audit is defensive and compliance-oriented — the same category as an SBOM scanner. It reads configuration and traffic you already own. It does not break, harvest or exploit anything.
Network, transport, certificates, PKI and source are covered. Endpoint binaries, mainframe, infrastructure-as-code and cloud KMS are not — we would rather name the gap than let you find it halfway through an engagement.
We are not TCVN-certified and we do not claim to be. Community edition v0.4.0 is public under MIT; Enterprise is in pilot and pre-production.
The output is built to sit inside work governed by NIST, CNSA 2.0 and, in Vietnam, TCVN 11930, NHNN 09/2020 and Decree 85/2016. Interpreting those for your institution remains your counsel's job.
Send a representative capture or point us at one segment. You get the inventory, the HNDL scoring and the CBOM back as a report you can put in front of a client or a regulator — under your name if that is the arrangement.