Quantum-safe website test

Is My Website Quantum Safe?

Run a free public scan to check whether your website has the visible foundations for post-quantum cryptography: TLS 1.3, downgrade resistance, security headers and post-quantum readiness signals.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.

Check a Public Domain

Enter a website domain. The free scan checks visible transport security and quantum-readiness signals, then lets you save the result in a free account.

Loading scanner...
What to look for

A Website Is Not Quantum-Safe From One Signal Alone

Treat the public scan as the first evidence point. A credible quantum-safe claim needs visible endpoint checks, saved evidence, inventory and supplier review.

TLS 1.3 is available

TLS 1.3 is the practical foundation for current hybrid post-quantum key exchange deployments.

Legacy downgrade paths are controlled

TLS 1.0, TLS 1.1 and weak TLS 1.2 configurations increase downgrade and compatibility risk.

Hybrid PQC signals are visible

A public endpoint may show active hybrid key exchange such as X25519MLKEM768 when the CDN, server and client path support it.

Security headers support safe migration

HSTS, CSP and clickjacking protections reduce adjacent web risk while cryptography migration is planned.

Long-lived data is prioritised

Websites handling health, finance, identity or confidential records need earlier planning for harvest-now-decrypt-later exposure.

Next steps

If the Scan Shows Gaps

  1. 1. Save the result. Keep the domain, score and visible evidence in a free account so the baseline is not lost.
  2. 2. Fix basic web posture. Resolve TLS, header and downgrade issues before making stronger quantum-safe claims.
  3. 3. Build the inventory. Map certificates, APIs, signing workflows, identity systems, suppliers and data lifetime.
  4. 4. Prioritise long-lived data. Health, finance, legal, identity and confidential records need earlier migration planning.

Save the First Evidence Point

A free account lets you keep the first public scan, rerun it after fixes and use the record as the starting point for badge qualification or a migration discussion.

Quantum-Safe Website FAQ

Can a website be fully quantum-safe today?

A public website can show strong readiness signals such as TLS 1.3, modern security headers and sometimes hybrid post-quantum key exchange. A complete quantum-safe claim also depends on APIs, identity, signing, suppliers and internal systems.

What does the free scan check?

The free scan checks externally visible TLS posture, security headers, downgrade indicators, post-quantum readiness signals and harvest-now-decrypt-later exposure for a public domain.

What should I do if the site is not quantum-safe?

Save the scan, fix basic TLS and header issues, build a cryptographic inventory and prioritise systems that protect long-lived or regulated data.

Does this scan inspect private infrastructure?

No. It is an external public-domain scan. It does not access private networks, source code, identity systems, databases or supplier environments.

Run the Check Before You Claim Readiness

The fastest useful answer starts with a public scan and a saved baseline.