Your code never leaves your machine. Sign in and your cryptographic inventory follows you.
PCI DSS v4.0 requirement 12.3.3 requires a documented inventory of the cryptography you use — today, not in 2030. PQLens generates that evidence in an afternoon, and flags the embarrassing stuff (MD5, SHA-1, TLS 1.0, RSA-1024) while it's at it. Post-quantum readiness is the roadmap it hands you next.
Honesty is the brand. Every claim below is checkable.
Your code, certs, keystores and passwords are read and classified by a WebAssembly module running in this tab. The engine is the same open-source Go code that ran as a desktop app — nothing hidden server-side.
TLS and SSH checks need a real network connection a browser can't make — those run from our edge, contacting only the host you name. Nothing else does.
Evidence packs are signed with the FIPS 204 post-quantum signature — the same class of cryptography the report itself recommends. Verification is free for anyone.
Canonical hashing and signing live in cybxsan-evidence, Apache-2.0. You don't have to trust our binary to trust the format.
One tool, from source to endpoint. An inventory is only as good as the places it looks — so PQLens looks at the crypto you call, the crypto you ship, the crypto you declare, and the crypto you serve.
Crypto API usage across Python, JavaScript/TypeScript, Java/Kotlin and Go — algorithm, key size, library, file:line.
Lockfiles for npm, Go, pip/poetry, Maven, Cargo and Bundler — the crypto your libraries ship, whether or not you call it directly.
nginx, Apache and HAProxy TLS settings; Terraform and cert-manager key specs; SSH public keys. The crypto you declare, not the crypto you call.
PEM/DER stores and directories — key algorithm and size, signature hash, validity, deprecated-signature warnings, code-signing keys called out.
Ingest a CycloneDX or SPDX SBOM and attribute the crypto each dependency ships, classified for quantum risk.
Protocol versions, cipher suites, key-exchange groups (spot classical ECDHE vs hybrid X25519MLKEM768) — probed live from our edge.
Host-key algorithm, read pre-authentication. No credentials, no login attempt — just what your fleet presents.
The JSON Web Key Set behind your JWT trust — every signing key classified, so your token layer is in the inventory too.
PKCS#12 (.p12/.pfx) and Java KeyStores (.jks) — where Java services, load balancers and signing pipelines actually keep their certificates.
Your managed keys and certificates — read-only, metadata only. Coming to the browser app; ask if you need it sooner.
The automated sibling of a $4,500 consulting engagement — a readiness score, executive summary and prioritized roadmap, recomputed every time you scan.
Preview of the Enterprise dashboard — illustrative, not a live result.
Free = see everything. Pro = keep everything. Enterprise = prove everything.
The cryptographic-inventory requirement has been mandatory since March 2025, and a QSA can ask for it today. The EU wants PQC migration started by the end of 2026; NIST deprecates RSA and ECDSA after 2030. Most of these rules ask for the same artifact first — an inventory of the cryptography you are actually running.
That template is the inventory these rules ask for — blank. PQLens fills it in for you: scan your code, dependencies, configs, certificates, keystores, TLS and SSH endpoints and JWKS, and your account keeps one consolidated inventory you can export straight back to Excel.
How to scan each surface, and what the results actually mean. Longer reads on the blog.