Full Stack PQC Migration Engine

PQC migration,
made easy.

QuTrust finds quantum-vulnerable cryptography across all seven surfaces of your stack, then hands you a prioritized roadmap to fix it. Discovery to done, in one engine.

Start your free audit
No Docker. No infrastructure. First findings in under five minutes, in our cloud or inside your perimeter.

Everyone else hands you a scan.
You need a decision.

The deadline is not one date, and it is not just the U.S. Governments are converging on 2030 to 2035: U.S. federal systems by 2030 and 2031, the EU securing critical infrastructure by 2030, and the UK's NCSC requiring cryptographic discovery by 2028. A migration this size takes years, so wherever you operate, the clock is already running. Yet most teams are stuck: the tools they can buy only scan, and a scan is not a migration.

One clock, every jurisdiction · converging on 2030–2035
United States
2030 · key establishment on high-impact systems
2031 · digital signatures and certificates
EO 14412 · covered contractors by 2030
European Union
2026 · national transition roadmaps
2030 · critical infrastructure secured
2035 full transition · NIS2, DORA
United Kingdom
2028 · cryptographic discovery and plan
2031 · high-priority upgrades
2035 complete · NCSC
Your Sector
2028–2032 · financial services (DORA, FS-ISAC)
2030 · energy, telecom, health (EU critical infra)
Government and defense move first

Establish a living
PQC migration roadmap.

Work with the baseline inventory you already keep. Compress years into weeks. A multi-year PQC migration begins with finding the risk across thousands of artifacts spread through your hardware and software stack. QuTrust analyzes all of them in a single engine, across the full migration lifecycle, and builds the PQC migration roadmap for you. No guesswork. No CBOM or SBOM required to start.

Start from the inventory you already keep
CMDB-native, not another console
A scanner makes you hand it a list of what to check, then leaves the results in a console nobody opens twice. QuTrust works the other way around. Connect ServiceNow, BMC Helix, and other CMDB platforms, and QuTrust reads your asset inventory straight from the system you already trust, then analyzes what it finds there for quantum exposure. No list to build by hand. No CBOM or SBOM required to start.
What you get

Every audit produces machine-readable artifacts that speak the formats your pipeline already consumes, ready to ingest into your CMDB, GRC platform, or remediation tracker.

Quantum Exposure Report
Every quantum-vulnerable algorithm mapped to file and line, rated by severity, and paired with a migration hint and recommended actions, so AI, Cloud, IT, and OT assets can be remediated in priority order.
CycloneDX CBOM
A CycloneDX Cryptography Bill of Materials, the de facto standard for cryptographic inventory disclosure. Hand it to your auditor, your customer's supply-chain security team, or federal procurement without translation.
Dependency SBOM
Your existing CycloneDX or SPDX inventory, enriched with quantum-risk annotations. No re-analysis required if you already maintain an SBOM.
Standards-native
FIPS 203FIPS 204FIPS 205Coming July 2026CNSA 2.0NIST IR 8547EO 14412

FIPS is only the cryptographic layer. QuTrust findings become evidence across the broader control environment you already answer to, mapped in context, so one audit feeds many frameworks.

SOC 2ISO 27001PCI DSSHIPAADORACMMCGDPR+30 more →

Analyze. Map. Move.

Discovery is the starting line, not the finish. QuTrust takes you from raw artifacts to a roadmap your teams can execute, on a timeline your board can track.

1
Analyze
The engine reads your artifacts across the full hardware and software stack to uncover cryptographic algorithms and risks that do not align with modern standards.
2
Map
The risk engine translates architectural risk into clear transition roadmaps tied directly to your operational timelines.
3
Move
Your development teams execute migration workflows using automated guidance to preserve long-term data protection.

Built for the people
who own the answer.

CISOs & GRC Leadership
The board wants a timeline. You need a real inventory first.
You cannot scope a migration you cannot see, or prove progress against an inventory that is stale on delivery.

QuTrust gives you portfolio-wide visibility across all seven surfaces, a CycloneDX CBOM your team can act on, and a quantum-risk-prioritized remediation queue. Board-ready, regulator-ready, built on evidence, not estimates.
Engineering & DevSecOps
Close the ticket and mean it.
Scanners miss things: vendored libraries, build-time dependencies, the JWT tokens your services issue every second. One regression slips in, and your name is on the sign-off.

QuTrust gives you file-and-line evidence across all seven surfaces, FIPS-mapped findings, and CI/CD gating that fails the build when banned crypto returns. In your pipeline, not your inbox.
Federal & Defense ProgramsComing Soon
SaaS is a non-starter. Coverage still isn't.
Your workloads are controlled, classified, or air-gapped. "Upload your source to our cloud" ends the conversation. The 2035 mandate does not care.

QuTrust runs as a signed binary entirely inside your perimeter, or as a dedicated tenant within boundaries you control. Source, certs, and binaries never leave unless you choose to sync. Full seven-surface coverage with evidence your ATO package can cite (FedRAMP, ITAR, CMMC).

Discovery is the starting line.

A first audit sets a continuous baseline; every later scan compares against it, so progress toward 2030 and 2035 is measurable, not anecdotal. From the baseline, QuTrust sorts every finding into four lanes, each derived from severity and algorithm status.

Catastrophic
Rotate or revoke immediately.
Exposed private-key material or a live credential exposure. The most urgent finding QuTrust surfaces, straight to the top of the queue.
Migrate
Schedule into the migration roadmap.
Confirmed quantum-vulnerable public-key crypto such as RSA, EC, and DH. Not broken yet, but on the clock toward 2035.
Classical
Fix on normal timelines.
Non-quantum security issues: SHA-1, MD5, RC4, 3DES, and legacy TLS. Real weaknesses, handled at your usual cadence.
Investigate
Triage, then route to a lane or clear.
Crypto detected, but the algorithm or exposure is unconfirmed. QuTrust flags it for a decision instead of guessing.
.github/workflows/qutrust.yml
# Gate every pull request on quantum exposure
- name: QuTrust Audit
  uses: arcqubit/qutrust-action@v1
  with:
    token: ${{ secrets.QUTRUST_TOKEN }}
    project: my-service

From discovery to
full migration.

A phased plan across AI, Cloud, IT, and OT, aligned to global mandates, U.S. NIST and CISA, the EU's NIS2 and DORA, and the UK's NCSC, plus your sector's regulators. One roadmap, every environment, so nothing falls between the teams that own it. And it does not matter where you are on the timeline: scoping your first audit, mid-migration, or hardening the last legacy system, QuTrust meets you at your phase and moves you forward.

Phase 1 · 2025-2028
Discover and protect
Build the cryptographic inventory across AI, Cloud, IT, and OT, set the compliance baseline, and protect the most exposed assets first.
Phase 2 · 2025-2031
Hybrid transition
Roll out hybrid post-quantum cryptography, rotate keys and certificates, and validate PQC across your providers and pipelines.
Phase 3 · 2031-2035
Full migration
Retire classical algorithms, re-issue roots, and enforce post-quantum cryptography by default across every environment.

Continuous governance and executive reporting throughout: what is protected, what is not, and what happens next.

All seven. One engine.

Most tools cover one surface and call it done. Here is every surface QuTrust analyzes, what it finds, and where single-purpose scanners fall short.

Surface
What QuTrust finds
Competitive Landscape
Source Code
Python · Java · Go · JS · TypeScript · Rust · Ruby
RSA and EC key generation calls at exact file-and-line location, each mapped to FIPS 203, 204, and 205.
Incomplete
Most SAST tools find crypto but do not classify findings by quantum risk or map them to post-quantum standards.
Dependency Manifests
npm · pip · Maven · Cargo · Gemfile · Go modules
Quantum-vulnerable packages (node-rsa, jsonwebtoken, crypto-js, bcrypt) flagged before they ship, risk-classified, not just listed.
Incomplete
SCA tools flag CVE-vulnerable packages but rarely assess or score quantum exposure.
Existing SBOMs
CycloneDX · SPDX
Quantum-risk overlay applied directly to inventories your team already maintains. No re-analysis required.
Rarely covered
Few PQC tools ingest existing SBOMs to add quantum-risk annotation.
Certificates & Keys
PEM · CRT · CER · DER · P12 · PFX
Algorithm identification across every format, private-key markers detected, every finding assessed against the 2030 to 2035 migration deadlines.
Rarely covered
Certificates and keys are rarely analyzed as a standalone cryptographic surface.
Infrastructure Configs
nginx · Kubernetes · Envoy · Istio · HAProxy · Traefik · Apache
TLS settings and mTLS policies surfaced across every major load balancer, proxy, and service mesh. The crypto your infrastructure enforces, not just what developers wrote.
Rarely covered
Infrastructure configuration is rarely treated as a cryptographic surface.
Deployed Artifacts
.class · .dll · .so · .deb
Runtime binaries analyzed for vendored libraries, build-time dependencies, renamed crypto packages, and embedded cryptographic code invisible to source-level scanners.
Partial
The one surface artifact-focused tools tend to cover, and even then with language and format limits.
JWT Tokens
RS256 · RS384 · ES256 · ES384 · PS256
Runtime authentication flows analyzed for quantum-vulnerable signing algorithms, identified at the point of issuance.
Rarely covered
Most tools stop short of runtime token analysis.

Every other PQC approach forces you to buy a three to five product stack and stitch it together. The exposure lives in the gaps between those tools, and the intelligence lives in a proprietary engine they do not have. QuTrust closes both: no integration tax, no blind spots.

7/7
Complete surface coverage
One analysis closes every cryptographic surface at once. No integration work, no blind spots between tools, no dashboards to reconcile. Your complete quantum exposure picture, in one place.
Σ
Proprietary risk engine
QuTrust does not pattern-match strings like a scanner. The engine interprets what each artifact actually does, classifies its quantum risk, and maps it to FIPS 203, 204, and 205. This is intelligence no SAST, SCA, or BOM tool can produce.
:42
File-and-line evidence
Every finding includes the exact file path and line number, not a vague risk score, not a count. Actionable evidence your engineers can triage and remediate without a second tool to locate the issue.

One engine.
Your choice of where it runs.

The same proprietary engine powers every deployment mode, so the choice is about where your data lives, not what your tool can find. Most enterprise customers run more than one path in parallel: one for the compliance workflow, one for the build pipeline.

No-Code · Hosted
QuTrust Cloud
A no-code interface that runs entirely in your browser, hosted in a secure, isolated cloud. Nothing to install, no terminal. Connect GitHub, cloud drives, or object storage, or drop files straight in, and drive intake, reports, and CMDB integration without writing a line of code.
Built for: CISOs, GRC leads, compliance officers, mid-market security teams, and commercial unclassified workloads.
Low-Code · In your environment
QuTrust CLI
A signed binary that runs entirely inside your perimeter. Source, certificates, configs, and binaries never leave your environment unless you choose to sync findings. A tiny surface (qutrust login, qutrust scan) and declarative CI/CD, gating pull requests in an afternoon.
Built for: regulated environments, including those aligned to FINRA and HIPAA requirements, and environments where SaaS is not an option.
Hybrid · Enterprise & Federal
Coming Soon
Dedicated Tenant
The no-code experience of the Cloud combined with the data sovereignty of the CLI, deployed as a dedicated, single-tenant instance inside your own cloud environment. The platform, the engine, and every finding stay within boundaries you control.
Built for: large enterprise and federal programs.

Same engine. Same findings. Same standards. The only variable is where your data lives. In CLI and dedicated-tenant modes, your source, certificates, keys, and binaries are analyzed in place, with zero data egress, so you meet the deadline without breaking the data-residency rules you are already bound by.

Deploys as
Hosted cloudCLI in your perimeterDedicated tenantAir-gapped

Built for the highest-
stakes industries.

Where QuTrust delivers in the sectors that can't afford to get cryptography wrong.

Financial Services

Answer the board's question

Teams running multiple tools still can't say where RSA actually lives. QuTrust delivers one inventory across all seven surfaces — and a migration roadmap you can defend to regulators.

Healthcare

Protect data that has to outlive the threat

Patient data must stay protected for decades. QuTrust maps cryptographic exposure without a single byte of PHI leaving your environment, and drops findings straight into your HIPAA evidence.

Energy, Telecom & SaaS

Find crypto in systems you can't modify

Much of your cryptography is buried in systems you can't touch. Agentless analysis surfaces vulnerable TLS and aging certificates you didn't know you had — before an auditor does.

Blockchain & Digital Assets

Plan migration before the clock runs out

An exposed public key on an immutable ledger is a ticking clock. QuTrust analyzes your signing and custody stack so you can plan a migration while the math still protects the chain.

Built by the people who
defend the real thing.

Credentials
VOSBWOSBCAGESAM.gov registered and active
National-security pedigree
ArcQubit co-founders built a career inside big tech firms and high-stakes environment work, including Sandia National Laboratories, Pacific Northwest National Laboratory, and government research entities domestically and internationally. The people reading your risk exposure have defended the real thing.
Research, not marketing
Our solutions are grounded in peer-reviewed research, not slideware. ArcQubit's founders have authored dozens of publications, including the first framework to formally define dual quantum technology risk. The science is published, not promised.
Veteran-led, federal-ready
Co-founded and led by a U.S. Army combat veteran of the 82nd Airborne, ArcQubit already holds the credentials federal and defense work demands: VOSB, WOSB, CAGE, and active SAM.gov registration. The mission discipline and the contracting paperwork are both in place, not on a roadmap.
Enterprise and government fluency
The team has experience providing leadership across the Department of War, NASA, the Missile Defense Agency, the largest federal contractors in the country, and the International Atomic Energy Agency. That range means ArcQubit speaks two languages fluently: the commercial language of an enterprise decision-maker, and the compliance language of a federal program office.

Priced to your
deployment and boundary.

Every plan runs the same proprietary engine across all seven surfaces and maps findings to FIPS 203, 204, and 205. What changes is where it runs and how deep the compliance workflow goes. Start with a free audit, and we will scope from there.

Cloud
Custom
No-code, hosted in a secure cloud. Fastest path to a board-ready answer.
  • All 7 surfaces, one engine
  • No-code dashboard and connectors (GitHub)
  • CBOM, SBOM, and quantum exposure report
  • CMDB integration
Start free audit
Federal / Dedicated
Coming Soon
Custom
Sovereign and air-gap capable, within boundaries you control.
  • Everything in Enterprise
  • Dedicated single-tenant instance in your environment
  • Air-gapped deployment
  • FedRAMP, ITAR, and CMMC alignment and ATO support
Contact federal team

Just shipping code? QuCode is the self-serve, developer path, from $50 a month.

Frequently asked
questions.

How is QuTrust different from a scanner?
A scanner pattern-matches strings on one surface and hands you a list. QuTrust is a full-spectrum quantum exposure engine. It interprets what each artifact does across all seven surfaces, classifies its quantum risk, maps every finding to the GRC standard that replaces it, and turns the result into a prioritized migration roadmap. A scan is a snapshot. QuTrust is the plan.
What are the seven surfaces?
Source code, dependency manifests, existing SBOMs, certificates and keys, infrastructure configs, deployed binaries, and runtime JWT tokens. Most tools cover one. QuTrust covers all seven in a single engine.
Do we need an existing SBOM or CBOM to start?
No. QuTrust builds context from your raw artifacts, and it reads your asset inventory straight from the CMDB and other artifacts you already maintain, including ServiceNow and BMC Helix. If you already keep a CycloneDX or SPDX SBOM, QuTrust enriches it rather than re-analyzing it.
Where does our data live?
Wherever your rules require. Run QuTrust hosted in our cloud for speed, as a CLI inside your own perimeter, or as a dedicated tenant in your environment. In CLI and dedicated-tenant modes, your source, certificates, private keys, and binaries are analyzed in place, with zero data egress.
How do findings map to the standards our auditors ask about?
Every finding maps to FIPS 203, 204, and 205, with outputs aligned to CNSA 2.0, NIST IR 8547, and EO 14412. But FIPS is only the cryptographic layer. Because ArcQubit delivers context-aware GRC, those findings become evidence for the broader frameworks you answer to, including SOC 2, ISO 27001, PCI DSS, HIPAA, DORA, and CMMC, so one body of work serves many audits. QuTrust produces a CycloneDX CBOM, a dependency SBOM, and a quantum exposure report, all standards-native and ready for procurement, your auditor, or a customer's supply-chain security team.
What deadline are we actually working against?
There isn't one deadline, and it isn't only American. Mandates are converging worldwide between 2030 and 2035. In the U.S., Executive Order 14412 requires post-quantum key establishment on high-impact federal systems by 2030 and digital signatures by 2031, with covered contractors due by 2030. The EU's coordinated roadmap expects national plans by 2026 and critical-infrastructure migration by 2030, completing by 2035, reinforced by NIS2 and DORA. The UK's NCSC sets cryptographic discovery for 2028, high-priority upgrades by 2031, and full migration by 2035. Financial-sector programs align through DORA and FS-ISAC on phases between 2028 and 2032. A migration of this scale takes years, so wherever you operate, it needs to start now.
How does QuTrust relate to QuCode?
QuCode is the self-serve developer product, covering the five code-time surfaces from $50 a month. QuTrust is the enterprise product, covering all seven surfaces with full deployment, sovereignty, and compliance options. Teams often start with QuCode and grow into QuTrust as the organization scales.
VOSBWOSBCAGESAM.gov active
Built by people from Sandia National Laboratories, Pacific Northwest National Laboratory, NASA, the Missile Defense Agency, and the IAEA.

See your full cryptographic
exposure. All seven surfaces.

Run QuTrust in our cloud for a board-ready answer in minutes, or inside your own perimeter where your data never leaves your network. Either way: every surface, every finding mapped to FIPS, file by file. No Docker. No guesswork about what got missed.

Start your free audit

Hosted cloud, CLI, or dedicated tenant. Federal & enterprise: book a working session.