Cryptography is everywhere
Applications, dependencies, certificates, TLS, JWT, SAML, mTLS, build systems, and infrastructure all carry quantum-relevant assumptions.
Enterprise QAST for post-quantum exposure
RelixQ turns cryptography discovery into an evidence-backed operating system for security and engineering: HNDL exposure windows, attack paths, safe validation, RelixQ Score, reports, tickets, retests, and release gates.
RelixQ Enterprise
38
RelixQ Score
104
HNDL-critical
186
open findings
10
integrations

Engineering
RelixQ Score, findings, next actions
QAST
HNDL register and exposure evidence
Integrations
SIEM and observability delivery
Applications, dependencies, certificates, TLS, JWT, SAML, mTLS, build systems, and infrastructure all carry quantum-relevant assumptions.
Security leaders need to know which data can be harvested now, which paths are reachable, and which controls prove risk is going down.
Findings need owners, tickets, retests, exceptions, and PR gates or the same exposure returns after every release.
Why RelixQ
RelixQ should make buyers feel the shift immediately: scattered cryptography becomes HNDL exposure, exposure becomes evidence, and evidence becomes controls that keep new risk from entering the roadmap.
186
quantum findings
104
HNDL-critical
12
attack paths
4
control outputs
Animated QAST storyboard
RSA, ECC, DH, TLS, certificates, JWT, SAML, mTLS, dependencies, and custom crypto live in code, services, and infrastructure.
RelixQ ranks exposure by harvestability, data lifetime, reachability, confidence, and Mosca windows.
QAST ties findings to attack paths, safe validation, owner context, recommendations, and honest proof boundaries.
The same evidence drives RelixQ Score, reports, tickets, SIEM events, retests, exceptions, and PR gates.
Score trend, HNDL exposure, remediation progress
Finding evidence, confidence, owner, retest state
PR gate, policy baseline, migration target
Report, accepted risk, audit-ready source chain
Before RelixQ
A spreadsheet of algorithms, unclear owners, no data lifetime, no safe validation, and no release control.
After RelixQ
HNDL register, attack paths, score drivers, reports, tickets, retests, integrations, and PR gates from one evidence chain.
Enterprise narrative
The buyer is not only asking "can you find RSA?" They are asking whether RelixQ can help them run a post-quantum migration program: posture, owners, evidence, safe validation, governance, and release control.
Category map
Code, dependencies, TLS, certificates, JWT, SAML, mTLS, infrastructure, and protocol surfaces become one inventory.
Findings are ranked by data lifetime, harvestability, reachability, confidence, and score impact instead of raw algorithm count.
Signed-RoE active probes and PQC Lab checks prove negotiation posture without dangerous claims or unauthorized testing.
RelixQ turns the same evidence into score trends, tickets, SIEM events, retests, reports, and PR gates.
Inventory
Crypto evidence
QAST
Exposure and validation
Control plane
Score, gates, reports
Why now
Government roadmaps, national crypto discovery programs, and customer trust reviews are turning quantum inventory into a funded security workstream.
Why RelixQ
RelixQ does not stop at algorithm discovery. It links findings to HNDL windows, attack paths, safe validation, score movement, tickets, reports, and PR gates.
Why credible
QAST shows exposure, reachability, harvestability, classical breaks, and modeled quantum cost. It does not claim impossible quantum decryption.
Why buy
CISOs get posture, AppSec gets evidence, engineers get gates, GRC gets reports, and platform teams get integrations into the tools they already run.
Buyer rooms
Needs a board-ready score, exposure trend, risk owners, and evidence that the migration is moving.
Needs exact findings, confidence, context, recommendations, retest state, and safe validation history.
Needs APIs, webhooks, SIEM delivery, ownership routing, policy gates, and repeatable operating controls.
Needs audit-ready reports, accepted risk records, customer proof, and a defensible no-theater story.
Product proof
These screens make the Enterprise story concrete: portfolio posture, RelixQ Score, findings, QAST exposure modeling, PQC Lab validation, and integrations all look like one operating system.
Portfolio view
Projects, at-risk applications, open findings, and average RelixQ Score give leadership a starting point before drilling into a product area.

AppSec workflow
RelixQ Score, HNDL-critical exposures, next best actions, services, signals, and confidence explain what engineering should fix first.

Operational analytics
Findings by service, algorithm, language, and scan history give AppSec teams the evidence needed to prioritize work by system and trend.

Evidence detail
Finding filters, severity, algorithm, owner, service, environment, risk, recommendation, and migration target stay in one review surface.

CISO reporting
Score movement, severity mix, and quantum exposure turn migration progress into a board-readable story instead of a one-time scan result.

HNDL register
QAST makes the honesty boundary visible: no decryption is performed; exposure is modeled with reachability, harvestability, and Mosca windows.

Safe validation
Read-only observations show negotiated group, hybrid support, classical acceptance, downgrade labels, duration, and handshake size.

Operations
Datadog, Splunk, Microsoft Sentinel, OpenTelemetry, Elastic Security, webhooks, and observability destinations make findings operational.

PQC news watch
Latest source-checked regional signals as of July 13, 2026. This is a curated watchlist for post-quantum cryptography, cryptographic inventory, and quantum-safe migration demand.
United States
June 2026M-26-15 names automated cryptographic inventory and CBOM as the foundation of federal migration planning.
Why it matters
The U.S. market now has a clear buyer phrase: dynamic crypto inventory, policy enforcement, dashboards, and leadership reporting.
Canada
April 2026 milestoneCanada set April 2026 planning and reporting milestones, with high-priority systems targeted by 2031 and remaining systems by 2035.
Why it matters
Inventory, system analysis, and component-level crypto visibility are explicit prerequisites for government migration work.
Europe
2026 roadmap windowThe EU roadmap frames PQC as a synchronized transition and asks Member States to align timelines, awareness, and implementation work.
Why it matters
This supports a cross-border enterprise need for readiness reporting, governance evidence, and consistent crypto inventory controls.
UAE
May 2026The UAE Cyber Security Council and QuantumGate launched CDT for cryptographic discovery, inventory management, continuous monitoring, and national posture reporting.
Why it matters
This is direct market proof that quantum inventory is becoming a national infrastructure and critical-sector requirement.
Asia
May 2026 regional updateIndia published a quantum-safe ecosystem report tracking readiness work in Singapore, South Korea, China, and India.
Why it matters
The region is validating the same enterprise buyer need: cryptographic visibility, risk assessment, migration planning, and crypto-agility.
Market position
Enterprise buyers already hear discovery, crypto-agility, and PQC lab stories. RelixQ should stand out by connecting every finding to data lifetime, attack reachability, safe validation, executive score movement, and developer enforcement.
HNDL math
Models DataAsset lifetime, harvestability, crypto status, and Mosca X+Y>Z so teams can see which data is harvestable now and decryptable later.
Attack paths
Projects quantum attack paths over the readiness graph from exposed endpoints and ciphertext to the data assets that actually matter.
Safe validation
Runs read-only TLS and SSH negotiation checks only behind signed Rules of Engagement, authority attestation, blackout windows, rate clamps, and kill switches.
Break proofs
Uses local golden fixtures and modeled Shor/Grover cost estimates to separate proven classical breaks from modeled HNDL risk. No decryption claim, ever.
Score
Turns exposure into a leadership metric with traceable drivers, confidence, next actions, score deltas, and a timeline of readiness progress.
Dev loop
Blocks new HNDL exposures before merge, supports SARIF and baselines, and links remediation to retest/regression status instead of a static report.
Two product motions
Keep the open-source scanner credible and visible, but make the enterprise value unmistakable: QAST, governance, integrations, private rules, executive evidence, and release control.
Enterprise product
Private SaaS and enterprise deployment for teams that need a productized QAST program: HNDL exposure math, attack paths, safe validation, RelixQ Score, PR gates, and audit-ready evidence.
Open product
Open-source scanner and self-hosted stack for teams that want local scans, transparent rules, GitHub releases, and a practical path into post-quantum inventory work.
Operating proof
This is the story that can stand in front of sales, investors, and a technical buyer: every workflow consumes the same evidence instead of inventing a new spreadsheet after the scan.
Find crypto in code, dependencies, TLS, certificates, JWT, SAML, mTLS, and infrastructure evidence.
Separate BROKEN_NOW, HNDL_AT_RISK, and QUANTUM_OK so AES/SHA and PQC algorithms are not mislabeled.
Bind findings to data assets, confidentiality horizons, harvestability, and blast-radius graph context.
Use signed-RoE, read-only PQC handshake probes to check hybrid selection, classical acceptance, and true downgrade.
Attach safe classical-break proofs and modeled quantum cost estimates with explicit assumptions and citations.
Feed RelixQ Score, retest state, regression gates, PR checks, reports, alerts, and tickets from the same pipeline.
Enterprise outcomes
RelixQ Score turns technical exposure into a repeatable leadership metric with traceable drivers.
Reports preserve the chain from finding to data asset to safe validation to remediation state.
PR and release gates stop new HNDL exposure before it becomes another migration backlog item.
The open-source scanner remains visible while Enterprise adds private rules, workflow depth, and governance.
Next step
Request a demo for the QAST workflow, or inspect the OSS scanner first if your buyer wants transparent technical proof.