PostQ Alternatives
PostQ provides cryptographic discovery, inventory, and migration tooling for post-quantum readiness. It scans TLS, certificates, cloud KMS, Kubernetes, JWTs, and source code to identify quantum-vulnerable cryptography. Below are 8 security & compliance platforms apps with similar functionality to PostQ, matched by what each product actually does — not ranked or scored. Explore each to find the closest fit for your use case.
- PostQ Labspostqlabs.com
PostQ Labs provides quantum security intelligence by offering a database that maps the quantum risk posture of 3,687 publicly listed Japanese companies. The platform addresses the growing threat posed by quantum computers to current cryptographic standards, specifically highlighting vulnerabilities in RSA, ECDSA, and ECDH algorithms. Its core service is to identify organizations at risk from quantum attacks, enabling enterprises to act proactively as quantum decryption capabilities become a reality. The database includes 19 data fields per company, such as quantum vulnerability status, quantum risk score (ranging from 0 to 100), risk level (CRITICAL, HIGH, MEDIUM, LOW, NONE), public key algorithm, key size, CDN provider, and post-quantum key exchange details. Proprietary risk scoring is based on algorithm type, key size, and TLS configuration, allowing organizations to prioritize remediation efforts. The data is updated regularly, with monthly or quarterly updates depending on the selected plan, and is delivered as a CSV file via email within 24 hours of purchase. PostQ Labs is designed for enterprise use cases, serving security vendors, cyber insurance providers, investment funds, and auditors. Security vendors can use the data to identify prospects for post-quantum cryptography (PQC) migration consulting, while cyber insurers can leverage the data for underwriting and portfolio risk assessment. Investment funds may incorporate quantum risk posture into due diligence and ESG evaluations, and auditors can generate compliance and cryptographic readiness reports based on the risk scores. The service is offered through tiered pricing: an Evaluation Sample at $330 for a one-time purchase covering 35 companies, a Standard plan at $1,990 per year for the full dataset with quarterly updates, and an Enterprise plan at $4,990 per year with monthly updates and priority support. Custom data, API access, and exclusive licensing are available upon request. The data is licensed for internal use only, with resale and redistribution prohibited. All sales are final once data is delivered, and a delivery guarantee ensures customers receive their data within 24 hours or are eligible for a full refund.
- pqc-auditpypi.org
pqc-audit is an open-source CLI tool that scans local repositories to detect cryptographic components vulnerable to quantum attacks. It generates exposure reports and recommends migration paths to post-quantum cryptography, helping security teams future-proof their codebases.
Free PQC readiness scanthrondar.aiCryptographic Bill of Materials provides an in-browser tool to scan codebases for post-quantum cryptography vulnerabilities, grading readiness from A to F. It offers a free browser-based scan, a GitHub Action for CI integration, and exports CycloneDX CBOMs and SARIF reports. Security engineers can use it to assess and document cryptographic exposure without uploading sensitive code.
- pqc-migration-scannergithub.com
pqc-migration-scanner is an open-source CLI tool that scans codebases for vulnerabilities related to post-quantum cryptography. It helps security engineers and developers identify and address compliance issues in preparation for the post-quantum era. The tool is MIT licensed and suitable for integration into security workflows.
- PQCToolkit Post-Quantum Cryptopqcserver.com
PQCToolkit is a security application offering post-quantum encryption and digital signature capabilities using ML-KEM and ML-DSA. It operates entirely locally, ensuring privacy and no telemetry, and is available as a mobile app and browser extension.
- pqcprobepypi.org
pqcprobe is a command-line tool for probing server TLS configurations and evaluating readiness for post-quantum key exchanges, specifically ML-KEM. It helps security engineers and administrators audit cryptographic compliance and future-proof their infrastructure.
- pqcheckpypi.org
pqcheck is an open-source command-line tool that scans source code and dependency graphs to detect risks related to post-quantum cryptography. It helps security engineers and developers identify vulnerable algorithms and supply-chain issues, supporting SBOM and SARIF formats for integration into security workflows.
- pqc-checkpypi.org
pqc-check is an open-source command-line tool that scans cryptographic implementations for vulnerabilities to quantum attacks. It helps security engineers and developers assess and improve the quantum safety of their codebases. Distributed under the MIT license, it is freely available for integration into security workflows.