Free vulnerability scan

Post-Quantum Vulnerability Scanner

Scan a public website for externally visible cryptographic weaknesses linked to the post-quantum transition: TLS posture, downgrade exposure, missing security headers and harvest-now-decrypt-later risk signals.

Scan a Public Domain

Enter a domain to check visible post-quantum readiness and common web-security signals. After the scan, you can save the result in a free account.

Loading vulnerability scanner...

What This Public Scan Checks

Quantum-vulnerable TLS posture

Checks whether the public endpoint still depends on classical transport signals without visible hybrid post-quantum key exchange evidence.

Downgrade and legacy protocol exposure

Flags older TLS paths and downgrade risks that can undermine a later PQC rollout.

Security-header weaknesses

Reviews HSTS, CSP, clickjacking and MIME-sniffing controls because visible browser weaknesses often sit beside cryptographic gaps.

Harvest-now-decrypt-later risk signals

Highlights where public endpoint posture should trigger a deeper inventory for long-lived sensitive data.

Scope and limits

Public Vulnerability Scans Are a Starting Point

A public scan is useful because it is fast, repeatable and tied to real evidence on an exposed endpoint. It can show whether a website still has visible transport, downgrade or browser-security weaknesses before deeper migration work starts.

It cannot prove that the organisation is quantum-safe. NCSC and FedRAMP guidance both treat vulnerability scanning as part of a wider management process. For post-quantum work, the next step is a cryptographic inventory across endpoints, certificates, APIs, signing systems and suppliers.

What This Scan Cannot See

  • -Private APIs, VPNs and internal services
  • -Source code, application business logic and authentication flaws
  • -Databases, backups and data-at-rest encryption
  • -Supplier systems, contracts and managed-service controls
  • -Code-signing keys, firmware signing and document workflows
  • -Full cryptographic inventory across endpoints and assets

How to Use the Result

1. Save the scan

Keep the domain, visible findings and score as a repeatable baseline in a free account.

2. Fix visible gaps

Prioritise TLS, downgrade and browser-security issues that are externally visible.

3. Expand to inventory

Map quantum-vulnerable cryptography in APIs, suppliers, signing workflows and long-lived data paths.

Post-Quantum Vulnerability Scanner FAQ

What is a post-quantum vulnerability scanner?

It is a public website scan that checks visible signals related to quantum-readiness, such as TLS posture, downgrade exposure, security headers and whether post-quantum or hybrid key exchange evidence is visible.

Can this prove my organisation is quantum-safe?

No. A public scan can find visible endpoint weaknesses, but a full post-quantum assessment also needs a cryptographic inventory, supplier review, internal systems review and migration plan.

Is this the same as a normal vulnerability scanner?

No. Normal vulnerability scanners look for broad technical weaknesses. This page focuses on externally visible cryptographic and post-quantum readiness signals, then explains when a broader vulnerability management programme is needed.

What should I do after a warning result?

Save the scan in a free account, fix visible TLS and header issues, then build a cryptographic inventory for systems that protect long-lived sensitive data.

Run the Free Public Scan First

Use the vulnerability scan to capture visible evidence, then save the report and decide whether you need a broader post-quantum readiness assessment.