Free HNDL website check

Harvest Now, Decrypt Later Scanner

Check whether a public website shows visible risk signals for harvest-now-decrypt-later exposure. Start with TLS, downgrade posture and post-quantum readiness, then save the result as the first evidence record for deeper inventory work.

Scan a Public Website

Enter a domain to check externally visible TLS posture, security headers and post-quantum readiness signals. Save the result when you need a report to revisit after fixes.

Loading scanner...
Public signals

What the HNDL Scanner Looks For

NIST describes HNDL as a reason to start encrypting data with post-quantum techniques as soon as practical. A public website scan is not the whole answer, but it is a fast way to collect the first visible evidence.

TLS foundation

Checks whether the public endpoint has a modern TLS baseline before treating PQC as a realistic next step.

Downgrade exposure

Flags older protocol paths that can weaken confidentiality even before a PQC migration begins.

PQC visibility

Looks for externally visible post-quantum or hybrid key exchange signals where public negotiation evidence is available.

Report evidence

Lets teams save a repeatable public baseline, then rescan after CDN, TLS or provider changes.

Risk triage

HNDL Risk Depends on Data Lifetime

The scan gives you public endpoint evidence. The business decision comes next: which data crossing that endpoint must stay confidential for years, and which systems store or sign records that attackers may want later?

Use the saved report to justify the next step: remove visible TLS gaps, ask providers about PQC support, and build a cryptographic inventory for high-lifetime data.

Short-lived public content

Usually lower priority for HNDL because the information loses value quickly.

Customer or patient portals

Higher priority because intercepted encrypted sessions may protect data with long confidentiality lifetimes.

Payment, identity or API traffic

Prioritise when records, tokens, signatures or partner data remain sensitive for years.

Archived regulated data

A public scan cannot see archives, but the result should trigger inventory work for data-at-rest systems.

Three-step path

From Public Scan to PQC Planning

  1. 1. Scan the public endpoint. Enter a domain and run the free public scanner for TLS, headers, downgrade risk and PQC readiness signals.
  2. 2. Save the report. Use the free account flow to save the scan as a repeatable HNDL evidence baseline.
  3. 3. Prioritise long-lived data. Use the result to decide which portals, APIs, suppliers and data stores need deeper PQC inventory work.
Scope boundary

What a Public HNDL Scan Cannot Prove

It cannot inspect private APIs, data-at-rest encryption, code signing, VPNs, key management, supplier contracts or archived data. Those belong in a broader cryptographic inventory.

NCSC guidance frames PQC migration as planning, supplier engagement and system update work. Treat this scan as the visible starting point, not the final assurance.

HNDL Scanner FAQ

What is harvest now, decrypt later?

Harvest now, decrypt later means an attacker records encrypted traffic today and stores it in the hope that future quantum computers can decrypt it. The risk is strongest for data that must stay confidential for years.

Can a public website scan prove HNDL risk?

No. A public scan can only inspect visible endpoint posture such as TLS, security headers and PQC readiness signals. It cannot inspect internal systems, databases, VPNs, private APIs or archives.

Why scan if the full risk depends on hidden data?

The public endpoint is a practical first signal. If a site still has TLS gaps or no visible PQC readiness, it gives the team evidence to start cleanup, inventory and supplier questions.

What should I do after the scan?

Save the report, rescan after fixes, then build a cryptographic inventory for systems handling long-lived sensitive data, APIs, certificates, signatures and supplier services.

Primary References

Check the Public Endpoint First

Run the free HNDL scanner, save the report, and use it to decide where deeper post-quantum inventory work should start.