SCAN
7-module cryptographic discovery across code, TLS, binaries, K8s Secrets, infrastructure, dependencies, and legacy PDFs using Claude Vision AI.
KAVACH-Q discovers vulnerable cryptography, calculates Quantum Vulnerability Scores, and helps enterprises migrate to post-quantum-safe algorithms with audit-ready compliance.
End-to-End Automation
Each stage automatically hands off to the next—from discovery and prioritisation to secure migration and compliance evidence.
7-module cryptographic discovery across code, TLS, binaries, K8s Secrets, infrastructure, dependencies, and legacy PDFs using Claude Vision AI.
Kafka 3.5 asynchronous pipeline. The API returns a scan ID in under two seconds. Celery workers and priority queues support national-scale deployment.
The QVS Engine uses vectorised risk scoring for every finding. Five decision-ready risk tiers explain each result in simple language.
Generate ML-KEM-768, ML-DSA-65 and SLH-DSA migration plans. Select hybrid or PQC-only strategies and route critical changes through CAB approval.
A secure on-premise agent deploys migrations inside protected and air-gapped networks. Mandatory dry runs and automatic rollback reduce deployment risk.
Generate digitally signed evidence reports with trusted timestamps. Every finding is mapped to applicable CERT-In, RBI and ISO 27001 requirements.
CERT-IN · RBI · ISO 27001 · MeitY NQM Aligned
KAVACH-Q discovers RSA, ECC, and legacy cryptographic assets across your technology estate, scores them against NIST FIPS 203, 204, and 205, and maps each finding to applicable CERT-IN, RBI, and ISO 27001:2022 requirements.
Every finding—from expired certificates and SHA-1 usage to hardcoded keys and unencrypted DPDPA-covered data—is risk-scored, mapped to the relevant compliance requirement, and included in an exportable, audit-ready report.
Applications, APIs, certificates, infrastructure, containers, dependencies, binaries, and legacy systems—all visible through one centralized cryptographic inventory.
Every certificate, key, and algorithm—mapped into a Cryptographic Bill of Materials (CBOM).
A 0–100 quantum-vulnerability score for each asset, prioritized against applicable CERT-IN and RBI requirements.
A board-ready migration plan supported by signed, auditor-verifiable compliance evidence.
National Quantum Mission Outlay
Government of India · 2023–24 to 2030–31
NQM Programme Period
India’s national quantum ecosystem initiative
Finalized NIST PQC Standards
ML-KEM · ML-DSA · SLH-DSA
CERT-In Technical Guidance
Cryptographic and quantum asset visibility
The operational backbone of KAVACH-Q—enabling scalable security assessments, real-time progress visibility, automatic recovery, and compliance-ready audit traceability.
Processes security scans in parallel across growing enterprise environments without interrupting ongoing operations.
Automatically manages priorities, retries, schedules, timeouts, and recovery to keep critical security workflows running.
Provides real-time scan progress, status updates, controlled cancellation, and immediate visibility through the dashboard.
Every cryptographic asset receives a Quantum Vulnerability Score between 0 and 100 — computed using a proprietary scoring methodology and environment-aware risk multipliers. Provisional patent filed with IP India before any external demo.
QVS Assessment Model
QVS combines cryptographic, exposure, data and environmental signals through a proprietary weighted methodology to produce a normalized risk score from 0 to 100.
Evaluates the security characteristics and resilience of cryptographic assets against emerging quantum threats.
Considers how cryptographic assets are exposed across systems, services, infrastructure and external interfaces.
Accounts for the sensitivity and long-term value of information protected by cryptographic assets.
Considers the operational and business context surrounding each cryptographic asset.
Considers the practical complexity and effort involved in transitioning affected assets.
Assessment Context
Cryptographic + Environment Signals
Proprietary Engine
Weighted Risk Methodology
Output
QVS · 0–100
QVS Assessment Pipeline
Repositories, certificates, binaries, infrastructure, containers and cryptographic assets across the enterprise.
Evaluate cryptographic, exposure, data and environmental context using the QVS methodology.
Classify findings by risk and generate migration priorities with clear remediation guidance.
QVS findings are grouped into risk tiers to help security teams prioritize remediation and migration activities.
Immediate remediation
Priority remediation
Planned remediation
Monitor & schedule
Monitor
WebSocket progress streams provide near real-time scan visibility. Resilient asynchronous processing allows scans to resume after agent disconnects, with encrypted checkpoints maintained in Redis.
scan_id is returned immediately, keeping scan requests asynchronous and preventing duplicate submissions.
Critical · Standard · Background — prioritized processing for time-sensitive security findings.
AES-256-GCM encrypted Redis checkpoints allow interrupted scans to resume from the last completed file batch.
Scan only files changed since the last commit SHA to reduce unnecessary scanning and compute.
DEMO TENANT · Synthetic organization, endpoints, files and findings shown for illustration only. No client or government infrastructure is represented.
scanner@kavachq:~$ scan --org ORG_DEMO --depth FULL
Initialising 7 scanner modules...
✓ tree-sitter AST · Java/Python/Go/C++/JS
✓ sslyze TLS · demo endpoints queued
✓ Kafka scan-requests topic published
──────────────────────────────────
⚠ [M1] RSA-2048 · PaymentGateway.java:142
method: RSAKey.generate(2048) · AST · HIGH
✓ QVS: 91 → CRITICAL · Demo SLA: 30 days
✗ [M2] TLS 1.1 + Expired cert · api.demo.internal
RSA-2048 · Certificate expired · DEMO FINDING
✓ PKI policy citation attached
⚠ [M6] Legacy PDF · Bank_Sandbox_01_Mainframe.pdf
Document analysis: DES-56 on p.14 · HIGH
✓ QVS: 98 → CRITICAL · Demo plan triggered
scanner@kavachq:~$
Stage 6 · Comply
Claude Citations API maps every finding to the relevant regulatory clause, page, and section. Reports are digitally signed, timestamped, and archived for audit review.
Cyber Security Framework
Crypto Policy, TLS Guidelines, PKI Guidelines, PQC Advisory, Hash Standards, SDLC Security, and Audit Framework.
IT & Cyber Security Framework
IT Framework, Cyber Security, PKI Policy, SDLC, and Future-Ready Security guidelines prepared for inspection.
Annex A Controls
A.10.1.1, A.10.1.2, A.14.1.2, and A.12.4.1 mapped automatically per finding.
India regulatory coverage
National Quantum Mission guidance and DPDPA 2023 Section 8(5) personal data protection requirements.
Compliance Mapping Matrix
| Finding | CERT-IN | RBI Clause | Severity |
|---|---|---|---|
RSA-1024 in production | Crypto Policy §3.1 | IT Framework §5.2 | CRITICAL |
RSA-2048 in production | Crypto Policy §3.1 | IT Framework §5.2 | HIGH |
TLS < 1.3 enabled | TLS Guidelines §2.4 | Cyber Sec §4.1 | HIGH |
No PQC migration plan | PQC Advisory §1.3 | Future-Ready §3.2 | HIGH |
Expired certificates | PKI Guidelines §5.1 | PKI Policy §7.3 | CRITICAL |
SHA-1 in use | Hash Standards §4.2 | Crypto Baseline §2.1 | HIGH |
Hardcoded keys in source | SDLC Security §4.3 | SDLC Framework §3.1 | CRITICAL |
DPDPA data unencrypted | — | Data Privacy §2.3 | CRITICAL |
ECDH without PQC upgrade | PQC Advisory §2.1 | Future-Ready §3.4 | MEDIUM |
KAVACH-Q focuses on sectors where cryptographic failure has national, regulatory, or public-service impact, from government systems to finance and infrastructure.
NIC-hosted portals, ministry APIs, and citizen-services platforms — including legacy documents readable only through vision-assisted analysis.
RBI-regulated banks, SEBI-registered firms, insurance companies, and payment processors with clause-level reporting for regulatory review.
Power grids, telecom networks, water treatment, railways, and defence contractors where source access may be partial or unavailable.
KAVACH-Q is deployed as a controlled platform for government and regulated institutions: tenant isolation, SSO, data residency, scoped asset discovery, QVS scoring, migration controls, and audit-ready compliance evidence.
Configure the organization tenant, RBAC roles, SSO, data residency, retention policy, and immutable audit logging before scans begin.
Register repositories, servers, APIs, binaries, TLS endpoints, SBOMs, and internal environments with scoped credentials or private connectors.
All 7 scanner modules run against internal targets. QVS scores computed in real time.CRITICAL findings trigger CISO alerts within 4 hours; remediation follows the applicable severity-based SLA. Coverage reports identify and flag coverage gaps
Use CI/CD policy gates, dry-run migration controls, owner assignments, and compliance exports for CERT-IN, RBI, ISO 27001, and internal audits.
Start your crypto inventory today. KAVACH-Q gives you a complete cryptographic posture report, QVS scores for every asset, and a CERT-IN aligned remediation roadmap.
Alert: 4h · Report: 24h · Remediation SLA: 30 days
Built in India. For India.