Security Dashboard
Real-time QCrypton threat monitoring
Scan Distribution
Threat Verdicts
Key Performance Indicators
Remediation Burn-Down
Recent Activity
No activity yet. Run a scan to get started.
HNDL Portfolio Exposure
Prompt Injection Scanner
Detect prompt injection attacks targeting AI assistants
Scan Input
Tool Poisoning Detector
Analyze MCP tool definitions for hidden malicious behaviors
Tool Definition (JSON)
Data Exfiltration Scanner
Detect attempts to steal payment and sensitive data
Payload to Inspect
MCP Server Config Auditor
Audit MCP server configurations for security compliance
Server Configuration (JSON)
Quantum Code Scanner
Assess cryptographic resilience against quantum computing attacks (Shor's, Grover's, HNDL)
System Quantum Configuration (JSON)
Quantum Threat Remediation
PQC Migration & CorrectionGenerate a remediation plan based on the current quantum scan. Recommends PQC algorithm replacements, per-finding fixes, migration steps, and a corrected configuration for re-scanning.
Per-Finding Remediation Actions
PQC Migration Recommendations
Corrected Configuration
Auth Attack Scanners
Detect brute-force, dictionary, and credential stuffing attacks against authentication systems
Scan Input
Auth Attack Scanners
Detect brute-force, dictionary, and credential stuffing attacks against authentication systems
Scan Input
Auth Attack Scanners
Detect brute-force, dictionary, and credential stuffing attacks against authentication systems
Scan Input
Phishing Attack Scanner
Detect fake portals, credential harvesting, homoglyph domains, and social engineering
Scan Input
Auth Attack Scanners
Detect brute-force, dictionary, and credential stuffing attacks against authentication systems
Scan Input
Auth Attack Scanners
Detect brute-force, dictionary, and credential stuffing attacks against authentication systems
Scan Input
Noise Reachability Scanner
Classify noise sources, evaluate QEC codes, identify errors that propagate past correction — like CVE reachability for quantum systems
Noise Reachability Scan
Noise Threat Remediation
QEC Correction & MitigationGenerate a remediation plan based on the current noise scan. Recommends optimal QEC codes, per-error fixes, hardware upgrades, and a corrected configuration for re-scanning.
QEC Correction Plan
Per-Error Remediation Actions
Hardware Recommendations
Corrected Configuration
Crypto Threats
Detect weak algorithms, crypto vulnerabilities, hardcoded keys, and secrets across 6 languages
Scan Code Snippet
Crypto Threat Remediation
Auto-Fix & PQC MigrationGenerate a remediation plan based on the current code scan. Auto-patches weak algorithms (MD5, SHA-1, DES, RC4, AES-ECB) with quantum-safe replacements, and flags asymmetric algorithms (RSA, ECDSA, Ed25519) that require manual PQC migration.
Auto-Fix Patches
Remaining Issues (Manual Fix Required)
Corrected Code
Attack Simulator
Simulate 36 real-world attack scenarios across 5 categories — quantum threats, crypto attacks, general threats, card fraud, and ASPM/agentic threats
⚛ Quantum Threats
Quantum HNDL
Harvest encrypted data now, decrypt with future quantum computers
CriticalShor's Algorithm (RSA)
Factor RSA-2048 keys using 4,098 logical qubits to break TLS and signatures
CriticalShor's Algorithm (ECC)
Compute elliptic curve discrete log to break ECDSA, ECDH, and Ed25519
CriticalGrover's Key Search
Halve effective key length of AES-128 and 3DES via quantum brute-force
HighDepolarizing Channel Attack
Exploit quantum channel noise to corrupt qubits past QEC correction threshold
CriticalCosmic Ray Burst
Correlated multi-qubit errors from high-energy particle strikes defeat standard QEC
CriticalQubit Crosstalk Exploit
Induce correlated gate errors between adjacent qubits to propagate past surface code
HighPQC Migration Gap
Exploit systems stuck in partial PQC migration with mixed classical/quantum crypto
High🔎 Crypto Threats
Weak Algorithm Exploitation
Exploit MD5, SHA-1, DES, RC4 weaknesses to forge hashes or decrypt data
CriticalHardcoded Key Extraction
Extract encryption keys, API secrets, and tokens embedded in source code
CriticalNonce Reuse / IV Attack
Exploit static IVs in AES-GCM to recover authentication key and decrypt traffic
CriticalPadding Oracle
Decrypt AES-CBC ciphertext one byte at a time via padding error side-channel
High⚠ General Threats
Pricing Manipulation
Override pricing calculations via prompt injection to bypass charges
CriticalData Poisoning
Inject false data through compromised MCP tools
CriticalCard Data Theft
Exfiltrate payment card data to external servers
CriticalLocation Tracking
Extract real-time user GPS and location records
HighMCP Rug Pull
Tool activates malicious behavior after gaining trust
CriticalBrute-Force Attack
Automated password guessing against accounts and PINs
CriticalCredential Stuffing
Reuse leaked breach credentials to compromise accounts at scale
CriticalDictionary Attack
Crack passwords using wordlists and mutation rules
CriticalPhishing Campaign
Mass phishing emails impersonating legitimate services to harvest card data
CriticalPayment Keylogger
Magecart-style script injected on payment pages to steal card data
Critical💳 Card Fraud
Physical Card Swap
Distraction-based card swap at payment terminal to steal debit/credit cards
CriticalNFC Relay Attack
Relay contactless card signal to remote terminal for unauthorized payments
CriticalCard Skimming
Install skimming device on payment terminal to capture card data and PINs
CriticalDigital Wallet Hijack
Provision stolen card into attacker mobile wallet via SIM swap
CriticalBIN Attack / Carding
Generate valid card numbers from BIN and test with micro-transactions
Critical🤖 ASPM & Agentic Threats
AI Triage Evasion
Craft findings that trick the AI triage agent into marking true positives as false positives
CriticalNoise Collapse Poisoning
Systematically mark true positives as false positives to corrupt the learned suppression model
CriticalRemediation PR Injection
Manipulate autonomous PR generation to inject backdoors via crafted code patches
CriticalDependency Confusion
Upload malicious package with same name as internal dependency to public registry
CriticalWorkflow Rule Bypass
Manipulate finding severity to avoid auto-assignment, SLA tracking, and Jira ticket creation
HighCNSA 2.0 Deadline Exploit
Exploit organizations in partial CNSA 2.0 migration with mixed approved/deprecated algorithms
HighSBOM Tampering
Modify CycloneDX SBOM to hide vulnerable dependencies from the dependency graph
HighFinding Suppression Abuse
Abuse risk acceptance workflow to suppress critical findings without compensating controls
HighNIST Post-Quantum Migration
Assess readiness and plan migration to NIST-standardized post-quantum cryptographic algorithms
Migration Readiness Assessment
Remediation
Auto-fix security issues — sanitize input, fix configs, patch weak crypto, and generate autonomous PRs
Noise Reachability Remediation
Input Sanitization
Config Remediation
Code Remediation
Security Policies
Manage custom detection rules for security threats
Create New Policy
Active Policies
0Loading policies...
SLA Dashboard
Real-time uptime metrics, response time guarantees, and incident history
SLA Guarantees by Plan
| Metric | Large | Enterprise |
|---|---|---|
| Uptime SLA | 99.9% | 99.99% |
| API Response Time | < 200ms (P95) | < 100ms (P95) |
| Scan Throughput | 200K queries/mo | Unlimited |
| Support SLA | 4h response | 1h response + dedicated manager |
| Incident Resolution | 8h target | 2h target |
| Data Retention | 90 days | 1 year + custom |
Uptime History (Last 90 Days)
Recent Incidents
No incidents in the last 30 days
Usage Analytics
API consumption, scan trends, and team activity across your organization
API Usage by Scanner
Daily Query Volume (Last 30 Days)
Team Activity
Loading team activity...
Team Management
Invite users, assign roles, and manage your organization
Invite Team Member
User Registrations
Onboarding
Get started with QCrypton in minutes
Setup Checklist
Generate API Key
Create your first API key to authenticate scan requests
Run First Scan
Scan a code snippet or configuration for threats
Assess Quantum Readiness
Scan your cryptographic configuration for quantum vulnerabilities
Check CNSA 2.0 Compliance
Validate your crypto posture against NSA CNSA Suite 2.0 requirements
Connect GitHub
Enable autonomous PR generation to auto-fix weak crypto in your repos
Connect Slack
Get real-time alerts for threats, assignments, and SLA breaches
Configure Webhook
Send scan results to your SIEM or notification channel
Invite Your Team
Add team members with role-based access
Integrate CI/CD Gate
Add QCrypton security gate to your build pipeline
Quick Start Code
curl -X POST https://your-instance.qcrypton.com/api/scan/quantum \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"config":{"name":"my-system","algorithms":[{"name":"RSA-2048","usage":"TLS"}],"tls":"TLS 1.2"}}'
White-Label & Branding
Customize the QCrypton console with your organization's branding
Brand Settings
Preview
Compliance & Reports
MTTR tracking, compliance dashboards (SOC 2, ISO 27001, PCI-DSS, HIPAA, CNSA 2.0), security posture trends, and GDPR data export
Mean Time to Remediate (MTTR)
Security Posture Trend (30 days)
Compliance Framework Mapping
SOC 2 Type II
41 / 44 controls met
ISO 27001
98 / 114 controls met
PCI-DSS v4.0
188 / 241 requirements met
NIST CSF 2.0
108 / 114 subcategories met
HIPAA
42 / 50 safeguards met
CNSA 2.0
Phase 1 compliant
Generate Report
Scheduled Digests
Automatically send scan summaries and threat alerts to your team via email.
SSO Configuration
Configure Single Sign-On providers for your organization
Active SSO Providers
GitHub
Not ConfiguredAzure AD
Not ConfiguredOkta
Not ConfiguredConfigure Provider
Callback URLs
Add these URLs to your OAuth provider's authorized redirect URIs:
https://your-instance.qcrypton.com/auth/google/callback
Google
https://your-instance.qcrypton.com/auth/github/callback
GitHub
https://your-instance.qcrypton.com/auth/azure/callback
Azure AD
https://your-instance.qcrypton.com/auth/okta/callback
Okta
Billing & Subscription
Manage your subscription, payment methods, and view invoices
Payment Method
Loading payment methods...
Enter Card Details
Invoices
| Date | Description | Amount | Status | Action |
|---|---|---|---|---|
| Loading invoices... | ||||
Audit Log
Immutable record of all security events, scans, and administrative actions
Filters
Events
Data Export & Privacy
GDPR-compliant data export and deletion — your data, your control
Export Your Data
Under GDPR Article 20, you have the right to receive your personal data in a structured, machine-readable format.
Delete Your Data
Under GDPR Article 17 (Right to Erasure), you can request deletion of all your personal data. This action is irreversible.
Compliance & Certifications
SOC 2 Type II and ISO 27001 control evidence mapped to QCrypton capabilities
SOC 2 Type II Controls
| Control | Description | Status | Evidence |
|---|
ISO 27001 Controls
| Control | Description | Status | Evidence |
|---|
PCI-DSS 4.0.1 Controls
| Control | Description | Status | Evidence |
|---|
HIPAA Security Rule Controls
| Control | Description | Status | Evidence |
|---|
Risk & SLA Dashboard
Contextual risk scoring, business context, finding lifecycle, SLA tracking, and uptime metrics
Top Priority Findings
| Rule | Asset | Score | Priority | Status | SLA |
|---|
Asset Registry
Discover, track, and manage software assets with ownership, dependencies, and business context
Auto-Discovery
Auto-discover repositories, dependencies, containers, and microservices from connected integrations.
Register Asset
Assets
| Name | Type | Source | Criticality | Classification | Environment | Tags | Dependencies | Owner |
|---|
Findings
Finding lifecycle with contextual risk scoring, deduplication, and SLA enforcement
Open Findings
| Rule | Severity | Score | Priority | Status | Occurrences | SLA | Assignee |
|---|
Compensating Controls
Define mitigations that quantitatively reduce contextual risk scores
Add Control
Controls
| Name | Type | Reduction | Enabled |
|---|
Vault & Secrets
Encrypted storage, Shamir secret sharing, and HPKE hybrid encryption
Store Secret
Stored Secrets
| Name | Version | Tags | Created | Actions |
|---|
Vault & Secrets
Encrypted storage, Shamir secret sharing, and HPKE hybrid encryption
Split Secret
Combine Shares
Paste the JSON shares array from the split result above, or click "From Split Above" to auto-fill. Any k shares (matching the threshold) will reconstruct the original secret.
SIEM Forwarding
Forward audit events to external SIEM systems in Syslog, CEF, or JSON format
Configure SIEM
Delivery Stats
PQC Performance Benchmarks
Compare NIST post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA, XMSS) against classical crypto — with lattice-based algorithm focus
Run Benchmarks
Quantum Attack Cost Explorer
FTQC resource analysis: physical qubits, T-gates, and runtime for quantum attacks on 28 cryptographic algorithms with timeline scenario presets
Algorithm Comparison
| Algorithm | Attack | Logical Qubits | Physical Qubits | Runtime | Status |
|---|
Autonomous PR Generation
AI-powered agentic remediation — analyzes code, reasons about fixes, and opens pull requests automatically
Remediation Agent
The remediation agent uses AI to analyze your codebase, reason about the safest fix for each finding, generate patches, and open PRs — behaving like an expert AppSec engineer. Supports Claude, GPT, Gemini, and local models (Ollama).
Create Remediation PR (Manual)
Manually target a specific repository and branch. Bundles open scan findings above your chosen risk level into a single PR. Use this when you want direct control over where patches are pushed.
Remediation PRs
| Repo | Platform | Branch | Patches | Status | PR | Created | Actions |
|---|
Vault & Secrets
Encrypted storage, Shamir secret sharing, and HPKE hybrid encryption
Generate Key Pair
Generate an X25519 key pair for HPKE operations.
Encrypt (Seal)
Decrypt (Open)
CNSA 2.0 Compliance
Validate cryptographic posture against NSA CNSA Suite 2.0 requirements and migration timelines
Run Compliance Check
CNSA 2.0 Timeline
Approved Algorithms
| Algorithm | FIPS | Category | Deadline | Notes |
|---|
Federal Compliance Mandates
Track compliance against OMB M-23-02, NSM-10, EO 14028, NIST IR 8547, and CNSA 2.0 with unified timeline
Run Federal Compliance Check
Mandate Compliance Scores
Unified Compliance Timeline
Financial Risk Quantification
Board Number model — translate quantum exposure into dollar-denominated financial risk for board and CISO reporting
Calculate Board Number
Scenario Comparison
Cryptographic Debt Score
7-factor weighted risk model — quantify how much cryptographic technical debt your organization carries
Calculate Crypto Debt
Factor Breakdown
HNDL Exposure Analysis
Harvest Now, Decrypt Later — identify data that will outlive its cryptographic protection window
Check HNDL Exposure
Exposure Timeline
Timeline Scenario Analysis
Compare quantum attack feasibility across Early (2027), Planning (2030), and Late (2038) CRQC arrival scenarios
Compare Scenarios
Physical Qubits by Scenario
Slack Integration
Send threat alerts, finding assignments, SLA breaches, and PR status updates to Slack
Add Slack Webhook
Configured Webhooks
| Name | Channel | Events | Deliveries | Last Sent | Enabled | Actions |
|---|
Supported Events
| Event | Description |
|---|---|
threat_critical | Critical or suspicious threat detected during scanning |
finding_assigned | A security finding is assigned to a team member |
sla_breach | A finding breaches its SLA remediation deadline |
pr_created | An autonomous remediation PR is opened on GitHub |
* | All events (wildcard) |
Unified Findings
Aggregated, deduplicated view across all 13 scanners with cross-scanner correlation
All Findings
| Scanner | Rule | Severity | Risk Score | Asset | Status | Occurrences | First Seen | Assignee | Reachable |
|---|
Intelligence Graph
Vulnerability correlation with exploitability, code reachability, and business context
Attack Path Visualization
Reachability Analysis
| Vulnerability | Asset | Reachable | Exploit Available | Business Impact | True Risk | Action |
|---|
Jira Integration
Create tickets from findings, sync status bidirectionally, and track remediation in Jira
Connection Settings
Ticket Mapping
Recent Tickets
| Ticket | Finding | Severity | Status | Assignee | Created |
|---|---|---|---|---|---|
| Connect Jira to see synced tickets | |||||
Workflow Automation
Auto-assign findings, escalate SLA breaches, create Jira tickets, and enforce CI/CD gates
Automation Rules
Auto-Assign to Asset Owner
Automatically assign new findings to the registered owner of the affected asset
SLA Breach Escalation
Send Slack alert and email to team lead when a finding breaches its SLA deadline
Auto-Create Jira Tickets
Automatically create Jira tickets for critical and high severity findings
Auto-Generate Remediation PRs
Trigger autonomous PR generation for crypto findings with known fixes
Slack Notifications for New Findings
Post to configured Slack channel when new critical or high findings are detected
CI/CD Gate Enforcement
Block deployments when open critical findings exist on the target asset
Auto-Close Verified Remediations
Automatically close findings when the next scan confirms the fix is deployed
Microsoft Teams Notifications
Send alerts to Microsoft Teams channel via webhook for threat detections
Automation Log
| Time | Rule | Action | Finding | Result |
|---|
AI Triage Agent
Autonomous AI-powered vulnerability validation, false positive elimination, and intelligent prioritization
Triage Queue
Positive
RSA-2048 in TLS handshake — payment-api
Severity: Critical • Confidence: 96%
Positive
MD5 usage detected — logging-service
Severity: High • Confidence: 91%
Review
ECDSA-P256 in JWT signing — auth-service
Severity: Critical • Confidence: 68%
Positive
Prompt injection pattern detected — docs-search
Severity: High • Confidence: 88%
False Positive Management
ML-based noise collapse that learns from your team's triage decisions to auto-suppress false positives over time
Learned Suppression Patterns
Recent Suppressions
| Finding | Pattern | Confidence | Suppressed | Override |
|---|---|---|---|---|
| SHA-1 in test/crypto.test.js | Test file weak crypto | 94% | 2026-05-23 | |
| MD5 in cache-warmer.js:28 | Non-security checksum | 97% | 2026-05-23 | |
| "ignore instructions" in docs/security.md | Documentation string | 92% | 2026-05-22 |
Dependency Graph
Visual SBOM dependency tree with vulnerability overlay and transitive risk analysis
Dependency Tree
Vulnerable Dependencies
| Package | Version | Vulnerability | Severity | Fix Version | Depth |
|---|
Integrations
Connect QCrypton with your existing tools — Slack, Jira, SIEM, IDE extensions, and more
Slack
Real-time alerts for threats, assignments, SLA breaches, and PR status
ConfiguredJira
Auto-create tickets, bidirectional sync, severity-based priority mapping
Not ConnectedSIEM Forwarding
Forward audit events in Syslog, CEF, or JSON to Splunk, Elastic, or ArcSight
Not ConfiguredIDE Extensions
VS Code, JetBrains, Cursor, Windsurf, GitHub Copilot, Neovim
AvailableGitHub
Autonomous PR generation, repository scanning, branch management
ConnectedSSO / SAML / OIDC
Google, GitHub, Azure AD, Okta single sign-on configuration
AvailableMicrosoft Teams
Threat notifications and finding alerts via Teams webhooks
Coming SoonShopline Integration
Threats, personalized quantum intel, and board-number risk derived from connected Shopline stores
Detected Threats
| Severity | Title | Category | Shop | IP | Risk | Detected |
|---|
Impact on your posture
0 algorithm(s) you runGlobal quantum milestones
0 entriesCrypto debt by algorithm
Harvest-now-decrypt-later exposure
Installed merchants
| Merchant | Shop | Plan | Onboarding | OAuth | HPKE | Threats | Orders | MCP keys | Joined |
|---|
MCP server manifest
Issued MCP keys
| Label | Prefix | Shop | Status | Last used | Created |
|---|
IDE Extensions & Developer Assist
Real-time security guidance directly in your editor as you code
Available Extensions
VS Code
Inline vulnerability alerts, auto-fix suggestions, and PQC migration hints as you type.
JetBrains (IntelliJ/WebStorm)
Gutter icons for weak crypto, intention actions for migration, and CNSA 2.0 compliance checks.
Cursor
AI-assisted remediation with QCrypton context. Cursor Agent auto-generates PQC migration code.
Windsurf
Cascade flow integration for end-to-end crypto remediation with QCrypton security context.
GitHub Copilot
Custom Copilot agent that surfaces QCrypton findings inline and suggests quantum-safe alternatives.
Neovim / CLI
Terminal-native scanning with npx qcrypton scan. LSP integration for Neovim diagnostics.
Configuration
QKD / BB84 Key Distribution
Quantum key distribution using the BB84 protocol with enhanced eavesdrop detection and AES-256-GCM secret wrapping
BB84 Key Exchange
Wrap Secret with QKD Key
Unwrap Secret
Crypto Threat Intelligence
Track quantum computing milestones and dynamic threat timelines for cryptographic algorithms
Threat Timeline by Algorithm
| Algorithm | Optimistic | Realistic | Conservative | Years Left | Urgency | Risk Multiplier |
|---|
Algorithm Lookup
Quantum Computing Milestones
| Date | Source | Event | Qubits | Category | Timeline Impact |
|---|
Runtime TLS Crypto Monitor
Probe live TLS endpoints to assess cipher suites, certificate chains, and quantum vulnerability
Single Endpoint Probe
Batch Scan
TLS Posture Summary
| Date | Verdict | Risk Score | Findings |
|---|
Supply Chain Crypto Audit
Scan dependency manifests to identify quantum-vulnerable cryptographic packages across your supply chain
Project Scan
Manifest Audit
Supply Chain Risk Summary
Crypto Package Database
75+ packages tracked across npm, pip, Go, Cargo, and Maven with quantum vulnerability assessments.
Autonomous PQC Migration Agent
AI-driven workflow: inventory crypto, map dependencies, plan migration order, and generate sequential PRs
Launch Migration Agent
Migration Agents
| Agent ID | Repo | Status | Progress | Created | Actions |
|---|
Agent Workflow
Inventory
Scan repo for all crypto algorithm usage across 6 languages
Dependency Map
AI identifies crypto dependency chains (key generation → usage)
Migration Plan
AI plans ordered steps: leaf-first, auto-fix before manual
Execute PRs
Generate remediation PRs in sequence via GitHub
Natural Language Console
Drive security workflows using natural language — AI resolves intents and dispatches API calls
Ask QCrypton
Available Intents
Predictive Models
ML-based forecasting for quantum timelines, MTTR trends, and risk score trajectories
Quantum Timeline Forecast
MTTR Trend Forecast
Risk Score Trajectory
Parallel Sweep Engine
Org-wide concurrent security scanning across repositories, endpoints, and supply chains
Launch Sweep
Recent Sweeps
| ID | Type | Status | Progress | Started | |
|---|---|---|---|---|---|
| No sweeps yet | |||||
Migration Optimizer
Evaluate cost/risk tradeoffs across PQC migration strategies to find the optimal migration order
Available Strategies
Risk-First
Migrate highest-risk algorithms first to minimize quantum exposure window
Low-Effort First
Start with quick wins to build momentum and reduce finding count early
Dependency-First
Migrate leaf dependencies first to avoid rework in upstream consumers
Balanced
Equal weighting across urgency, exposure, effort, and dependencies
Optimize Migration Plan
Findings are auto-loaded from your Code Scanner results. You can also paste custom findings or load demo data.
Compare Two Strategies
PQC Readiness Maturity Model
5-dimension assessment of your organization's post-quantum cryptographic readiness
Overall Maturity
Dimension Details
Recommended Next Actions
- Run an assessment to see recommendations.
PQC Solution Scoring Registry
Independent scoring of post-quantum cryptography implementations across 10 quality dimensions
Leaderboard
| # | Implementation | Vendor | Type | Score | Algorithms |
|---|
Evidence Package Generator
Compile security evidence into a structured bundle for auditors, regulators, and cyber insurers