Free inventory starter

Cryptographic Inventory Scanner and PQC Template

Start your post-quantum cryptographic inventory with a public endpoint scan, a CSV template for owners and algorithms, and a free account for saved scan evidence.

Scan the First Inventory Item

Enter a public domain to collect visible TLS, header, downgrade and PQC-readiness evidence. Save the result after the scan, then add the report URL to your inventory.

Loading inventory scanner...

What to Capture First

Public endpoint evidence

Capture domain, TLS version, visible downgrade risk, security headers and whether post-quantum key exchange is visible.

Quantum-vulnerable uses

Flag systems that may still depend on classical public-key cryptography such as RSA, ECDH, ECDSA, DH or DSA.

Supplier and ownership gaps

Record which CDN, cloud, identity, certificate, hosting or managed-service provider controls the cryptography.

Migration priority

Tie each asset to data lifetime, business owner, evidence URL, next action and PQC migration status.

CSV template

Turn Scan Evidence Into an Inventory Row

The free scanner gives you a public evidence item. The CSV template turns that evidence into a wider post-quantum migration record with owners, suppliers, algorithm notes, data lifetime and next actions.

NIST and NCSC guidance both point teams toward discovery, prioritisation and staged migration. A lightweight inventory gives that work a structure before expensive tooling or consultancy is justified.

Template Fields

  • -System or domain
  • -Owner
  • -Cryptographic use
  • -Algorithm evidence
  • -Data lifetime
  • -Supplier
  • -PQC status
  • -Next action

Inventory Workflow

  1. 1. Scan the public endpoint. Run a visible scan first. This gives the inventory a concrete evidence URL for TLS, headers and PQC-readiness signals.
  2. 2. Download the CSV template. Use the same structure for APIs, VPN portals, signing workflows, identity systems, suppliers and internal services.
  3. 3. Save evidence in a free account. Keep the first scan result, rescan after fixes and use the report as evidence when updating the inventory.
  4. 4. Expand from public to private systems. A public scan cannot see everything. Add private APIs, code-signing keys, HSMs, data stores and supplier answers manually.
Scope and limits

This Is a Starter Scan, Not a Full Estate Discovery

A public endpoint scan is useful because it is fast, repeatable and tied to real evidence. It helps you start the inventory with something verifiable instead of a blank spreadsheet.

A complete cryptographic inventory still needs private systems, source repositories, identity platforms, signing workflows, HSMs, managed suppliers and data-at-rest controls. Use the scan to start and prioritise, then expand the scope.

What the scan cannot see

  • -It does not inspect source code, private networks, VPNs, databases, HSMs or internal service meshes.
  • -It does not prove every cryptographic dependency is known.
  • -It should be treated as the first public evidence item, not a replacement for a full discovery exercise.
Saved evidence

Keep the First Scan With Your Inventory

Use a free account when you want the scan evidence to survive beyond the browser session. Add a domain during signup and the scanner opens directly after account creation.

This gives you a practical loop for the inventory: scan, save, fix, rescan, then update the CSV row with the current evidence and next action.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.

Cryptographic Inventory Scanner FAQ

What is a cryptographic inventory scanner?

For post-quantum migration, it is a tool-supported way to collect evidence about where cryptography is used, which systems may depend on quantum-vulnerable public-key algorithms and what should be migrated first.

Can this scan create my full cryptographic inventory?

No. The free public scan starts the inventory with visible endpoint evidence. A complete inventory also needs private APIs, VPNs, applications, signing systems, suppliers, data-at-rest encryption and owners.

Why does a PQC inventory start with public endpoints?

Public endpoints are fast to verify, often carry customer or partner traffic, and usually expose early TLS, downgrade and supplier evidence that can shape the rest of the migration backlog.

Do I need an account to use the inventory template?

No. The CSV template can be downloaded directly. A free account is useful when you want to save scan evidence and rerun public endpoint checks over time.