Built by Soqucoin Labs Inc. — the team that migrated a production blockchain from ECDSA to NIST FIPS 204 (ML-DSA). Not theory — proven implementation.
PQCAT discovers every cryptographic asset across your infrastructure, classifies quantum vulnerability, scores compliance readiness, and delivers federal-grade reports — all from a single binary with zero runtime dependencies.
pqcat scan tls agency.gov --framework fisma --html report.html --save-db
That line needs Enclave or Pro, which are free to download. The Scanner built from this repository does discovery and classification; see Quick Start below.
Output: A scored Crypto Bill of Health with Quantum Vulnerable / Transitional / PQ Compliant zone breakdown, POA&M entries, and framework-specific migration recommendations.
Enclave and Pro are pre-built and downloadable from the public release. Enclave is the free product: every capability, bounded by a 25-host scope limit per scan until you license it.
| Feature | Scanner (this repo) | Enclave | Pro |
|---|---|---|---|
| CLI scanning + classification | ✓ | ✓ | ✓ |
| JSON / plain-text output | ✓ | ✓ | ✓ |
| Shell completions (bash/zsh/fish) | ✓ | ✓ | ✓ |
System health check (pqcat doctor) |
— | ✓ | ✓ |
| Compliance scoring + frameworks | — | ✓ | ✓ |
| Self-contained HTML and PDF reports | — | ✓ | ✓ |
| SQLite scan history & comparison | — | ✓ | ✓ |
| Evidence layer (coins, binding, disclosure) | — | ✓ | ✓ |
| TUI terminal dashboard | — | ✓ | ✓ |
Update check (pqcat update) |
— | ✓ | ✓ |
| REST API + web dashboard | — | — | ✓ |
| 4 persona views (CISO/Auditor/CIO/Exec) | — | — | ✓ |
| Notification center | — | — | ✓ |
| Role-based access control (RBAC) | — | — | ✓ |
| User management & HMAC audit logging | — | — | ✓ |
| Branded PDF reports (logo, cover page) | — | — | ✓ |
Prometheus observability (/metrics) |
— | — | ✓ |
| ML-DSA-44 report seals (FIPS 204) | — | — | ✓ |
| Scheduled scans & alert webhooks | — | — | ✓ |
| Confidential Compliance Engine (CCE) | — | — | ✓ |
| Section 508 / WCAG 2.1 AA accessible | — | — | ✓ |
All three builds come off one engine, and the Scanner's source is what lives here. Enclave compiles with zero network code beyond scan targets, which the compiler guarantees rather than a setting: there is no server in the binary to turn off. Pro adds that server. Both carry the proprietary compliance engine and are published as pre-built binaries alongside the Scanner archives.
Everything here runs on the build this repository produces. Commands that need Enclave or Pro are in the section below, kept separate on purpose: they exit with an error on a Scanner build, and a quick start whose first command fails is worse than no quick start.
# Build the Scanner
make
# Scan (auto-deep for single targets)
./pqcat scan tls example.com
# Machine-readable output
./pqcat scan tls example.com --json
# Generate an org config template
./pqcat config initScoring, frameworks, reports and the evidence layer are not compiled into the Scanner. Download Enclave, which is free, and the same target produces a scored Crypto Bill of Health:
# From https://github.com/soqucoin-labs/pqcat/releases/latest
pqcat scan tls example.com --framework fisma --html cboh.html --save-dbUnlicensed Enclave covers up to 25 hosts per scan. pqcat license trial starts a
free 14-day evaluation that raises it, needs no registration, and validates
offline.
| Module | Command | Description |
|---|---|---|
| TLS/SSL | scan tls |
Deep scan: full cipher enumeration, protocol probing, ML-KEM detection, quantum classification |
| SSH | scan ssh |
Key exchange, host key types |
| SBOM | scan sbom |
CycloneDX/SPDX crypto dependency analysis |
| PKI | scan pki |
Certificate chain walking and CA analysis |
| Code | scan code |
Source code pattern scanning (564 patterns, 39 file types) |
| Config | scan config |
Configuration file analysis (nginx, Apache, OpenSSL, SSH) for weak crypto settings |
| HSM/KMS | scan hsm |
Hardware security module key discovery |
| SCAP | scan scap |
SCAP/XCCDF benchmark results for crypto policy compliance |
| Image | scan image |
Container image (Docker, OCI) scanning for embedded crypto libraries |
| CIDR | scan tls <cidr> |
Subnet-wide TLS and SSH discovery across network ranges |
| Cloud (CSP) | scan cloud aws |
AWS KMS, ACM, ELB, S3, Route 53, IAM crypto discovery |
make # Build scanner
make test # Run unit tests
make sbom # Generate CycloneDX SBOM
make checksums # SHA-256 integrity manifest
make release # Cross-platform release package
make linux-amd64 # Cross-compile for Linux x86_64Pro Edition: The Pro source code is proprietary and not included in this repository. Pre-built Pro binaries are available from GitHub Releases. For enterprise licensing, contact labs@soqu.org.
PQCAT's deep scan mode provides SSL Labs-grade TLS assessment with quantum-risk classification in a single binary, air-gap safe.
# Deep scan (default for single targets)
pqcat scan tls example.com
# Explicit deep mode for network ranges
pqcat scan tls 10.0.0.0/24 --deep
# Force fast mode (single-connection, ~1s)
pqcat scan tls example.com --fastWhat deep scan detects:
- Full cipher suite enumeration (20+ suites per target)
- Protocol version matrix (TLS 1.0–1.3, SSLv3, SSLv2)
- Raw TCP probes for legacy protocols (SSLv3/SSLv2, export ciphers)
- Complete certificate chain with SANs, fingerprints, OCSP, SCTs
- HTTP security headers (HSTS, CSP, X-Frame-Options)
- Server cipher preference detection
- Every component classified: RED (quantum-vulnerable) / GREEN (quantum-safe)
- Prioritized remediation actions with CNSA 2.0 / NIST references
Patent-pending per-asset "Harvest Now, Decrypt Later" exposure scoring.
- Time-weighted quantum risk based on data sensitivity, retention period, and estimated Q-Day timeline
- Per-asset HNDL multiplier integrated into compliance scoring
- Surfaces in scan results, reports, and the Pro dashboard
Prove compliance without revealing your infrastructure. Patent-pending privacy-preserving assessments.
pqcat scan tls agency.gov --confidential --framework fisma- Asset Anonymization: BLAKE2b-salted identifiers replace hostnames and IPs
- Aggregate-Only Reporting: Statistical summaries, zero individual asset detail
- Verifiable Score Binding: Transparent hash-based proof (Merkle commitment + Fiat-Shamir, SHA-384, no trusted setup) that binds a published score to its committed finding set. A holder of the findings can verify the opening; tampering with a finding or the score is detected
PQCAT Pro includes enterprise-grade security out of the box:
- RBAC: Three roles (viewer, analyst, admin) with route-level enforcement
- Session Auth: 256-bit tokens, HttpOnly/Secure/SameSite=Strict cookies, 8h TTL
- First-Run Admin: Cryptographically random password, force-change on first login
- Tamper-Proof Audit Log: HMAC-SHA256 chained entries with integrity verification
- ML-DSA-44 Report Seals: FIPS 204 post-quantum signatures on all reports
- Prometheus Metrics:
/metricsendpoint for operational observability - Security Headers: CSP, HSTS, X-Frame-Options, CORS, rate limiting
- Env-Only Secrets: TLS certs, SIEM tokens, audit keys via environment variables
| Document | Description |
|---|---|
| Quick Start | Install, first scan, generate reports — get running in 5 minutes |
| Deployment Guide | Binary install, Docker, air-gap deployment, systemd, hardening |
| Architecture | Four-layer design, package structure, build tags |
| API Reference | REST API endpoints, authentication, session management (Pro) |
| Admin Guide | RBAC, user management, audit logging, security configuration (Pro) |
| Standard Operations Procedure | Federal-grade SOP: installation, configuration, operations, maintenance |
| Changelog | Version history and release notes |
| Contributing | Development setup, testing, build commands |
| Security Policy | Vulnerability reporting, security architecture |
┌── Discovery Layer ──────────────── Open Source (Apache 2.0) ──┐
│ 11 scanner modules + algorithm classifier + data models │
├── Intelligence Layer ────────────── Proprietary ──────────────┤
│ Compliance engine + scoring + threat intel │
├── Security Layer ─────────────────────────────────────────────┤
│ RBAC · Session Auth · HMAC Audit · Rate Limiting · CSP │
├── Delivery Layer ─────────────────────────────────────────────┤
│ PDF · HTML · JSON · SIEM · TUI · REST API · Prometheus │
└───────────────────────────────────────────────────────────────┘
The scanner (this repository) is open source under Apache 2.0. The compliance engine is proprietary and distributed as compiled binaries under license.
| Framework | --framework |
Scope |
|---|---|---|
| CNSA 2.0 | cnsa2 |
NSA Commercial National Security Algorithm Suite 2.0 |
| NSM-10 | nsm10 |
National Security Memorandum — inventory and migration plans |
| FISMA | fisma |
NIST 800-53 federal agency compliance |
| FedRAMP | fedramp |
Cloud service provider authorization |
| NIST SP 800-131A | sp800131a |
Cryptographic algorithm deprecation guidance |
| CMMC | cmmc |
Cybersecurity Maturity Model Certification (DoD supply chain) |
| Framework | --framework |
Scope |
|---|---|---|
| PCI DSS | pci |
Payment Card Industry Data Security Standard |
| SOX | sox |
Sarbanes-Oxley Act — financial reporting controls |
| HIPAA | hipaa |
Health Insurance Portability and Accountability Act |
| NYDFS | nydfs |
NY Department of Financial Services cybersecurity regulation |
| SWIFT CSP | swift |
SWIFT Customer Security Programme |
The PQCAT scanner is licensed under the Apache License 2.0.
The compliance engine (scoring, reporting, REST API) is proprietary software. Contact labs@soqu.org for licensing.
Soqucoin Labs Inc.
228 Park Ave S, Pmb 85451, New York, NY 10003
soqucoin.com · labs@soqu.org