TLS foundation
Checks whether the public endpoint has a modern TLS baseline before treating PQC as a realistic next step.
Enter a domain to check externally visible TLS posture, security headers and post-quantum readiness signals. Save the result when you need a report to revisit after fixes.
NIST describes HNDL as a reason to start encrypting data with post-quantum techniques as soon as practical. A public website scan is not the whole answer, but it is a fast way to collect the first visible evidence.
Checks whether the public endpoint has a modern TLS baseline before treating PQC as a realistic next step.
Flags older protocol paths that can weaken confidentiality even before a PQC migration begins.
Looks for externally visible post-quantum or hybrid key exchange signals where public negotiation evidence is available.
Lets teams save a repeatable public baseline, then rescan after CDN, TLS or provider changes.
The scan gives you public endpoint evidence. The business decision comes next: which data crossing that endpoint must stay confidential for years, and which systems store or sign records that attackers may want later?
Use the saved report to justify the next step: remove visible TLS gaps, ask providers about PQC support, and build a cryptographic inventory for high-lifetime data.
Usually lower priority for HNDL because the information loses value quickly.
Higher priority because intercepted encrypted sessions may protect data with long confidentiality lifetimes.
Prioritise when records, tokens, signatures or partner data remain sensitive for years.
A public scan cannot see archives, but the result should trigger inventory work for data-at-rest systems.
It cannot inspect private APIs, data-at-rest encryption, code signing, VPNs, key management, supplier contracts or archived data. Those belong in a broader cryptographic inventory.
NCSC guidance frames PQC migration as planning, supplier engagement and system update work. Treat this scan as the visible starting point, not the final assurance.
Harvest now, decrypt later means an attacker records encrypted traffic today and stores it in the hope that future quantum computers can decrypt it. The risk is strongest for data that must stay confidential for years.
No. A public scan can only inspect visible endpoint posture such as TLS, security headers and PQC readiness signals. It cannot inspect internal systems, databases, VPNs, private APIs or archives.
The public endpoint is a practical first signal. If a site still has TLS gaps or no visible PQC readiness, it gives the team evidence to start cleanup, inventory and supplier questions.
Save the report, rescan after fixes, then build a cryptographic inventory for systems handling long-lived sensitive data, APIs, certificates, signatures and supplier services.