Discover
Build a complete crypto inventory
Scan source code, package manifests, TLS endpoints, certificates, infrastructure configuration, and hand-rolled implementations.
Open-source post-quantum readiness
Scan code, dependencies, TLS endpoints, and certificates locally or self-host the full stack. No account, no workspace, no source-code telemetry.
The readiness gap
Harvest-now-decrypt-later attacks make long-lived encrypted data a present-day concern. RelixQ OSS helps teams answer the first migration question: where is classical cryptography used?
Quantum-broken public-key cryptography
Protocol and configuration risk
Cryptography already broken today
Committed material and classical signatures
RelixQ OSS
Local scans, transparent rules, self-hosted workflows, and exports your team can inspect without sending source code to RelixQ.
Discover
Scan source code, package manifests, TLS endpoints, certificates, infrastructure configuration, and hand-rolled implementations.
Prioritize
Classify findings as quantum-broken, quantum-weakened, or broken today, then rank them with risk and crypto-agility scores.
Operationalize
Export JSON, SARIF, Markdown, and HTML. Gate pull requests on new findings while preserving an explicit, reviewable baseline.
Control
Run the scanner locally or self-host the full stack. RelixQ OSS does not send source code or scan findings to a SaaS backend.
Five-minute OSS evaluation
Download one release, scan a repository, and produce machine-readable evidence without uploading code or building a custom toolchain.
Choose a prebuilt binary, package, or container image.
Point RelixQ at a repository, dependency manifest, or TLS endpoint.
Inspect the risk score, exact file locations, and migration guidance.
Add SARIF and baseline-aware checks to the pull-request workflow.
Get the OSS scanner
Tell us who you are and get the Windows installer, release packages, and the GitHub repository. No account, no workspace - the scanner runs entirely on your machine.
Stay current
Get release notes, new language coverage, validation results, and practical guidance for building a post-quantum inventory.
OPEN SOURCE, OPEN EVIDENCE
Detection rules, the validation corpus, release artifacts, and implementation are reviewable in the public repository.
Explore the repository