TLS 1.3 foundation
Checks whether the public endpoint can use modern TLS, which is the baseline for current hybrid PQC key agreement work.
Enter a domain to check externally visible TLS posture and post-quantum readiness signals. The result can be saved to a free account after the scan.
Checks whether the public endpoint can use modern TLS, which is the baseline for current hybrid PQC key agreement work.
Looks for visible post-quantum key exchange signals such as X25519MLKEM768 where negotiation evidence is available.
Flags older TLS versions and fallback paths that can weaken the value of a future post-quantum deployment.
Reviews headers such as HSTS and CSP because TLS posture is only one part of a secure public endpoint.
A good PQC TLS result is a starting point, not the whole migration. Public TLS can show whether the edge is modern enough for hybrid key agreement and whether a provider is already exposing post-quantum negotiation signals.
The result should feed a practical worklist: remove downgrade paths, confirm CDN and origin behaviour, identify APIs with long-lived sensitive data, and decide which systems need a cryptographic inventory next.
A visible hybrid key exchange signal was detected. Treat this as strong public-endpoint evidence, then check certificates, signatures, APIs and internal systems separately.
The endpoint has a modern transport baseline, but no active post-quantum key exchange was visible during the scan.
The endpoint appears to rely on classical TLS key exchange. Long-lived sensitive data may need prioritised migration planning.
Older protocol support or weak fallback behaviour can undermine migration work even if a provider later enables PQC.
No external TLS checker can prove that an organisation is fully quantum-safe. It cannot inspect private APIs, database encryption, signing keys, VPNs, device firmware, supplier systems or archived data with long confidentiality lifetimes.
Use this result as the first visible evidence for public endpoints, then move to a cryptographic inventory and migration plan for systems that process regulated, contractual or long-lived sensitive data.