Public endpoint evidence
Capture domain, TLS version, visible downgrade risk, security headers and whether post-quantum key exchange is visible.
Enter a public domain to collect visible TLS, header, downgrade and PQC-readiness evidence. Save the result after the scan, then add the report URL to your inventory.
Capture domain, TLS version, visible downgrade risk, security headers and whether post-quantum key exchange is visible.
Flag systems that may still depend on classical public-key cryptography such as RSA, ECDH, ECDSA, DH or DSA.
Record which CDN, cloud, identity, certificate, hosting or managed-service provider controls the cryptography.
Tie each asset to data lifetime, business owner, evidence URL, next action and PQC migration status.
The free scanner gives you a public evidence item. The CSV template turns that evidence into a wider post-quantum migration record with owners, suppliers, algorithm notes, data lifetime and next actions.
NIST and NCSC guidance both point teams toward discovery, prioritisation and staged migration. A lightweight inventory gives that work a structure before expensive tooling or consultancy is justified.
A public endpoint scan is useful because it is fast, repeatable and tied to real evidence. It helps you start the inventory with something verifiable instead of a blank spreadsheet.
A complete cryptographic inventory still needs private systems, source repositories, identity platforms, signing workflows, HSMs, managed suppliers and data-at-rest controls. Use the scan to start and prioritise, then expand the scope.
Use a free account when you want the scan evidence to survive beyond the browser session. Add a domain during signup and the scanner opens directly after account creation.
This gives you a practical loop for the inventory: scan, save, fix, rescan, then update the CSV row with the current evidence and next action.
For post-quantum migration, it is a tool-supported way to collect evidence about where cryptography is used, which systems may depend on quantum-vulnerable public-key algorithms and what should be migrated first.
No. The free public scan starts the inventory with visible endpoint evidence. A complete inventory also needs private APIs, VPNs, applications, signing systems, suppliers, data-at-rest encryption and owners.
Public endpoints are fast to verify, often carry customer or partner traffic, and usually expose early TLS, downgrade and supplier evidence that can shape the rest of the migration backlog.
No. The CSV template can be downloaded directly. A free account is useful when you want to save scan evidence and rerun public endpoint checks over time.