PQLens

Know every algorithm you run — scan in your browser, free.

Your code never leaves your machine. Sign in and your cryptographic inventory follows you.

🔒 Runs in your browser — nothing uploaded 📋 PCI DSS 12.3.3 evidence 🧾 CycloneDX 1.6 CBOM 🔑 ML-DSA-signed reports

Is your domain quantum-vulnerable?

Ten-second check, no signup: we connect once and read what your server negotiates.

We probe the TLS handshake and don't store anything from this check. How this works → Now scan your own code the same way.

Cryptographic inventory is already mandatory.

PCI DSS v4.0 requirement 12.3.3 requires a documented inventory of the cryptography you use — today, not in 2030. PQLens generates that evidence in an afternoon, and flags the embarrassing stuff (MD5, SHA-1, TLS 1.0, RSA-1024) while it's at it. Post-quantum readiness is the roadmap it hands you next.

Broken / deprecated Quantum-vulnerable Quantum-weakened PQC-ready

Nothing uploaded — really

Honesty is the brand. Every claim below is checkable.

It's WebAssembly, auditable

Your code, certs, keystores and passwords are read and classified by a WebAssembly module running in this tab. The engine is the same open-source Go code that ran as a desktop app — nothing hidden server-side.

Endpoint probes are the one exception

TLS and SSH checks need a real network connection a browser can't make — those run from our edge, contacting only the host you name. Nothing else does.

ML-DSA-65 signed reports

Evidence packs are signed with the FIPS 204 post-quantum signature — the same class of cryptography the report itself recommends. Verification is free for anyone.

Open-source evidence engine

Canonical hashing and signing live in cybxsan-evidence, Apache-2.0. You don't have to trust our binary to trust the format.

Nine discovery surfaces, ready today

One tool, from source to endpoint. An inventory is only as good as the places it looks — so PQLens looks at the crypto you call, the crypto you ship, the crypto you declare, and the crypto you serve.

Code

Crypto API usage across Python, JavaScript/TypeScript, Java/Kotlin and Go — algorithm, key size, library, file:line.

Dependencies

Lockfiles for npm, Go, pip/poetry, Maven, Cargo and Bundler — the crypto your libraries ship, whether or not you call it directly.

Config & IaC

nginx, Apache and HAProxy TLS settings; Terraform and cert-manager key specs; SSH public keys. The crypto you declare, not the crypto you call.

Certificates

PEM/DER stores and directories — key algorithm and size, signature hash, validity, deprecated-signature warnings, code-signing keys called out.

SBOM enrichment

Ingest a CycloneDX or SPDX SBOM and attribute the crypto each dependency ships, classified for quantum risk.

TLS endpoints

Protocol versions, cipher suites, key-exchange groups (spot classical ECDHE vs hybrid X25519MLKEM768) — probed live from our edge.

SSH hosts

Host-key algorithm, read pre-authentication. No credentials, no login attempt — just what your fleet presents.

JWKS

The JSON Web Key Set behind your JWT trust — every signing key classified, so your token layer is in the inventory too.

Keystores

PKCS#12 (.p12/.pfx) and Java KeyStores (.jks) — where Java services, load balancers and signing pipelines actually keep their certificates.

Cloud KMS & ACMRoadmap

Your managed keys and certificates — read-only, metadata only. Coming to the browser app; ask if you need it sooner.

Enterprise

The PQC Readiness Assessment, automated

The automated sibling of a $4,500 consulting engagement — a readiness score, executive summary and prioritized roadmap, recomputed every time you scan.

78/ 100

Preview of the Enterprise dashboard — illustrative, not a live result.

  • P0 — 2 code-signing keys are RSA-2048 (CNSA 2.0's earliest deadline)
  • P1 — 14 TLS endpoints still negotiate classical-only key exchange
  • P2 — SSH fleet is entirely Ed25519 — no action needed yet

Pricing

Free = see everything. Pro = keep everything. Enterprise = prove everything.

Free
$0
forever
  • All nine discovery surfaces
  • View results in your browser
  • 5MB per scan · no monthly cap
  • One saved scan per surface
Scan free →
Pro
$49
/ month
  • Keep your inventory — full history & drift, 90-day retention
  • Export Excel, PDF, HTML, CSV, CBOM
  • 250MB scans, unlimited scans/month
Upgrade
Enterprise
$199
/ month
  • Prove it — ML-DSA-65-signed evidence packs
  • PCI 12.3.3 · ISO A.8.24 · CNSA 2.0 mappings
  • Automatic PQC Readiness Assessment · 1-year retention
Upgrade

PCI DSS 12.3.3 is not a future problem

The cryptographic-inventory requirement has been mandatory since March 2025, and a QSA can ask for it today. The EU wants PQC migration started by the end of 2026; NIST deprecates RSA and ECDSA after 2030. Most of these rules ask for the same artifact first — an inventory of the cryptography you are actually running.

That template is the inventory these rules ask for — blank. PQLens fills it in for you: scan your code, dependencies, configs, certificates, keystores, TLS and SSH endpoints and JWKS, and your account keeps one consolidated inventory you can export straight back to Excel.

Popular guides

How to scan each surface, and what the results actually mean. Longer reads on the blog.

PQLens by CybXSan · The evidence engine is open source: cybxsan-evidence.
We never claim “quantum-proof.” Verdicts follow NIST FIPS 203–205 and CNSA 2.0.