The Lifecycle
Five stages, one platform
KavachQ covers the assess-and-prove side of the quantum-safe lifecycle defined in the DST Task Force report — discover, score, plan, hand off, prove. Your team executes the migration; KavachQ never touches production.
01
Crypto discovery (BOMs)
Automated CBOM generation (CycloneDX 1.6) from live TLS scans, plus intake of the certificate exports and CBOMs you already hold.
02
Quantum risk analysis
HNDL exposure flagging and 0–100 / T1–T4 quantum-risk prioritisation against the DST Persona framework (Urgent / Regular / Vendor). Findings are cited against verbatim clauses from the mandates for Indian CII and BFSI — DST/NQM, RBI, SEBI CSCRF, CERT-In — with a grounded “Ask the Regulation” view that answers only from that corpus.
03
Migration plan
Phased roadmap aligned to the DST milestones (CII 2027/28/29 · Enterprise 2028/30/33), broken down by system, owner, impact, and supplier. A crypto impact graph computes blast radius — which downstream systems break when an algorithm falls — so sequencing follows real impact.
04
Hybrid roll-out plan
Phased migration plan for the hybrid (classical + PQC) roll-out across TLS, PKI, and code-signing chains. Recommended replacements are named where relevant — ML-KEM-768 (FIPS 203) for key establishment, ML-DSA-65 (FIPS 204) for signatures.
05
Assurance & reporting
Board-ready reports and regulator-facing exports, tagged to DST/NQM milestones. Every CBOM and report is digitally signed (ML-DSA-65, FIPS 204) and independently verifiable — tamper-evident attestation a regulator can check.