Which of your encryption will quantum computers break?
Paste your VPN, SSH or web server settings. It lists every algorithm, says what is weak today, what a quantum computer will break, and what is already safe, and gives you a starting cryptographic inventory. Traffic recorded today can be decrypted later, so key exchange comes first. Read in your browser.
Or paste the settings
The settings never leave this browser
Keys and secrets are never reported
Try it offline: it still works
Example report
VPN, SSH, TLS and a certificate
11 to retire now
3DES, MD5 and DH group 2 on a VPN!
TLS key exchange open to later decryption●
SSH already hybrid post-quantum✓
More in the full report●●●
Reading the settings in your browser
Finding every algorithm
Checking each against today’s and tomorrow’s attacks
Building the inventory
Post-quantum readiness
1 Summary
What was found
2 The checks
3 The cryptographic inventory
4 What this could not check
Checked against NIST’s post-quantum standards (FIPS 203, 204 and 205, August 2024) and its draft transition timeline (NIST IR 8547). When a large quantum computer will exist is uncertain; weak-today findings are certain. Read in your browser; nothing was sent to us. Guidance, not an audit; see the terms.
WHAT TO PASTE
The settings that choose the algorithms
Paste whole configs if easier: only the lines that pick algorithms are read. Several systems can go in one paste.
Cisco IOS or ASAshow running-config | section crypto: the isakmp, ikev1 and ikev2 policies and proposals, and transform sets.
FortiGateshow vpn ipsec phase1-interface, phase2-interface and show vpn ssl settings.
strongSwan, WireGuard, OpenVPNipsec.conf or swanctl.conf, wg0.conf (keys can be removed), or the .ovpn or server.conf file.
Linux and Unix servers/etc/ssh/sshd_config, or what the server really offers: sshd -T | grep -Ei 'kex|ciphers|macs|hostkey'.
Cisco switches and routersshow running-config | include ip ssh.
Nothing written?Then the built-in defaults apply, which this cannot see; sshd -T shows them.
nginx, Apache, HAProxyThe ssl_protocols, ssl_ciphers and ssl_ecdh_curve lines, or SSLProtocol and SSLCipherSuite, or ssl-default-bind lines.
Certificatesopenssl x509 -in cert.pem -noout -text and paste the output.
A live siteThe free certificate check reads a public site’s certificate and TLS versions.
What happens to it: it is read in your browser and dropped once the report is drawn. Only algorithm names are reported, never a key, a secret or an address. Our copy of your details carries only the counts.
QUESTIONS
Asked often
The questions people search for before they run the check.
What is post-quantum cryptography?
Encryption designed to resist attack by large quantum computers. NIST published the first standards in August 2024: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures. Hybrid schemes combine one of these with a classical algorithm, so a connection is safe if either holds.
What is harvest now, decrypt later?
Recording encrypted traffic today in order to decrypt it once a quantum computer can break the key exchange. It is why key exchange is the first thing to move: data that must stay secret for years is exposed now, even though the quantum computer is not here yet.
Which algorithms will quantum computers break?
The public-key ones: RSA, Diffie-Hellman (finite-field and elliptic-curve, including X25519) and ECDSA or Ed25519 signatures. Symmetric encryption such as AES-256 and hashes such as SHA-256 remain safe.
What is a CBOM?
A cryptographic bill of materials: an inventory of where and how cryptography is used, algorithms, key sizes, protocols and certificates. CERT-In's SBOM guidelines (version 2.0) describe it, and post-quantum plans start with one. This check builds a starting inventory from the settings you paste.
Are my settings uploaded?
No. They are read in your browser and dropped once the report is drawn, and only algorithm names are reported. If you ask for the report, we keep your details and a one-line summary with the counts.
Godwit AI Labs
This report is available as a branded PDF, and the inventory as a CSV. Use the download buttons on the page,
or ask us at godwit-tech.com/contact.
Start with an inventory
Every post-quantum plan begins with knowing where cryptography is used. Retire what is weak today, switch on hybrid key exchange where it is already supported, and plan the rest with your vendors.