Skip to main content
← Home
Notifications
🔎
0 Total Scans
0 Findings
🛡
0 Threats Blocked
0 Active Policies
--
Posture Score
--
--
Open Findings
--
SLA Compliance
--
Compliance Coverage
--
Quantum Readiness
--
MTTR Performance
--
Remediation Rate

Scan Distribution

Threat Verdicts

Key Performance Indicators

Remediation Burn-Down

--Today

Recent Activity

No activity yet. Run a scan to get started.

HNDL Portfolio Exposure

--Exposed Assets
--Exposure Rate
--Avg HNDL Window
--Data at Risk
Critical High Medium Low

Scan Input

Tool Definition (JSON)

Payload to Inspect

Server Configuration (JSON)

Why Quantum Code Scanning Matters

Quantum computers running Shor's algorithm will break RSA and ECC encryption protecting payment cards, financial transactions, and sensitive data. The Harvest Now, Decrypt Later (HNDL) threat means adversaries are already capturing encrypted data today, planning to decrypt it once quantum hardware matures. NIST has finalized post-quantum cryptography standards (ML-KEM, ML-DSA, SLH-DSA) — migration should begin now.

System Quantum Configuration (JSON)

Quantum Threat Remediation

PQC Migration & Correction

Generate a remediation plan based on the current quantum scan. Recommends PQC algorithm replacements, per-finding fixes, migration steps, and a corrected configuration for re-scanning.

Scan Input

Scan Input

Scan Input

Scan Input

Scan Input

Scan Input

12 Noise Types
6 QEC Codes
🔎
720 Evaluations / Scan
🔧
24 Compensating Controls

Noise Reachability Scan

Noise Threat Remediation

QEC Correction & Mitigation

Generate a remediation plan based on the current noise scan. Recommends optimal QEC codes, per-error fixes, hardware upgrades, and a corrected configuration for re-scanning.

🔎
262 Detection Patterns
6 Languages
10 Vulnerability Types
🛡
26 Secret Patterns

Scan Code Snippet

Crypto Threat Remediation

Auto-Fix & PQC Migration

Generate a remediation plan based on the current code scan. Auto-patches weak algorithms (MD5, SHA-1, DES, RC4, AES-ECB) with quantum-safe replacements, and flags asymmetric algorithms (RSA, ECDSA, Ed25519) that require manual PQC migration.

⚛ Quantum Threats

Quantum HNDL

Harvest encrypted data now, decrypt with future quantum computers

Critical
🔐

Shor's Algorithm (RSA)

Factor RSA-2048 keys using 4,098 logical qubits to break TLS and signatures

Critical
🔐

Shor's Algorithm (ECC)

Compute elliptic curve discrete log to break ECDSA, ECDH, and Ed25519

Critical
🔍

Grover's Key Search

Halve effective key length of AES-128 and 3DES via quantum brute-force

High
🌊

Depolarizing Channel Attack

Exploit quantum channel noise to corrupt qubits past QEC correction threshold

Critical

Cosmic Ray Burst

Correlated multi-qubit errors from high-energy particle strikes defeat standard QEC

Critical
🔄

Qubit Crosstalk Exploit

Induce correlated gate errors between adjacent qubits to propagate past surface code

High

PQC Migration Gap

Exploit systems stuck in partial PQC migration with mixed classical/quantum crypto

High

🔎 Crypto Threats

🔎

Weak Algorithm Exploitation

Exploit MD5, SHA-1, DES, RC4 weaknesses to forge hashes or decrypt data

Critical
🔑

Hardcoded Key Extraction

Extract encryption keys, API secrets, and tokens embedded in source code

Critical
🔄

Nonce Reuse / IV Attack

Exploit static IVs in AES-GCM to recover authentication key and decrypt traffic

Critical
🔏

Padding Oracle

Decrypt AES-CBC ciphertext one byte at a time via padding error side-channel

High

⚠ General Threats

$

Pricing Manipulation

Override pricing calculations via prompt injection to bypass charges

Critical

Data Poisoning

Inject false data through compromised MCP tools

Critical
💳

Card Data Theft

Exfiltrate payment card data to external servers

Critical
📍

Location Tracking

Extract real-time user GPS and location records

High
😈

MCP Rug Pull

Tool activates malicious behavior after gaining trust

Critical
🔒

Brute-Force Attack

Automated password guessing against accounts and PINs

Critical
👤

Credential Stuffing

Reuse leaked breach credentials to compromise accounts at scale

Critical
📖

Dictionary Attack

Crack passwords using wordlists and mutation rules

Critical
🎣

Phishing Campaign

Mass phishing emails impersonating legitimate services to harvest card data

Critical
👁

Payment Keylogger

Magecart-style script injected on payment pages to steal card data

Critical

💳 Card Fraud

🔁

Physical Card Swap

Distraction-based card swap at payment terminal to steal debit/credit cards

Critical
📡

NFC Relay Attack

Relay contactless card signal to remote terminal for unauthorized payments

Critical
🕳

Card Skimming

Install skimming device on payment terminal to capture card data and PINs

Critical
📱

Digital Wallet Hijack

Provision stolen card into attacker mobile wallet via SIM swap

Critical
🔢

BIN Attack / Carding

Generate valid card numbers from BIN and test with micro-transactions

Critical

🤖 ASPM & Agentic Threats

🤖

AI Triage Evasion

Craft findings that trick the AI triage agent into marking true positives as false positives

Critical
🔈

Noise Collapse Poisoning

Systematically mark true positives as false positives to corrupt the learned suppression model

Critical
🚀

Remediation PR Injection

Manipulate autonomous PR generation to inject backdoors via crafted code patches

Critical
📦

Dependency Confusion

Upload malicious package with same name as internal dependency to public registry

Critical

Workflow Rule Bypass

Manipulate finding severity to avoid auto-assignment, SLA tracking, and Jira ticket creation

High

CNSA 2.0 Deadline Exploit

Exploit organizations in partial CNSA 2.0 migration with mixed approved/deprecated algorithms

High
📋

SBOM Tampering

Modify CycloneDX SBOM to hide vulnerable dependencies from the dependency graph

High
🚫

Finding Suppression Abuse

Abuse risk acceptance workflow to suppress critical findings without compensating controls

High

NIST PQC Standards (FIPS 203, 204, 205)

NIST has finalized three post-quantum cryptographic standards: ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) for digital signatures, and SLH-DSA (FIPS 205) for hash-based signatures. Organizations should begin migrating from RSA, ECC, and classical Diffie-Hellman to these quantum-resistant algorithms immediately.

🔎
3 NIST Standards
5 Migration Phases
12 Vulnerable Algorithms
🔧
6 PQC Replacements

Migration Readiness Assessment

🔧

Detect → Fix → Verify

QCrypton doesn't just find problems — it fixes them. Noise Reachability Remediation generates QEC correction plans for quantum noise threats. Input Sanitization strips injection and exfiltration patterns. Config Remediation corrects insecure server configurations. Code Remediation patches weak cryptographic algorithms with quantum-safe alternatives.

Noise Reachability Remediation

Input Sanitization

Config Remediation

Code Remediation

Create New Policy

Active Policies

0

Loading policies...

📈
-- Uptime (30d)
-- Avg Response Time
📈
-- P99 Latency
0 Incidents (30d)

SLA Guarantees by Plan

MetricLargeEnterprise
Uptime SLA99.9%99.99%
API Response Time< 200ms (P95)< 100ms (P95)
Scan Throughput200K queries/moUnlimited
Support SLA4h response1h response + dedicated manager
Incident Resolution8h target2h target
Data Retention90 days1 year + custom

Uptime History (Last 90 Days)

90 days agoToday

Recent Incidents

No incidents in the last 30 days

📊
-- API Queries (this month)
📈
-- Quota Used
👥
-- Active Users (30d)
-- Most Used Scanner

API Usage by Scanner

Daily Query Volume (Last 30 Days)

30 days agoToday

Team Activity

Loading team activity...

Invite Team Member

👥
0 Total Users
0 Active
🔒
0 Verified
🕐
0 Logged In Recently
🏢
0 Tenants

User Registrations

Setup Checklist

0 / 9 complete

Generate API Key

Create your first API key to authenticate scan requests

Run First Scan

Scan a code snippet or configuration for threats

Assess Quantum Readiness

Scan your cryptographic configuration for quantum vulnerabilities

Check CNSA 2.0 Compliance

Validate your crypto posture against NSA CNSA Suite 2.0 requirements

Connect GitHub

Enable autonomous PR generation to auto-fix weak crypto in your repos

Connect Slack

Get real-time alerts for threats, assignments, and SLA breaches

Configure Webhook

Send scan results to your SIEM or notification channel

Invite Your Team

Add team members with role-based access

Integrate CI/CD Gate

Add QCrypton security gate to your build pipeline

Quick Start Code

curl -X POST https://your-instance.qcrypton.com/api/scan/quantum \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"config":{"name":"my-system","algorithms":[{"name":"RSA-2048","usage":"TLS"}],"tls":"TLS 1.2"}}'

Brand Settings

Preview

QCrypton
Quantum-Resilient Threat Detection & Remediation Platform
Primary
Accent

Mean Time to Remediate (MTTR)

4.2h
Critical MTTR
18.5h
High MTTR
3.2d
Medium MTTR
7.8d
Low MTTR

Security Posture Trend (30 days)

30 days agoToday

Compliance Framework Mapping

92%

SOC 2 Type II

41 / 44 controls met

87%

ISO 27001

98 / 114 controls met

78%

PCI-DSS v4.0

188 / 241 requirements met

95%

NIST CSF 2.0

108 / 114 subcategories met

83%

HIPAA

42 / 50 safeguards met

91%

CNSA 2.0

Phase 1 compliant

Generate Report

Scheduled Digests

Automatically send scan summaries and threat alerts to your team via email.

Active SSO Providers

G

Google

Not Configured
🐙

GitHub

Not Configured

Azure AD

Not Configured
O

Okta

Not Configured

Configure Provider

Callback URLs

Add these URLs to your OAuth provider's authorized redirect URIs:

https://your-instance.qcrypton.com/auth/google/callback Google
https://your-instance.qcrypton.com/auth/github/callback GitHub
https://your-instance.qcrypton.com/auth/azure/callback Azure AD
https://your-instance.qcrypton.com/auth/okta/callback Okta
💳
-- Current Plan
💰
-- Billed Annually
📅
-- Next Renewal
📊
-- Quota Used

Payment Method

Loading payment methods...

Accepted: Visa, Mastercard, American Express, Discover, Diners Club, JCB, UnionPay. Card details are securely handled by Stripe — they never touch our servers.

Invoices

DateDescriptionAmountStatusAction
Loading invoices...

Filters

Events

sarah.chen@company.com 2026-05-23 14:32:18
Policy Changed Updated CI/CD gate policy — added min PQC readiness score
- "minPqcScore": 60 + "minPqcScore": 80 - "failOnWeak": false + "failOnWeak": true
mike.johnson@company.com 2026-05-23 12:15:03
Finding Updated Accepted risk for TLS 1.0 on legacy-proxy — compensating control WAF added
- status: "open" + status: "risk_accepted" + acceptedBy: "mike.johnson@company.com" + compensatingControl: "WAF-001"
system 2026-05-23 11:00:00
SLA Breach Finding ECDSA-P256 in auth-service exceeded 72h remediation SLA
ci-bot 2026-05-22 16:45:22
Auto-Remediation PR #42 merged — replaced DES cipher with AES-256-GCM in config-service
- algorithm: "DES" + algorithm: "AES-256-GCM" - keySize: 56 + keySize: 256
admin@company.com 2026-05-22 09:30:11
Team Updated Added platform-team@company.com as Security Engineer
system 2026-05-21 22:00:00
Scan Complete Nightly quantum scan completed — 3 new findings, 2 remediated

Export Your Data

Under GDPR Article 20, you have the right to receive your personal data in a structured, machine-readable format.

Delete Your Data

Under GDPR Article 17 (Right to Erasure), you can request deletion of all your personal data. This action is irreversible.

SOC 2 Type II Controls

ControlDescriptionStatusEvidence

ISO 27001 Controls

ControlDescriptionStatusEvidence

PCI-DSS 4.0.1 Controls

ControlDescriptionStatusEvidence

HIPAA Security Rule Controls

ControlDescriptionStatusEvidence
📈
99.97%Uptime (30d)
42msAvg Response
📈
187msP99 Latency
1Incidents (30d)
📈
0 Total Findings
0 Avg Contextual Risk
0 SLA Breaches
🔀
0 Duplicates Suppressed

Top Priority Findings

RuleAssetScorePriorityStatusSLA

Auto-Discovery

Auto-discover repositories, dependencies, containers, and microservices from connected integrations.

Register Asset

Assets

NameTypeSourceCriticalityClassificationEnvironmentTagsDependenciesOwner

Open Findings

RuleSeverityScorePriorityStatusOccurrencesSLAAssignee

Add Control

Controls

NameTypeReductionEnabled

Store Secret

Stored Secrets

NameVersionTagsCreatedActions

Split Secret

Combine Shares

Paste the JSON shares array from the split result above, or click "From Split Above" to auto-fill. Any k shares (matching the threshold) will reconstruct the original secret.

Configure SIEM

Delivery Stats

📡
0 Events Sent
0 Failed
🕑
- Last Sent

Run Benchmarks

Algorithm Comparison

AlgorithmAttackLogical QubitsPhysical QubitsRuntimeStatus

Remediation Agent

Idle

The remediation agent uses AI to analyze your codebase, reason about the safest fix for each finding, generate patches, and open PRs — behaving like an expert AppSec engineer. Supports Claude, GPT, Gemini, and local models (Ollama).

Create Remediation PR (Manual)

Manually target a specific repository and branch. Bundles open scan findings above your chosen risk level into a single PR. Use this when you want direct control over where patches are pushed.

Remediation PRs

RepoPlatformBranchPatchesStatusPRCreatedActions

Generate Key Pair

Generate an X25519 key pair for HPKE operations.

Encrypt (Seal)

Decrypt (Open)

Run Compliance Check

CNSA 2.0 Timeline

Approved Algorithms

AlgorithmFIPSCategoryDeadlineNotes

Run Federal Compliance Check

Mandate Compliance Scores

OMB M-23-02
--
NSM-10
--
EO 14028
--
NIST IR 8547
--

Unified Compliance Timeline

Calculate Board Number

Calculate Crypto Debt

Check HNDL Exposure

Compare Scenarios

Add Slack Webhook

Configured Webhooks

NameChannelEventsDeliveriesLast SentEnabledActions

Supported Events

EventDescription
threat_criticalCritical or suspicious threat detected during scanning
finding_assignedA security finding is assigned to a team member
sla_breachA finding breaches its SLA remediation deadline
pr_createdAn autonomous remediation PR is opened on GitHub
*All events (wildcard)

All Findings

Saved:
0 findings
0 duplicates suppressed
ScannerRuleSeverityRisk ScoreAssetStatusOccurrencesFirst SeenAssigneeReachable
12
Critical Attack Paths
34
Reachable Vulnerabilities
8
Assets at Risk
156
False Positives Eliminated

Attack Path Visualization

Vulnerability
Asset
Exploit Available
Mitigated
Data Flow

Reachability Analysis

VulnerabilityAssetReachableExploit AvailableBusiness ImpactTrue RiskAction

Connection Settings

Not Connected

Ticket Mapping

Recent Tickets

TicketFindingSeverityStatusAssigneeCreated
Connect Jira to see synced tickets

Automation Rules

👥

Auto-Assign to Asset Owner

Automatically assign new findings to the registered owner of the affected asset

🚨

SLA Breach Escalation

Send Slack alert and email to team lead when a finding breaches its SLA deadline

📋

Auto-Create Jira Tickets

Automatically create Jira tickets for critical and high severity findings

🚀

Auto-Generate Remediation PRs

Trigger autonomous PR generation for crypto findings with known fixes

💬

Slack Notifications for New Findings

Post to configured Slack channel when new critical or high findings are detected

CI/CD Gate Enforcement

Block deployments when open critical findings exist on the target asset

🕑

Auto-Close Verified Remediations

Automatically close findings when the next scan confirms the fix is deployed

📨

Microsoft Teams Notifications

Send alerts to Microsoft Teams channel via webhook for threat detections

Automation Log

TimeRuleActionFindingResult
🤖
247Findings Triaged
💡
156False Positives Removed
78True Positives Confirmed
🕒
42hTime Saved

Triage Queue

True
Positive

RSA-2048 in TLS handshake — payment-api

Severity: Critical • Confidence: 96%

AI Reasoning: RSA-2048 key exchange is directly reachable via public TLS endpoint. Shor's algorithm reduces 2048-bit factoring to polynomial time on FTQC hardware (est. 4,098 logical qubits). The asset handles PCI cardholder data, making HNDL attacks a concrete threat. No compensating controls detected.
False
Positive

MD5 usage detected — logging-service

Severity: High • Confidence: 91%

AI Reasoning: MD5 is used solely for non-security log deduplication checksums (line 142 in logger.js). No passwords, tokens, or sensitive data are hashed. The function is not reachable from any external endpoint. Suppressing as non-exploitable.
Needs
Review

ECDSA-P256 in JWT signing — auth-service

Severity: Critical • Confidence: 68%

AI Reasoning: ECDSA-P256 is quantum-vulnerable, but JWT tokens have a 15-minute TTL which limits HNDL exposure. The migration path to ML-DSA requires HSM firmware update (Entrust nShield). Unable to determine if HSM is already scheduled for upgrade. Human review recommended.
False
Positive

Prompt injection pattern detected — docs-search

Severity: High • Confidence: 88%

AI Reasoning: The flagged string "ignore previous instructions" appears in a user-facing help article explaining prompt injection attacks. It is static content, not user input. The search index does not pass content to any LLM. No injection vector exists.
63%
Noise Reduction Rate
892
Patterns Learned
156
Suppressions This Month
99.2%
Precision (no missed TPs)

Learned Suppression Patterns

MD5 used for non-security checksums (logging, caching)412 suppressions
Test files containing intentional weak crypto for unit tests187 suppressions
Documentation strings mentioning attack patterns98 suppressions
Deprecated endpoints behind feature flags (not reachable)74 suppressions
Internal-only services with network segmentation63 suppressions
Vendor SDK using weak crypto internally (no user data)41 suppressions
Comments/strings matching injection regex but not executable17 suppressions

Recent Suppressions

FindingPatternConfidenceSuppressedOverride
SHA-1 in test/crypto.test.jsTest file weak crypto94%2026-05-23
MD5 in cache-warmer.js:28Non-security checksum97%2026-05-23
"ignore instructions" in docs/security.mdDocumentation string92%2026-05-22
📦
--Total Dependencies
--Vulnerable Packages
🔗
--Transitive Risks
--PQC-Ready

Dependency Tree

Secure
Outdated
Vulnerable
Quantum-Vulnerable

Vulnerable Dependencies

PackageVersionVulnerabilitySeverityFix VersionDepth
💬

Slack

Real-time alerts for threats, assignments, SLA breaches, and PR status

Configured
📋

Jira

Auto-create tickets, bidirectional sync, severity-based priority mapping

Not Connected
📡

SIEM Forwarding

Forward audit events in Syslog, CEF, or JSON to Splunk, Elastic, or ArcSight

Not Configured
💻

IDE Extensions

VS Code, JetBrains, Cursor, Windsurf, GitHub Copilot, Neovim

Available
🐙

GitHub

Autonomous PR generation, repository scanning, branch management

Connected
🔒

SSO / SAML / OIDC

Google, GitHub, Azure AD, Okta single sign-on configuration

Available
📩

Microsoft Teams

Threat notifications and finding alerts via Teams webhooks

Coming Soon
🛡
0 Total Threats
0 Critical
0 High
🔎
0 Medium / Low

Detected Threats

Severity Title Category Shop IP Risk Detected

Impact on your posture

0 algorithm(s) you run

Global quantum milestones

0 entries
👥
0 Total merchants
🔗
0 Shopline connected
0 Fully onboarded
0 On trial
💰
0 Paying

Installed merchants

Merchant Shop Plan Onboarding OAuth HPKE Threats Orders MCP keys Joined
🔑
0 Active MCP keys
🔒
0 Total issued
📈
0 Tool calls (all-time)
🌐
0 Merchants with MCP on

MCP server manifest

Issued MCP keys

Label Prefix Shop Status Last used Created

Available Extensions

🔸

VS Code

Inline vulnerability alerts, auto-fix suggestions, and PQC migration hints as you type.

JetBrains (IntelliJ/WebStorm)

Gutter icons for weak crypto, intention actions for migration, and CNSA 2.0 compliance checks.

💫

Cursor

AI-assisted remediation with QCrypton context. Cursor Agent auto-generates PQC migration code.

🌊

Windsurf

Cascade flow integration for end-to-end crypto remediation with QCrypton security context.

🐙

GitHub Copilot

Custom Copilot agent that surfaces QCrypton findings inline and suggests quantum-safe alternatives.

💻

Neovim / CLI

Terminal-native scanning with npx qcrypton scan. LSP integration for Neovim diagnostics.

Configuration

BB84 Key Exchange

Wrap Secret with QKD Key

Unwrap Secret

🌐
25 Quantum Milestones
5 High-Urgency Algorithms
📅
~2035 RSA Break (Realistic)
📈
-- Last Updated

Threat Timeline by Algorithm

AlgorithmOptimisticRealisticConservativeYears LeftUrgencyRisk Multiplier

Algorithm Lookup

Quantum Computing Milestones

DateSourceEventQubitsCategoryTimeline Impact

Single Endpoint Probe

Batch Scan

TLS Posture Summary

🔒
--Total Scans
--Quantum Vulnerable
--PQC Ready
📅
--Certs Expiring Soon
DateVerdictRisk ScoreFindings

Project Scan

Manifest Audit

Supply Chain Risk Summary

📦
--Total Dependencies
--Quantum Vulnerable
🔎
--Crypto Packages
--Ecosystems

Crypto Package Database

75+ packages tracked across npm, pip, Go, Cargo, and Maven with quantum vulnerability assessments.

Launch Migration Agent

Migration Agents

🤖
--Total Agents
--Active
--Completed
--Failed
Agent IDRepoStatusProgressCreatedActions

Agent Workflow

1

Inventory

Scan repo for all crypto algorithm usage across 6 languages

2

Dependency Map

AI identifies crypto dependency chains (key generation → usage)

3

Migration Plan

AI plans ordered steps: leaf-first, auto-fix before manual

4

Execute PRs

Generate remediation PRs in sequence via GitHub

💬
12 Available Intents
0 Queries Run

Ask QCrypton

Try:

Available Intents

-- RSA-2048 Predicted Break
📈
-- Forecasted MTTR (hours)
-- Compliance Target Date
📊
-- Risk Trend

Quantum Timeline Forecast

MTTR Trend Forecast

Risk Score Trajectory

0 Total Sweeps
0 Completed
0 Running

Launch Sweep

Recent Sweeps

IDTypeStatusProgressStarted
No sweeps yet
4 Strategies
📈
-- Recommended

Available Strategies

1

Risk-First

Migrate highest-risk algorithms first to minimize quantum exposure window

2

Low-Effort First

Start with quick wins to build momentum and reduce finding count early

3

Dependency-First

Migrate leaf dependencies first to avoid rework in upstream consumers

4

Balanced

Equal weighting across urgency, exposure, effort, and dependencies

Optimize Migration Plan

Findings are auto-loaded from your Code Scanner results. You can also paste custom findings or load demo data.

Compare Two Strategies

Overall Maturity

--
Level (1-5)
--
Score (0-100)

Dimension Details

Recommended Next Actions

  1. Run an assessment to see recommendations.

Leaderboard

#ImplementationVendorTypeScoreAlgorithms

Configure Package

Compliance Frameworks
Options