Skip to content
PQC TriageGitHub
Menu

Post-quantum migration triage

Find the cryptography a quantum computer breaks first, and the date you must migrate by.

Paste a real dependency manifest and a source excerpt. PQC Triage parses both, resolves every cryptographic call site to an algorithm, scores each one against published Shor resource estimates and NIST IR 8547 transition dates, and writes a sealed migration plan you can hand to a review. The 10-second path is a real import, a real score, a real persisted decision, and a downloadable plan.

Engine
hndl@1.0.0
NIST deprecates
2030
NIST disallows
2035
Keys needed
zero

Live posture

livefetched 03:18:48Z

Portfolio

58/100

high

Surfaces

12

discovered

First break

3.8y ago

capture already decryptable

Currently showing your newest survey, Demo: billing-gateway.

What it does

Three jobs, done end to end

No dashboards of decoration. Each of these is a real write against a hosted database, and each one leaves an artifact behind.

Inventory the cryptography you already ship

Import a package-lock.json, requirements.txt, go.mod, Gemfile.lock, composer.lock, Cargo.lock or pom.xml, plus the source where keys and ciphertext are handled. The extractor reports the line it matched.

Import now →

Decide what to migrate and by when

Set the data shelf life for each surface, record a decision with a rationale, and move the quantum-capability horizon. Mosca's arithmetic turns that into a start-by year that a board can read.

Open the workbench →

Hand over a plan you can verify

Download Markdown, JSON or CSV with every factor, citation and seal. The chain replays from the genesis value, and an agent can do the whole loop over JSON-RPC.

See the export →

Primary action

Import a manifest

Everything on this page works without an account. The anonymous owner cookie decides who can see which survey, and it is the only thing that guards your data.

Current work

Live from arXiv and NIST

Fetched 2026-10-04 03:18:48Z. Each row names the source it came from.

Papers on post-quantum migration

source

Standards news

source

Read the source, run it locally

MIT licensed, self-hostable, and it runs with zero environment variables: local development and the test suite use an embedded Postgres, production uses the hosted one through the same typed repository layer.

Star on GitHub