VPQ Audit · Post-quantum readiness assessment

You cannot migrate cryptography you cannot see.

Everyone else is selling a platform to manage the migration. We do the part that has to happen first: read what is actually on the wire, and hand back an inventory you can act on. One capture in, one report out. Nothing is installed anywhere.

HNDL scoring · how the risk is composed
V × S × R × EHNDL risk
“Endpoint uses RSA, therefore HIGH” is not a score.
641
Automated tests passing in the Enterprise build.
203 / 204 / 205
NIST standards covered — ML-KEM, ML-DSA and SLH-DSA — plus hybrid X25519MLKEM768 and CNSA 2.0.
CycloneDX 1.7
CBOM output, with SARIF for the pipelines that want findings instead of a document.
V × S × R × E
Harvest-now-decrypt-later scoring: vulnerability, data sensitivity, retention period, exposure.
What it reads

Three things
a spreadsheet
cannot tell you.

HNDL Radar

Reads a packet capture, parses the handshakes and scores what an adversary recording today could decrypt later. "Endpoint uses RSA, therefore HIGH" is a crude answer — risk is the vulnerability multiplied by how sensitive the data is, how long you are legally required to keep it, and how exposed the path is.

PKI hierarchy reconstruction

Rebuilds the trust chain from root through intermediates to leaf certificates and ranks the migration impact of each node. Migrating a mid-tier CA while the leaves below it stay classical is the failure nobody plans for, because nobody drew the tree first.

Benchmarks on your hardware

Classical against hybrid against pure post-quantum, measured on the machines you actually run, so the latency and key-size trade-off is a number in your environment rather than a claim in a vendor deck.


For consultancies and auditors

We are the instrument,
you keep the client.

You run the readiness engagement. We produce the on-wire inventory inside it — nothing installed at your client, and the relationship stays yours.

Post-quantum readiness is being written into mandates faster than the tooling layer can staff for it. Advisory firms are winning the engagements and then discovering that the inventory step needs instrumentation nobody on the team owns. That step is what we do, as a subcontracted measurement, delivered under your report.

What stays open, what stays closed

Open, because you have to be able to check it: what we measure — the standards covered, the scoring formula, the output fields, the protocols parsed. Closed, because it is the only thing we cannot hire twice: how the analysis engine is built.


Scope

What this is not.

Not an offensive tool

VPQ Audit is defensive and compliance-oriented — the same category as an SBOM scanner. It reads configuration and traffic you already own. It does not break, harvest or exploit anything.

It does not scan everything

Network, transport, certificates, PKI and source are covered. Endpoint binaries, mainframe, infrastructure-as-code and cloud KMS are not — we would rather name the gap than let you find it halfway through an engagement.

Not certified

We are not TCVN-certified and we do not claim to be. Community edition v0.4.0 is public under MIT; Enterprise is in pilot and pre-production.

Regulatory context, not regulatory advice

The output is built to sit inside work governed by NIST, CNSA 2.0 and, in Vietnam, TCVN 11930, NHNN 09/2020 and Decree 85/2016. Interpreting those for your institution remains your counsel's job.


Start with one capture.

Send a representative capture or point us at one segment. You get the inventory, the HNDL scoring and the CBOM back as a report you can put in front of a client or a regulator — under your name if that is the arrangement.