The breach already
happened. It just hasn't
been read yet.
Adversaries are copying encrypted financial traffic today — UPI, cards, net-banking, Aadhaar-linked records — to open the day a quantum computer breaks RSA. The data leaving an Indian bank this minute outlives the encryption protecting it.
Countdown to a conservative analyst estimate of a cryptographically-relevant quantum computer (~2030). Nobody knows the exact date — which is the point: you cannot wait for the alarm.
No alarm sounds when
the vault is finally opened.
Every public-key handshake under Indian finance runs on RSA and ECDSA — math a quantum computer is built to dissolve. Theft and decryption are separated by years.
This is harvest-now-decrypt-later. The only defence is to migrate before the data leaves — which means knowing, today, exactly what's exposed.
If this holds for you,
you needed to start yesterday.
X + Y > Z ⇒ the window to protect today's data has already closed for any secret that must survive a decade.
How long data must stay secret. Banking records, KYC, contracts: a decade+.
How long a real-estate crypto migration takes: years, not quarters.
Years until RSA breaks. Uncertain — and shrinking.
The category gets defined
in the next 18 months.
The standards landed
NIST finalised ML-KEM & ML-DSA (FIPS 203/204) in Aug 2024. The "let's wait for standards" excuse is gone — migration is now actionable.
The clock compresses
Quantum progress keeps accelerating and HNDL makes the risk present-tense, not 2030's problem. Boards are starting to ask.
India's sovereign moment
DST's National Quantum Mission + data-localisation + RBI/SEBI tightening create real appetite for a sovereign, in-perimeter answer — now.
These rarely line up. When they do, the default is chosen before the rules harden — not after.
No PQC deadline yet.
That is exactly the window.
India's rulebook is tightening toward quantum-safe — on an advisory path, not a statutory one. Whoever builds the record before the mandate defines what compliance looks like.
- ▸RBI IT Governance Master Direction — in force Apr 2024. Strong crypto, VAPT, 6-hour incident reporting. No PQC mandate.
- ▸SEBI Cyber-Security & Resilience Framework — circular 2024/113, effective Aug 2024. Resilience required. No quantum deadline.
- ▸DST · National Quantum Mission — advisory: 2027 foundations → 2029 quantum-safe CII → 2033 enterprise. Calls for CBOM in procurement from FY 2027–28.
When a CISO checks our claim against the actual circular and finds we didn't oversell the law — that's when we earn trust. The CBOM the DST will require in FY27–28 is the exact artifact KavachQ emits today.
Every bank knows quantum is
coming. Almost none can say
which cert dies first.
What crypto do we actually run?
Across thousands of certs, libraries, handshakes, vendors — there is no inventory.
What breaks first, and what falls with it?
One weak cert can sit under a whole internet-facing line of business. Nobody has the graph.
Can we prove our posture to a regulator?
A board slide is not evidence. There is no signed record.
You cannot fix what you cannot see. KavachQ is the telescope nobody has pointed at the bank's own crypto — yet.
Everyone is racing to do the
migration. KavachQ builds the
thing it can't exist without.
The migration / contractor layer
Ripping out RSA and bolting in PQC. Enormous — but services-heavy, fragmented, and it commoditises. Whoever does the swap is forgotten the day it's finished.
The trust / attestation layer
The assessment, the proof, the signed system of record the board and the regulator rely on. It's software, it recurs, it compounds — and in India it must be sovereign, which a global vendor structurally cannot ship.
We don't sell the cure. We're the diagnosis, the prescription, and the signed medical record — for the entire financial system.
The assessor, planner,
and notary — not
the contractor.
KavachQ tells a bank — and the financial system — how exposed it is to quantum, what to fix first, and proves it with post-quantum signatures.
See the exposure
Live TLS probe, cert & config intake → a typed CryptoGraph and a PQC-readiness score, 0–100.
Fix the right things first
A phased migration roadmap mapped to NIST replacements and DST/NQM advisory deadlines.
Make it undeniable
Every finding signed with ML-DSA-65 before storage. Tamper-evident. Verifiable by anyone.
We never touch the migration itself — that stays with the bank's integrators. KavachQ becomes the system of record for post-quantum compliance.
Everything you just read,
we just did. Live.
Not a mockup — a real TLS handshake against a real domain, parsed in real time. Public endpoint: kavachq.in/scan → api.kavachq.in (Fly.io, Mumbai).
A score of 0/100 for an all-RSA, internet-facing bank is not a bug — it's the correct, brutal answer.
Six services. One signed loop.
Intake
Live TLS probe, CSV/cert exports or existing CBOM → normalised inventory, signed at intake.
The CryptoGraph
Apps → certs → algorithms → data classes. 5-pass risk propagation, PQC score, CycloneDX 1.6 CBOM.
The plan
P0/P1/P2 phases → ML-KEM-768 & ML-DSA-65, DST personas, JIRA-exportable tasks.
The notary
ML-DSA-65 (FIPS 204) via liboqs. Canonicalise → sign before persist. No signature, no row.
Grounded regs
BM25 over hash-pinned verbatim clauses. A verifier rejects any number not in the source. Air-gapped.
Systemic view
Composes signed CBOMs across orgs into a sector blast-radius graph. Real engine; consent-based.
Persistence is the spine: one database per customer, path-isolated, append-only audit. It runs inside the bank, not in our cloud.
The global tools stop exactly
where India's problem starts.
SandboxAQ, PQShield, IBM Quantum Safe, InfoSec Global own commodity discovery. None can sit inside an Indian bank's perimeter and cite a SEBI circular.
| Capability | Global PQC tools | KavachQ |
|---|---|---|
| Crypto discovery + CBOM | Yes (generic) | CycloneDX 1.6 + typed graph |
| Maps to Indian clause & deadline | — No | SEBI 2024/113, RBI, DST/NQM |
| Signs the assessment quantum-safely | — No | ML-DSA-65 (FIPS 204) |
| Air-gapped / sovereign deploy | Cloud-first | Inside the perimeter |
| Systemic blast-radius view | — No | QSRG cross-org graph* |
A global incumbent structurally cannot occupy this wedge. Data residency, sovereign algorithms and regulator trust aren't features they can ship. *QSRG engine is real; the multi-org estate in demos is a clearly-labelled fictional fixture.
Start as a scan.
Become an institution.
Indian banks & NBFCs
The system of record for post-quantum compliance in regulated finance.
All Indian regulated CII
Insurers, exchanges, NPCI rails — then telecom, government, health. Same crypto problem, same sovereignty need.
Sovereign PQC, exported
The sovereign attestation layer for other regulated markets that also won't put foreign cloud inside their banks.
The product is a wedge. The mission is the trust infrastructure for post-quantum compliance — wherever sovereignty matters.
Real code. Live endpoint.
No hand-waving.
- No statutory PQC deadline exists today. We align you to advisory roadmaps; we never call advisory "law."
- Multi-org blast-radius runs a real engine over a clearly fictional seeded estate. A live multi-bank scan does not exist yet.
- The AI layer is real but defaults off; a verifier means the model never carries correctness — the source does.
- Stage: working prototype / early pilot. The core loop is real and proven; not yet production-hardened.
Don't take our word.
Scan a domain.
Run a real post-quantum exposure scan, in your browser, in seconds. Watch an all-RSA estate score zero — and understand why that matters.
▸ Try the live scan — kavachq.in/scan