Godwit AI Labs Talk to us

Home › Free tools › Post-quantum readiness check

Which of your encryption will quantum computers break?

Paste your VPN, SSH or web server settings. It lists every algorithm, says what is weak today, what a quantum computer will break, and what is already safe, and gives you a starting cryptographic inventory. Traffic recorded today can be decrypted later, so key exchange comes first. Read in your browser.

Or paste the settings
  • The settings never leave this browser
  • Keys and secrets are never reported
  • Try it offline: it still works
WHAT TO PASTE

The settings that choose the algorithms

Paste whole configs if easier: only the lines that pick algorithms are read. Several systems can go in one paste.

  1. Cisco IOS or ASAshow running-config | section crypto: the isakmp, ikev1 and ikev2 policies and proposals, and transform sets.
  2. FortiGateshow vpn ipsec phase1-interface, phase2-interface and show vpn ssl settings.
  3. strongSwan, WireGuard, OpenVPNipsec.conf or swanctl.conf, wg0.conf (keys can be removed), or the .ovpn or server.conf file.

What happens to it: it is read in your browser and dropped once the report is drawn. Only algorithm names are reported, never a key, a secret or an address. Our copy of your details carries only the counts.

QUESTIONS

Asked often

The questions people search for before they run the check.

What is post-quantum cryptography?

Encryption designed to resist attack by large quantum computers. NIST published the first standards in August 2024: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures. Hybrid schemes combine one of these with a classical algorithm, so a connection is safe if either holds.

What is harvest now, decrypt later?

Recording encrypted traffic today in order to decrypt it once a quantum computer can break the key exchange. It is why key exchange is the first thing to move: data that must stay secret for years is exposed now, even though the quantum computer is not here yet.

Which algorithms will quantum computers break?

The public-key ones: RSA, Diffie-Hellman (finite-field and elliptic-curve, including X25519) and ECDSA or Ed25519 signatures. Symmetric encryption such as AES-256 and hashes such as SHA-256 remain safe.

What is a CBOM?

A cryptographic bill of materials: an inventory of where and how cryptography is used, algorithms, key sizes, protocols and certificates. CERT-In's SBOM guidelines (version 2.0) describe it, and post-quantum plans start with one. This check builds a starting inventory from the settings you paste.

Are my settings uploaded?

No. They are read in your browser and dropped once the report is drawn, and only algorithm names are reported. If you ask for the report, we keep your details and a one-line summary with the counts.

Start with an inventory

Every post-quantum plan begins with knowing where cryptography is used. Retire what is weak today, switch on hybrid key exchange where it is already supported, and plan the rest with your vendors.