Splash Background
सशक्त · सक्षम · सुरक्षित
Home / AdviQ / Quantum Risk Assessment
Free Online Diagnostic Tool · UElement AdviQ

Every certificate, cipher and key your stack depends on. Vyuh lays out the formation.

Automated Cryptographic Bill of Materials (CBOM) & NIST PQC Migration Roadmap

Point Vyuh at a public endpoint or a code repository. It constructs an actionable cryptographic bill of materials, classifies what a quantum computer running Shor and Grover algorithms breaks, and outputs a clear migration path to NIST FIPS 203, 204, and 205, in about ninety seconds.

No agent or sensor install CycloneDX 1.6 CBOM export Board-ready PDF circulation
vyuh · scan simulation session
LIVE INSPECTION
→ target https://netbanking.enterprise.in
→ TLS 1.3 / 1.2 · 14 cipher suites enumerated
→ key exchange ECDHE-P256 [breakable: Shor]
→ certificate signature RSA-2048 / SHA-256 [breakable: Shor]
→ bulk transport cipher AES-128-GCM [weakened: Grover]
→ hash digest SHA-384 [quantum-safe]
→ ML-KEM hybrid group [not offered]
→ CBOM assembled · 27 assets mapped · 6 findings
0
Quantum Readiness ScoreHarvest-Now-Decrypt-Later exposure over 12-year horizon
Attack Surface Discovery

Two ways in, one inventory out.

Most organisations cannot answer a simple question: where is RSA or classical ECC running, and what relies on it? Vyuh answers it from the outside in via protocol handshakes, or from the source out across repositories.

https://

Public Web Endpoints

Vyuh negotiates directly with internet-facing services the way a client browser or API partner would, evaluating negotiated and fallback cryptographic suites.

  • TLS 1.3/1.2 versions, negotiated cipher suites, and key exchange groups
  • Full X.509 certificate chain inspection: signature algorithms, key sizes, CA roots
  • Detection of hybrid post-quantum key encapsulation (e.g. X25519MLKEM768)
  • HSTS, OCSP stapling validation, session ticket secrecy, and downgrade behavior
  • Discovered subdomains and APIs harvested from Certificate Transparency logs
git://

Code Repositories

Point Vyuh at a public repository or connect a private repo with a scoped read-only token. Vyuh traverses the code tree to parse cryptographic primitives and dependencies.

  • Cryptographic API calls across Java, Python, Go, C/C++, TypeScript, and .NET
  • Library versions: OpenSSL, BouncyCastle, PyCA/cryptography, libsodium
  • Hardcoded private keys, weak pseudo-random generators, and legacy SHA-1/MD5 digests
  • Certificates, keystores (JKS/PKCS12), and PEM credentials committed to version control
  • Infrastructure-as-Code (Terraform, Kubernetes) and CI/CD TLS configuration audit
NIST FIPS Standards

NIST Quantum Vulnerability & Replacement Matrix.

How classical cryptographic primitives perform under Shor’s and Grover’s algorithms, and their certified NIST FIPS 203, 204, and 205 post-quantum replacements.

Algorithm Vulnerability & Replacement Matrix

Classical primitives vs quantum threats and NIST FIPS targets

NIST FIPS Validated6 Primitives Mapped
Classical PrimitiveEnterprise LocationQuantum VerdictNIST FIPS Replacement
RSA-2048 / RSA-4096TLS certificates, code signing, JWT tokensBroken by ShorML-KEM-768 · ML-DSA-65
ECDSA P-256 / P-384Certificate signatures, mTLS, zero-trust tokensBroken by ShorML-DSA-65 · SLH-DSA
ECDH / X25519TLS session key exchange, VPN tunnels, SSHBroken by ShorX25519MLKEM768 Hybrid
AES-128-GCMSymmetric session encryption, database columnsHalved by GroverAES-256-GCM
SHA-1 / MD5Legacy HMACs, file integrity, older microservicesAlready InsecureSHA-384 · SHA-3
AES-256-GCM / SHA-384Modern high-assurance envelope encryptionQuantum-SafeNo modification required
Standards baseline: NIST SP 800-208 / FIPS 203, 204, 205CycloneDX 1.6 Cryptographic BOM format compatible
Transparent Methodology

How a scan runs.

Vyuh is free to use and gated only by a verified professional identity, ensuring diagnostic telemetry and cryptographic discoveries are shared strictly with verified organizational stewards.

1

Verify who you are

Work email and mobile number are confirmed via one-time verification codes, accompanied by your professional LinkedIn profile. Personal free mailboxes are rejected to ensure accountability.
2

Name the target

Provide a website URL or repository URI with explicit declaration of authorization. Vyuh executes only read-only, non-invasive cryptographic inspection without injecting payloads.
3

Vyuh probes and classifies

Handshakes, certificates, and AST source patterns are parsed. Every primitive is evaluated against NIST FIPS 203, 204, and 205 post-quantum standards and HNDL longevity formulas.
4

Inspect, export, and download

Live findings display in your browser immediately. The full cryptographic assessment downloads as a board-ready PDF report, with the machine-readable CBOM available in CycloneDX 1.6 format.
Clarity & Governance

Questions asked before scanning.

UElement AdviQ Practice

You cannot migrate what you have not inventoried.

Start with one internet-facing endpoint or one critical repository. The first actionable CBOM and quantum readiness verdict is ready in ninety seconds.