See exactly what a scan returns
Real CipherGap output across the grade spectrum — the same readiness breakdown, findings, and downloadable evidence (JSON, CSV, CycloneDX CBOM) you get from a live scan.
Hybrid PQC enabled
TLS 1.3 negotiating X25519MLKEM768 with a healthy certificate.
pqc-ready.example
PQC key exchange ready
This host negotiates hybrid post-quantum key exchange — ahead of most of the internet. Its certificate authentication is still classical (RSA/ECDSA), which is expected on the public web today.
Readiness breakdown
Negotiates hybrid post-quantum key exchange (X25519MLKEM768).
TLS 1.3 with a strong ECDSA certificate.
Certificate authentication is still classical (ECDSA-SHA256). Post-quantum certificate signatures are not yet broadly deployable on the public web — this is expected today.
What we found
Key exchange
PassHybrid post-quantum key exchange (X25519MLKEM768) is supported.
Certificate key
InfoECDSA 256-bit, signed with ECDSA-SHA256.
Modern TLS, no PQC
TLS 1.3 and a strong certificate, but no post-quantum key exchange yet.
modern.example
Largely protected
Strong TLS posture with minor gaps. A few tweaks put this host fully in the quantum-safe zone.
Readiness breakdown
Only classical key exchange is offered — sessions are exposed to harvest-now-decrypt-later.
TLS 1.3 with a strong ECDSA certificate.
Certificate authentication is still classical (ECDSA-SHA256). Post-quantum certificate signatures are not yet broadly deployable on the public web — this is expected today.
What we found
Key exchange
HighOnly classical key exchange is offered; sessions are exposed to harvest-now-decrypt-later.
Enable a hybrid PQC key exchange (e.g. X25519MLKEM768) on your TLS terminator.
TLS version
InfoNegotiated TLS 1.3.
Certificate key
InfoECDSA 256-bit, signed with ECDSA-SHA256.
Certificate uses classical (quantum-vulnerable) cryptography; track PQC certificate availability.
TLS 1.2 only
TLS 1.2 with a standard RSA-2048 certificate and no PQC.
legacy12.example
Partially exposed
Traffic to this host can be captured today and decrypted once a cryptographically-relevant quantum computer exists.
Readiness breakdown
Only classical key exchange is offered — sessions are exposed to harvest-now-decrypt-later.
TLS 1.2, RSA 2048-bit.
Certificate authentication is still classical (SHA256-RSA). Post-quantum certificate signatures are not yet broadly deployable on the public web — this is expected today.
What we found
Key exchange
HighOnly classical key exchange is offered; sessions are exposed to harvest-now-decrypt-later.
Enable a hybrid PQC key exchange (e.g. X25519MLKEM768) on your TLS terminator.
TLS version
InfoNegotiated TLS 1.2.
Certificate key
InfoRSA 2048-bit, signed with SHA256-RSA.
Certificate uses classical (quantum-vulnerable) cryptography; track PQC certificate availability.
Weak, expiring certificate
An undersized RSA-1024 certificate that is also close to expiry.
weakcert.example
Exposed
This host relies on cryptography that quantum computers are expected to break. Recorded traffic is at real risk.
Readiness breakdown
Only classical key exchange is offered — sessions are exposed to harvest-now-decrypt-later.
Weak certificate key (RSA 1024-bit).
Certificate authentication is still classical (SHA256-RSA). Post-quantum certificate signatures are not yet broadly deployable on the public web — this is expected today.
What we found
Key exchange
HighOnly classical key exchange is offered; sessions are exposed to harvest-now-decrypt-later.
Enable a hybrid PQC key exchange (e.g. X25519MLKEM768) on your TLS terminator.
TLS version
InfoNegotiated TLS 1.3.
Certificate key
MedRSA 1024-bit, signed with SHA256-RSA.
Certificate uses classical (quantum-vulnerable) cryptography; track PQC certificate availability.
Certificate expiry
MedCertificate expires in 7 day(s).
Renew the certificate.
Legacy TLS 1.0
Obsolete TLS 1.0 — critically exposed to interception and downgrade.
ancient.example
Critically exposed
Everything sent over TLS here is vulnerable to “harvest now, decrypt later.” An adversary recording traffic today could read it the day quantum arrives.
Readiness breakdown
Only classical key exchange is offered — sessions are exposed to harvest-now-decrypt-later.
Negotiated legacy TLS 1.0.
Certificate authentication is still classical (SHA256-RSA). Post-quantum certificate signatures are not yet broadly deployable on the public web — this is expected today.
What we found
Key exchange
HighOnly classical key exchange is offered; sessions are exposed to harvest-now-decrypt-later.
Enable a hybrid PQC key exchange (e.g. X25519MLKEM768) on your TLS terminator.
TLS version
MedNegotiated TLS 1.0.
Disable TLS 1.0/1.1 and require TLS 1.2 or higher (ideally TLS 1.3) on your TLS terminator.
Certificate key
InfoRSA 2048-bit, signed with SHA256-RSA.
Certificate uses classical (quantum-vulnerable) cryptography; track PQC certificate availability.