KavachQ · The Platform

Quantum-safe migration, simplified for India

KavachQ is a platform for the quantum-safe migration journey — cryptographic discovery, quantum risk scoring, migration planning, and reporting tagged to DST/NQM milestones.

SEE IT ON YOUR OWN DOMAIN

Scan any public domain free, in seconds — no login, nothing stored. A live TLS read returns a PQC-readiness score (0–100), a risk tier (Critical / High / Medium / Low), the certificate key type and size, and any quantum-vulnerable algorithms (RSA, ECDSA, DSA) or weak TLS (1.0/1.1) it negotiates.

Run the free scan
FRAMEWORKS WE MAP TO NQM Task Force · May 2026 NIST FIPS 203/204/205 + 206 (draft) TEC / STQC / BIS CERT-In · NCCS
The Lifecycle

Five stages, one platform

KavachQ covers the assess-and-prove side of the quantum-safe lifecycle defined in the DST Task Force report — discover, score, plan, hand off, prove. Your team executes the migration; KavachQ never touches production.

01

Crypto discovery (BOMs)

Automated CBOM generation (CycloneDX 1.6) from live TLS scans, plus intake of the certificate exports and CBOMs you already hold.

Outputs CBOM in CycloneDX 1.6
02

Quantum risk analysis

HNDL exposure flagging and 0–100 / T1–T4 quantum-risk prioritisation against the DST Persona framework (Urgent / Regular / Vendor). Findings are cited against verbatim clauses from the mandates for Indian CII and BFSI — DST/NQM, RBI, SEBI CSCRF, CERT-In — with a grounded “Ask the Regulation” view that answers only from that corpus.

0–100 SCORE · T1–T4 · cited to DST · RBI · SEBI
03

Migration plan

Phased roadmap aligned to the DST milestones (CII 2027/28/29 · Enterprise 2028/30/33), broken down by system, owner, impact, and supplier. A crypto impact graph computes blast radius — which downstream systems break when an algorithm falls — so sequencing follows real impact.

Auto-aligned to DST milestones
04

Hybrid roll-out plan

Phased migration plan for the hybrid (classical + PQC) roll-out across TLS, PKI, and code-signing chains. Recommended replacements are named where relevant — ML-KEM-768 (FIPS 203) for key establishment, ML-DSA-65 (FIPS 204) for signatures.

ML-KEM · ML-DSA · SLH-DSA · FN-DSA
05

Assurance & reporting

Board-ready reports and regulator-facing exports, tagged to DST/NQM milestones. Every CBOM and report is digitally signed (ML-DSA-65, FIPS 204) and independently verifiable — tamper-evident attestation a regulator can check.

SIGNED ML-DSA-65 · INDEPENDENTLY VERIFIABLE
Architecture

How KavachQ fits in

Deployed inside your environment as a self-hosted deployment. Air-gap-compatible.

Hybrid (classical + PQC) is the default approach. Algorithm coverage expands as NIST standards finalise.

Capability Map

What KavachQ covers, line by line

Mapped one-to-one against the DST Task Force recommendations and Sub-Group I/II frameworks.

CapabilityDST referenceKavachQ moduleOutput
Cryptographic asset repositorySection 9.0 A — Short-termDiscovery + BOM EngineSigned CBOM (CycloneDX 1.6)
Quantum risk analysisSub-Group II — Phase 1Risk Scoring0–100 / T1–T4 risk register + impact blast-radius
Crypto-agile designSection 9.0 — Critical PrinciplesDesign principleAlgorithm-agnostic data model
Assurance reportingSub-Group I — Assurance LevelsReportingBoard PDF + signed CBOM, milestone-tagged
Sectoral persona prioritisationSub-Group II — PersonasPersona ProfileUrgent / Regular / Vendor tagging
Who it's for

Three personas, one platform

Urgent

Urgent Adopters (CII)

Power, telecom, transport, defence, ISRO, DRDO, ONGC, banking core. Compressed CII timeline: foundations 2027, high-priority migration 2028, full PQC 2029.

L4 assurance · air-gap modes
Regular

Regular Enterprise

Government, financial services, healthcare, insurance, IT services. Standard timeline: foundations 2028, high-priority 2030, full PQC 2033.

L2 / L3 assurance · hybrid by default
Vendor

Technology Vendors

HSM and KMS makers, cloud providers, PKI operators, network equipment vendors. The DST advisory roadmap recommends vendor CBOM disclosure from FY 2027–28.

CycloneDX
Algorithm Support

Aligned to the NIST PQC standards

KavachQ is designed around the NIST-standardised PQC algorithms and the latest selections. Algorithm coverage expands as standards finalise.

FIPS 203

ML-KEM

Module-Lattice KEM (formerly Kyber). Sizes 512 / 768 / 1024.

FIPS 204

ML-DSA

Module-Lattice Signatures (formerly Dilithium). Sizes 44 / 65 / 87.

FIPS 205

SLH-DSA

Stateless Hash-based Signatures (formerly SPHINCS+). Conservative.

FIPS 206 (Draft)

FN-DSA

FFT NTRU Signatures (formerly Falcon). Smallest lattice signatures.

5th Selection

HQC

Code-based KEM, selected March 2025 for algorithmic diversity.

Hybrid

X25519 + ML-KEM

Default hybrid key exchange during the transition window.

Hybrid

ECDSA + ML-DSA

Hybrid signatures for code and certificate chains.

Symmetric

AES-256 · SHA-384/512

Doubled symmetric strength, hardened against Grover.

Get Started

Start with a discovery scan

A 30-minute call to scope a KavachQ Discovery engagement — the first deliverable in any DST-aligned migration plan.

KavachQ is available for evaluation as a self-hosted, air-gap-compatible deployment — request evaluation access.

Scope a pilot engagement — a Discover → Score → Plan pilot in your environment.