Everyone else is selling a platform to manage the migration. We do the part that has to happen first: read what is actually on the wire, and hand back an inventory you can act on. One capture in, one report out. Nothing is installed anywhere.
Reads a packet capture, parses the handshakes and scores what an adversary recording today could decrypt later. "Endpoint uses RSA, therefore HIGH" is a crude answer — risk is the vulnerability multiplied by how sensitive the data is, how long you are legally required to keep it, and how exposed the path is.
Rebuilds the trust chain from root through intermediates to leaf certificates and ranks the migration impact of each node. Migrating a mid-tier CA while the leaves below it stay classical is the failure nobody plans for, because nobody drew the tree first.
Classical against hybrid against pure post-quantum, measured on the machines you actually run, so the latency and key-size trade-off is a number in your environment rather than a claim in a vendor deck.
You run the readiness engagement. We produce the on-wire inventory inside it — nothing installed at your client, and the relationship stays yours.
Post-quantum readiness is being written into mandates faster than the tooling layer can staff for it. Advisory firms are winning the engagements and then discovering that the inventory step needs instrumentation nobody on the team owns. That step is what we do, as a subcontracted measurement, delivered under your report.
Open, because you have to be able to check it: what we measure — the standards covered, the scoring formula, the output fields, the protocols parsed. Closed, because it is the only thing we cannot hire twice: how the analysis engine is built.
VPQ Audit is defensive and compliance-oriented — the same category as an SBOM scanner. It reads configuration and traffic you already own. It does not break, harvest or exploit anything.
Network, transport, certificates, PKI and source are covered. Endpoint binaries, mainframe, infrastructure-as-code and cloud KMS are not — we would rather name the gap than let you find it halfway through an engagement.
We are not TCVN-certified and we do not claim to be. Community edition v0.4.0 is public under MIT; Enterprise is in pilot and pre-production.
The output is built to sit inside work governed by NIST, CNSA 2.0 and, in Vietnam, TCVN 11930, NHNN 09/2020 and Decree 85/2016. Interpreting those for your institution remains your counsel's job.
Send a representative capture or point us at one segment. You get the inventory, the HNDL scoring and the CBOM back as a report you can put in front of a client or a regulator — under your name if that is the arrangement.