RQRelixQ

Enterprise QAST for post-quantum exposure

Own the quantum migration before it owns your roadmap.

RelixQ turns cryptography discovery into an evidence-backed operating system for security and engineering: HNDL exposure windows, attack paths, safe validation, RelixQ Score, reports, tickets, retests, and release gates.

Built for AppSec and platform teamsCISO-facing score and evidenceOSS scanner path stays intact

RelixQ Enterprise

Live product surface

real UI

38

RelixQ Score

104

HNDL-critical

186

open findings

10

integrations

RelixQ Enterprise engineering dashboard showing RelixQ Score, HNDL-critical exposures, next actions, and scan signals.

Engineering

RelixQ Score, findings, next actions

QAST

HNDL register and exposure evidence

Integrations

SIEM and observability delivery

Cryptography is everywhere

Applications, dependencies, certificates, TLS, JWT, SAML, mTLS, build systems, and infrastructure all carry quantum-relevant assumptions.

Inventory is not enough

Security leaders need to know which data can be harvested now, which paths are reachable, and which controls prove risk is going down.

Migration must survive engineering reality

Findings need owners, tickets, retests, exceptions, and PR gates or the same exposure returns after every release.

Why RelixQ

Because quantum migration needs a story the whole company can act on.

RelixQ should make buyers feel the shift immediately: scattered cryptography becomes HNDL exposure, exposure becomes evidence, and evidence becomes controls that keep new risk from entering the roadmap.

186

quantum findings

104

HNDL-critical

12

attack paths

4

control outputs

Animated QAST storyboard

Unknown crypto -> governed migration

live control loop
01Unknown estate

Crypto is scattered across the business

RSA, ECC, DH, TLS, certificates, JWT, SAML, mTLS, dependencies, and custom crypto live in code, services, and infrastructure.

Signal: Blind spot
Output: Crypto inventory
02HNDL exposure

Inventory becomes time-bound risk

RelixQ ranks exposure by harvestability, data lifetime, reachability, confidence, and Mosca windows.

Signal: X + Y > Z
Output: Dated exposure window
03QAST proof

Risk becomes explainable evidence

QAST ties findings to attack paths, safe validation, owner context, recommendations, and honest proof boundaries.

Signal: No decryption claim
Output: Evidence chain
04Control loop

Evidence becomes operating control

The same evidence drives RelixQ Score, reports, tickets, SIEM events, retests, exceptions, and PR gates.

Signal: Regression blocked
Output: Migration control plane
finding.createdscore.deltapr.blocked
Board

Score trend, HNDL exposure, remediation progress

AppSec

Finding evidence, confidence, owner, retest state

Engineering

PR gate, policy baseline, migration target

GRC

Report, accepted risk, audit-ready source chain

Before RelixQ

A spreadsheet of algorithms, unclear owners, no data lifetime, no safe validation, and no release control.

After RelixQ

HNDL register, attack paths, score drivers, reports, tickets, retests, integrations, and PR gates from one evidence chain.

Enterprise narrative

RelixQ has to feel richer because the sale is bigger than a scanner.

The buyer is not only asking "can you find RSA?" They are asking whether RelixQ can help them run a post-quantum migration program: posture, owners, evidence, safe validation, governance, and release control.

regional policy signals
5
product surfaces
8
buyer rooms
4
evidence chain
1

Category map

From unknown crypto to governed migration.

01

Discover

Code, dependencies, TLS, certificates, JWT, SAML, mTLS, infrastructure, and protocol surfaces become one inventory.

02

Prioritize

Findings are ranked by data lifetime, harvestability, reachability, confidence, and score impact instead of raw algorithm count.

03

Validate

Signed-RoE active probes and PQC Lab checks prove negotiation posture without dangerous claims or unauthorized testing.

04

Operate

RelixQ turns the same evidence into score trends, tickets, SIEM events, retests, reports, and PR gates.

Inventory

Crypto evidence

QAST

Exposure and validation

Control plane

Score, gates, reports

Why now

PQC has moved from research to execution pressure

Government roadmaps, national crypto discovery programs, and customer trust reviews are turning quantum inventory into a funded security workstream.

Why RelixQ

The product connects exposure to control

RelixQ does not stop at algorithm discovery. It links findings to HNDL windows, attack paths, safe validation, score movement, tickets, reports, and PR gates.

Why credible

The story is honest about proof boundaries

QAST shows exposure, reachability, harvestability, classical breaks, and modeled quantum cost. It does not claim impossible quantum decryption.

Why buy

Every stakeholder gets an operating artifact

CISOs get posture, AppSec gets evidence, engineers get gates, GRC gets reports, and platform teams get integrations into the tools they already run.

Buyer rooms

One product story, four buying conversations.

CISO

Needs a board-ready score, exposure trend, risk owners, and evidence that the migration is moving.

AppSec

Needs exact findings, confidence, context, recommendations, retest state, and safe validation history.

Platform

Needs APIs, webhooks, SIEM delivery, ownership routing, policy gates, and repeatable operating controls.

GRC / Trust

Needs audit-ready reports, accepted risk records, customer proof, and a defensible no-theater story.

Product proof

Show the product, not a promise.

These screens make the Enterprise story concrete: portfolio posture, RelixQ Score, findings, QAST exposure modeling, PQC Lab validation, and integrations all look like one operating system.

Portfolio view

Organization posture

Projects, at-risk applications, open findings, and average RelixQ Score give leadership a starting point before drilling into a product area.

RelixQ Enterprise projects overview showing Acme Corp portfolio posture and at-risk projects.

AppSec workflow

Engineering score

RelixQ Score, HNDL-critical exposures, next best actions, services, signals, and confidence explain what engineering should fix first.

RelixQ Enterprise engineering page showing RelixQ Score and next best actions.

Operational analytics

Engineering analytics

Findings by service, algorithm, language, and scan history give AppSec teams the evidence needed to prioritize work by system and trend.

RelixQ Enterprise engineering analytics showing findings by service, algorithm, language, and recent scans.

Evidence detail

Findings workbench

Finding filters, severity, algorithm, owner, service, environment, risk, recommendation, and migration target stay in one review surface.

RelixQ Enterprise findings page with filters and expanded RSA finding detail.

CISO reporting

Executive score trend

Score movement, severity mix, and quantum exposure turn migration progress into a board-readable story instead of a one-time scan result.

RelixQ Enterprise executive page showing RelixQ Score trend, open findings, and quantum exposure.

HNDL register

Quantum Exposure (QAST)

QAST makes the honesty boundary visible: no decryption is performed; exposure is modeled with reachability, harvestability, and Mosca windows.

RelixQ Enterprise Quantum Exposure QAST page showing HNDL register and exposure metrics.

Safe validation

PQC handshake lab

Read-only observations show negotiated group, hybrid support, classical acceptance, downgrade labels, duration, and handshake size.

RelixQ Enterprise PQC Lab table showing handshake observations.

Operations

Enterprise integrations

Datadog, Splunk, Microsoft Sentinel, OpenTelemetry, Elastic Security, webhooks, and observability destinations make findings operational.

RelixQ Enterprise integrations catalog showing SIEM and observability destinations.

PQC news watch

Quantum inventory is becoming a government-level requirement.

Latest source-checked regional signals as of July 13, 2026. This is a curated watchlist for post-quantum cryptography, cryptographic inventory, and quantum-safe migration demand.

United States

June 2026
Source: White House / OMB

White House and OMB move PQC from strategy to execution

M-26-15 names automated cryptographic inventory and CBOM as the foundation of federal migration planning.

Why it matters

The U.S. market now has a clear buyer phrase: dynamic crypto inventory, policy enforcement, dashboards, and leadership reporting.

Read source

Canada

April 2026 milestone
Source: Canadian Centre for Cyber Security

Departmental PQC plans and annual reporting are active

Canada set April 2026 planning and reporting milestones, with high-priority systems targeted by 2031 and remaining systems by 2035.

Why it matters

Inventory, system analysis, and component-level crypto visibility are explicit prerequisites for government migration work.

Read source

Europe

2026 roadmap window
Source: European Commission

EU roadmap pushes coordinated Member State transition

The EU roadmap frames PQC as a synchronized transition and asks Member States to align timelines, awareness, and implementation work.

Why it matters

This supports a cross-border enterprise need for readiness reporting, governance evidence, and consistent crypto inventory controls.

Read source

UAE

May 2026
Source: Abu Dhabi Media Office

UAE launches national Crypto Discovery Tool

The UAE Cyber Security Council and QuantumGate launched CDT for cryptographic discovery, inventory management, continuous monitoring, and national posture reporting.

Why it matters

This is direct market proof that quantum inventory is becoming a national infrastructure and critical-sector requirement.

Read source

Asia

May 2026 regional update
Source: India DST / National Quantum Mission

Asia moves toward readiness indices and sector rollouts

India published a quantum-safe ecosystem report tracking readiness work in Singapore, South Korea, China, and India.

Why it matters

The region is validating the same enterprise buyer need: cryptographic visibility, risk assessment, migration planning, and crypto-agility.

Read source

Market position

The wedge is not inventory. It is evidence-to-control.

Enterprise buyers already hear discovery, crypto-agility, and PQC lab stories. RelixQ should stand out by connecting every finding to data lifetime, attack reachability, safe validation, executive score movement, and developer enforcement.

HNDL math

Dated exposure windows, not flat crypto counts

Models DataAsset lifetime, harvestability, crypto status, and Mosca X+Y>Z so teams can see which data is harvestable now and decryptable later.

Attack paths

Graph projection to crown-jewel data

Projects quantum attack paths over the readiness graph from exposed endpoints and ciphertext to the data assets that actually matter.

Safe validation

Consent-gated active probes

Runs read-only TLS and SSH negotiation checks only behind signed Rules of Engagement, authority attestation, blackout windows, rate clamps, and kill switches.

Break proofs

Classical proof without quantum theater

Uses local golden fixtures and modeled Shor/Grover cost estimates to separate proven classical breaks from modeled HNDL risk. No decryption claim, ever.

Score

RelixQ Score with HNDL drivers

Turns exposure into a leadership metric with traceable drivers, confidence, next actions, score deltas, and a timeline of readiness progress.

Dev loop

PR and release gates

Blocks new HNDL exposures before merge, supports SARIF and baselines, and links remediation to retest/regression status instead of a static report.

Two product motions

Enterprise for governed migration. OSS for transparent adoption.

Keep the open-source scanner credible and visible, but make the enterprise value unmistakable: QAST, governance, integrations, private rules, executive evidence, and release control.

Enterprise product

RelixQ Enterprise

Private SaaS and enterprise deployment for teams that need a productized QAST program: HNDL exposure math, attack paths, safe validation, RelixQ Score, PR gates, and audit-ready evidence.

  • Mosca-modeled HNDL exposure windows
  • Signed-RoE active probes and safe break proofs
  • Score, retest, SIEM, ticketing, and PR gate workflow
Explore Enterprise

Open product

RelixQ OSS

Open-source scanner and self-hosted stack for teams that want local scans, transparent rules, GitHub releases, and a practical path into post-quantum inventory work.

  • Apache-2.0 scanner and validation corpus
  • Local and self-hosted execution
  • JSON, SARIF, Markdown, and HTML evidence exports
Explore OSS

Operating proof

One evidence chain from scan to board report.

This is the story that can stand in front of sales, investors, and a technical buyer: every workflow consumes the same evidence instead of inventing a new spreadsheet after the scan.

  1. 01

    Inventory

    Find crypto in code, dependencies, TLS, certificates, JWT, SAML, mTLS, and infrastructure evidence.

  2. 02

    Classify

    Separate BROKEN_NOW, HNDL_AT_RISK, and QUANTUM_OK so AES/SHA and PQC algorithms are not mislabeled.

  3. 03

    Map

    Bind findings to data assets, confidentiality horizons, harvestability, and blast-radius graph context.

  4. 04

    Validate

    Use signed-RoE, read-only PQC handshake probes to check hybrid selection, classical acceptance, and true downgrade.

  5. 05

    Prove

    Attach safe classical-break proofs and modeled quantum cost estimates with explicit assumptions and citations.

  6. 06

    Operate

    Feed RelixQ Score, retest state, regression gates, PR checks, reports, alerts, and tickets from the same pipeline.

Enterprise outcomes

What your sales team can actually sell.

Board-ready posture

RelixQ Score turns technical exposure into a repeatable leadership metric with traceable drivers.

Evidence for buyers

Reports preserve the chain from finding to data asset to safe validation to remediation state.

Developer enforcement

PR and release gates stop new HNDL exposure before it becomes another migration backlog item.

OSS-backed trust

The open-source scanner remains visible while Enterprise adds private rules, workflow depth, and governance.

Next step

Put RelixQ in front of a real Enterprise pilot.

Request a demo for the QAST workflow, or inspect the OSS scanner first if your buyer wants transparent technical proof.