TLS 1.3 foundation
Modern TLS is the practical baseline for current public-endpoint post-quantum key agreement work.
Check whether a public website shows the visible signals needed before you can call it quantum-safe: TLS 1.3, no weak downgrade paths, security headers and post-quantum key exchange evidence where available.
Enter a domain to run the same public scanner used by the free report flow. After the scan, you can save the result in a free account.
Modern TLS is the practical baseline for current public-endpoint post-quantum key agreement work.
The checker looks for public evidence of hybrid post-quantum key exchange where browser-facing negotiation data is available.
Legacy TLS paths can weaken a future PQC rollout by allowing clients to fall back to non-PQC transport.
HSTS, CSP, clickjacking and MIME-sniffing controls show whether the public endpoint has basic web-security discipline.
A website result is useful evidence, but it is not a full organisation-wide attestation. It tells you whether the public browser-facing endpoint has the visible transport-security baseline needed for post-quantum migration.
If the result shows no visible post-quantum key exchange, treat that as a practical next question for the CDN, hosting provider or gateway owner. Then expand the work to APIs, certificates, signing workflows and systems with long-lived sensitive data.
The public endpoint shows visible evidence of hybrid post-quantum key exchange. Save the result, then check origins, APIs, certificates and suppliers.
The endpoint has a modern TLS foundation, but no public post-quantum key exchange signal was detected during the scan.
TLS downgrade paths, missing security headers or classical-only key exchange mean the website should not be described as quantum-safe yet.
The useful output is not only a pass or warning. It is a repeatable evidence record that helps you ask better provider, engineering and supplier questions.
No. It checks externally visible website signals. A full quantum-safe position also needs API, origin, certificate, signing, supplier and data-lifetime review.
For a public website, start with TLS 1.3, no weak downgrade paths, strong security headers and visible hybrid post-quantum key exchange where the provider supports it.
You can save the result in a free account, rerun it after fixes and use it as the first evidence item for a wider post-quantum migration plan.
Many providers support post-quantum options, but they may need to be enabled per zone, product or edge path. The origin and API paths may also differ from the public website edge.