VPQ Audit · Free Check

Is your TLS ready for post-quantum?

Enter up to 5 hostnames. We read each one's TLS handshake on port 443 — key exchange, protocol versions, certificate chain — and grade it A–F against what harvest-now-decrypt-later can attack today.

How we grade

A
Post-quantum key exchange and no classical weakness. Certificates are a planning item: no public CA issues post-quantum web certificates yet (deadline 2030–2035, NIST IR 8547 draft).
B
Post-quantum key exchange, but the configuration has a classical weakness to fix.
C
Classical key exchange: traffic recorded today can be decrypted once a quantum computer exists (harvest-now-decrypt-later). Enable hybrid X25519MLKEM768.
D
Classical key exchange (harvest-now-decrypt-later exposure) and a classical weakness in the configuration.
F
Broken even without a quantum computer: fix this first.