Product Built around India's quantum-safe framework

The platform behind a quantum-safe migration

See the cryptography you run, find what's most exposed, get a phased plan to NIST PQC — and the board-ready evidence to prove it. Grounded in the DST National Quantum Mission roadmap and the regulators your auditors answer to: RBI, SEBI, IRDAI, CERT-In.

🔒 The free scan reads only what's publicly negotiated in a TLS handshake — no sign-in, nothing stored.

Where KavachQ fits

Made for the way India regulates and runs

Global crypto-discovery tools map to someone else's regulator. KavachQ is shaped around India's framework, deadlines, and deployment constraints.

India's framework, natively

Grounded in the DST National Quantum Mission roadmap, its M1/M2/M3 milestones, and India's regulators — not a foreign mandate.

Runs in your environment

Managed scan, in-VPC, on-prem, or air-gapped self-hosted Docker. Your cryptographic inventory stays inside your boundary.

Open, portable evidence

The inventory is a signed CBOM in open CycloneDX 1.6 — evidence your own auditors can reproduce, and that travels with you. No lock-in.

Try before you talk to us

Start with a free public scan of any domain's TLS — no sign-in, results in seconds. See the product work before a conversation.

The flow

From your estate to a signed-off plan

One pipeline. Your cryptography goes in; a ranked plan and audit-ready evidence come out.

INPUT Public TLS + the certs / CBOM you supply
01

Discover

Build a Cryptographic Bill of Materials — certificates, algorithms, and the key parameters behind them — in CycloneDX 1.6.

OUT → signed CBOM
02

Score

Score every asset 0–100 and tier it T1–T4 — algorithm strength, internet exposure, criticality, cert expiry, harvest-now — worst-first.

OUT → risk register
03

Plan

A phased, impact-aware move to ML-KEM / ML-DSA / SLH-DSA — hybrid by default, with the apps each change touches mapped.

OUT → migration plan
04

Hand off

Export the phased roadmap to Jira (CSV) / your tracker. Your team executes — KavachQ never touches production.

OUT → Jira / tracker CSV
05

Prove

A board PDF + signed CBOM, every finding tagged to DST/NQM milestones and the relevant RBI / SEBI / CERT-In references.

OUT → board pack
OUTPUT Board pack + machine-readable CBOM

The free scan runs stages 01–02 on your public TLS, instantly. The rest unlocks in an engagement.

Discovery scope today — stated plainly

Shipping now: live public-TLS scanning, plus ingest of the certificates and CBOMs you supply (CSV, tarball, or CycloneDX 1.6) — serialised into one signed CBOM with a quantum-risk graph. On the roadmap: agent-based internal discovery, CA/PKI chain walking, cloud key stores, and source/code scanning. We name the surfaces we cover, so the gaps are never implied away.

Where KavachQ sits

In your evidence path — never your control path

A CISO should never put a third party between their production traffic and their keys. KavachQ reads and advises; you stay in control of every change.

YOUR ENVIRONMENT

You stay in control

  • Your cryptographic estate & production keys
  • Your team makes every change
  • Deploy KavachQ in-VPC, on-prem, or air-gapped
  • Keys never leave your boundary
READ-ONLY ⇄ PLAN & EVIDENCE
KAVACHQ

Reads & advises

  • Discovers cryptography (read-only)
  • Scores quantum risk (0–100, T1–T4)
  • Plans the phased migration
  • Produces the CBOM & board evidence

Trust boundary — KavachQ does not hold, rotate, or enforce your production cryptography.

What you walk away with

Concrete artifacts your board and auditor accept

Not a dashboard you have to live in — portable deliverables you own.

01 · Inventory

A cryptographic inventory (CBOM)

Every certificate, algorithm, and key parameter we can see — a signed CycloneDX 1.6 CBOM your auditors can re-open.

02 · Risk

A ranked quantum-risk register

A 0–100 score and a T1–T4 tier per asset — algorithm strength, exposure, criticality, cert expiry, and harvest-now risk.

03 · Plan

A phased migration plan

A sequenced, impact-aware move to ML-KEM / ML-DSA / SLH-DSA your team can calendar — hybrid by default.

04 · Evidence

A board-ready report

A board PDF + signed CBOM — every finding tagged to DST/NQM milestones and RBI / SEBI / CERT-In references.

kavachq · board-pack.pdf
BOARD PACK · DST / NQMCBOM ✓ signed
T1 · Critical12
T2 · High34
T3 · Medium88
T4 · Low210
payments-api · RSA-204892
core-banking · 3DES88
vpn-gw · ECDH-P25664
archive · AES-25618
SCORED 0–100 · TIERED T1–T4 · HNDL-WEIGHTED

Illustrative output — not real customer data.

How an engagement starts

Start small, prove value, then scale

A low-commitment path — see it work before you widen the scope.

1

Free public scan

Run it on any domain today. See Discover + Score on your public TLS in seconds — no sign-in, nothing stored.

NOW · SELF-SERVE
2

Scoped assessment

A scoped engagement on a slice of your estate — supply your certs / CBOM and get a real signed CBOM, a ranked risk register, and a first plan.

SCOPED ENGAGEMENT
3

Deploy in your environment

Run KavachQ where your regulated data lives — in-VPC, on-prem, or air-gapped self-hosted Docker — with no key custody.

IN YOUR VPC
Fits your workflow

Hands off to the tools you already run

KavachQ produces portable artifacts, so the plan lands where your team already works.

Shipping today

Export to Jira (CSV)

The phased roadmap exports as a Jira-ready CSV — alongside the signed CycloneDX 1.6 CBOM and a JSON risk graph that drop into any system you run.

On the roadmap

Direct connectors

Two-way connectors are planned, not shipped — shown greyed so nothing is implied as live.

cloud · AWS / Azure CA / PKI HSM / key store GitHub / GitLab ServiceNow
Understand it first

We'd rather you learn than be sold to

Free, open material on the quantum threat and India's response — the understanding our team works from.

What you can verify today

Proof you can check yourself

Free public scan

Run it on any domain. The product works in front of you, before any sales call.

Signed CycloneDX 1.6

A standard, machine-readable CBOM — reproducible, portable, no lock-in.

Air-gap-ready

Self-hosted Docker (incl. air-gapped) keeps sensitive estates inside your boundary.

Vendor-neutral

We summarise official DST and NIST sources plainly; no pay-for-placement.

Get started

See your exposure in seconds

Run a free scan, then bring KavachQ to your whole estate — discovery, scoring, planning, and proof, aligned to India's framework.