KavachQ
Post-quantum compliance · Indian regulated finance
Harvest now · Decrypt later

The breach already
happened. It just hasn't
been read yet.

Years
:
Days
:
Hours
:
Min
:
Sec

Adversaries are copying encrypted financial traffic today — UPI, cards, net-banking, Aadhaar-linked records — to open the day a quantum computer breaks RSA. The data leaving an Indian bank this minute outlives the encryption protecting it.

Countdown to a conservative analyst estimate of a cryptographically-relevant quantum computer (~2030). Nobody knows the exact date — which is the point: you cannot wait for the alarm.

The quiet heist

No alarm sounds when
the vault is finally opened.

Every public-key handshake under Indian finance runs on RSA and ECDSA — math a quantum computer is built to dissolve. Theft and decryption are separated by years.

2026
Encrypted traffic & long-lived secrets are copied and warehoused. Invisible. No breach notice fires.
…wait…
The data sits. PII, keys, contracts — still valuable a decade later.
~2030
A quantum computer arrives. The 2026 archive is decrypted retroactively. The breach was always now.

This is harvest-now-decrypt-later. The only defence is to migrate before the data leaves — which means knowing, today, exactly what's exposed.

The math of being late · Mosca's inequality

If this holds for you,
you needed to start yesterday.

7y
Secrecy needed (X)
+
5y
Migration time (Y)
>
~4y
Until Q-Day (Z)

X + Y > Z  ⇒  the window to protect today's data has already closed for any secret that must survive a decade.

X

How long data must stay secret. Banking records, KYC, contracts: a decade+.

Y

How long a real-estate crypto migration takes: years, not quarters.

Z

Years until RSA breaks. Uncertain — and shrinking.

Why now — three forces converging

The category gets defined
in the next 18 months.

Force 01

The standards landed

NIST finalised ML-KEM & ML-DSA (FIPS 203/204) in Aug 2024. The "let's wait for standards" excuse is gone — migration is now actionable.

Force 02

The clock compresses

Quantum progress keeps accelerating and HNDL makes the risk present-tense, not 2030's problem. Boards are starting to ask.

Force 03

India's sovereign moment

DST's National Quantum Mission + data-localisation + RBI/SEBI tightening create real appetite for a sovereign, in-perimeter answer — now.

These rarely line up. When they do, the default is chosen before the rules harden — not after.

The regulators are already moving

No PQC deadline yet.
That is exactly the window.

India's rulebook is tightening toward quantum-safe — on an advisory path, not a statutory one. Whoever builds the record before the mandate defines what compliance looks like.

  • RBI IT Governance Master Direction — in force Apr 2024. Strong crypto, VAPT, 6-hour incident reporting. No PQC mandate.
  • SEBI Cyber-Security & Resilience Framework — circular 2024/113, effective Aug 2024. Resilience required. No quantum deadline.
  • DST · National Quantum Mission — advisory: 2027 foundations → 2029 quantum-safe CII → 2033 enterprise. Calls for CBOM in procurement from FY 2027–28.
We say this out loud — on purpose

When a CISO checks our claim against the actual circular and finds we didn't oversell the law — that's when we earn trust. The CBOM the DST will require in FY27–28 is the exact artifact KavachQ emits today.

The question nobody can answer

Every bank knows quantum is
coming. Almost none can say
which cert dies first.

Q1

What crypto do we actually run?

Across thousands of certs, libraries, handshakes, vendors — there is no inventory.

Q2

What breaks first, and what falls with it?

One weak cert can sit under a whole internet-facing line of business. Nobody has the graph.

Q3

Can we prove our posture to a regulator?

A board slide is not evidence. There is no signed record.

You cannot fix what you cannot see. KavachQ is the telescope nobody has pointed at the bank's own crypto — yet.

The idea

Everyone is racing to do the
migration. KavachQ builds the
thing it can't exist without.

What the crowd chases

The migration / contractor layer

Ripping out RSA and bolting in PQC. Enormous — but services-heavy, fragmented, and it commoditises. Whoever does the swap is forgotten the day it's finished.

What KavachQ is

The trust / attestation layer

The assessment, the proof, the signed system of record the board and the regulator rely on. It's software, it recurs, it compounds — and in India it must be sovereign, which a global vendor structurally cannot ship.

We don't sell the cure. We're the diagnosis, the prescription, and the signed medical record — for the entire financial system.

What KavachQ is

The assessor, planner,
and notary — not
the contractor.

KavachQ tells a bank — and the financial system — how exposed it is to quantum, what to fix first, and proves it with post-quantum signatures.

01 · Find

See the exposure

Live TLS probe, cert & config intake → a typed CryptoGraph and a PQC-readiness score, 0–100.

02 · Plan

Fix the right things first

A phased migration roadmap mapped to NIST replacements and DST/NQM advisory deadlines.

03 · Prove

Make it undeniable

Every finding signed with ML-DSA-65 before storage. Tamper-evident. Verifiable by anyone.

We never touch the migration itself — that stays with the bank's integrators. KavachQ becomes the system of record for post-quantum compliance.

Proof, not slideware

Everything you just read,
we just did. Live.

Not a mockup — a real TLS handshake against a real domain, parsed in real time. Public endpoint: kavachq.in/scanapi.kavachq.in (Fly.io, Mumbai).

kavachq · live scan

A score of 0/100 for an all-RSA, internet-facing bank is not a bug — it's the correct, brutal answer.

Under the hood · one coherent stack

Six services. One signed loop.

Discover

Intake

Live TLS probe, CSV/cert exports or existing CBOM → normalised inventory, signed at intake.

Assess

The CryptoGraph

Apps → certs → algorithms → data classes. 5-pass risk propagation, PQC score, CycloneDX 1.6 CBOM.

Roadmap

The plan

P0/P1/P2 phases → ML-KEM-768 & ML-DSA-65, DST personas, JIRA-exportable tasks.

VajraCrypt

The notary

ML-DSA-65 (FIPS 204) via liboqs. Canonicalise → sign before persist. No signature, no row.

CipherSense

Grounded regs

BM25 over hash-pinned verbatim clauses. A verifier rejects any number not in the source. Air-gapped.

QSRG · Compose

Systemic view

Composes signed CBOMs across orgs into a sector blast-radius graph. Real engine; consent-based.

Persistence is the spine: one database per customer, path-isolated, append-only audit. It runs inside the bank, not in our cloud.

How KavachQ is different

The global tools stop exactly
where India's problem starts.

SandboxAQ, PQShield, IBM Quantum Safe, InfoSec Global own commodity discovery. None can sit inside an Indian bank's perimeter and cite a SEBI circular.

CapabilityGlobal PQC toolsKavachQ
Crypto discovery + CBOMYes (generic)CycloneDX 1.6 + typed graph
Maps to Indian clause & deadline— NoSEBI 2024/113, RBI, DST/NQM
Signs the assessment quantum-safely— NoML-DSA-65 (FIPS 204)
Air-gapped / sovereign deployCloud-firstInside the perimeter
Systemic blast-radius view— NoQSRG cross-org graph*

A global incumbent structurally cannot occupy this wedge. Data residency, sovereign algorithms and regulator trust aren't features they can ship. *QSRG engine is real; the multi-org estate in demos is a clearly-labelled fictional fixture.

Where this goes

Start as a scan.
Become an institution.

Beachhead · now

Indian banks & NBFCs

The system of record for post-quantum compliance in regulated finance.

Expand · next
●●

All Indian regulated CII

Insurers, exchanges, NPCI rails — then telecom, government, health. Same crypto problem, same sovereignty need.

Category · later
●●●

Sovereign PQC, exported

The sovereign attestation layer for other regulated markets that also won't put foreign cloud inside their banks.

The product is a wedge. The mission is the trust infrastructure for post-quantum compliance — wherever sovereignty matters.

Built. Working. Honest.

Real code. Live endpoint.
No hand-waving.

850+
verified tests across the suite
8/8
step end-to-end run, first-try, live
ML-DSA-65
real FIPS-204 sign + tamper-detect
LIVE
public TLS scan on Fly.io, Mumbai
What's real — and what isn't (stated up front)
  • No statutory PQC deadline exists today. We align you to advisory roadmaps; we never call advisory "law."
  • Multi-org blast-radius runs a real engine over a clearly fictional seeded estate. A live multi-bank scan does not exist yet.
  • The AI layer is real but defaults off; a verifier means the model never carries correctness — the source does.
  • Stage: working prototype / early pilot. The core loop is real and proven; not yet production-hardened.
See it for yourself

Don't take our word.
Scan a domain.

Run a real post-quantum exposure scan, in your browser, in seconds. Watch an all-RSA estate score zero — and understand why that matters.

▸ Try the live scan — kavachq.in/scan
CV
Built by Chaitanya Vihari. Founder of KavachQ — designed and shipped the entire sovereign post-quantum assessment stack, from live crypto discovery to post-quantum-signed attestation.
kavachq.in | hello@kavachq.in | The assessor, planner & notary — not the contractor.
next   back   F fullscreen