🛡️ ISO/IEC 27001:2022
GAINT · National PQC Platform · 2026

Secure Your
Enterprise For
The Quantum Era

KAVACH-Q discovers vulnerable cryptography, calculates Quantum Vulnerability Scores, and helps enterprises migrate to post-quantum-safe algorithms with audit-ready compliance.

CERT-IN Aligned
RBI Framework
ISO 27001:2022
NIST FIPS 203/204/205
78
Quantum Risk
RSA-2048
Quantum Vulnerable · QVS 91
Algorithm
ML-KEM-768
Migrated · PQC Safe
RSA-2048
Quantum Vulnerable · QVS 91
ML-KEM-768
Post Quantum Ready
🔐
ML-DSA
Dilithium Standard
SLH-DSA
Hash-Based PQC
1,248
Repositories
3,592
Servers
842
Containers
2,116
Documents
98.7%
Coverage

End-to-End Automation

Six stages. One platform.Zero quantum blindspots.

Each stage hands off to the next automatically — scan, prioritise, score, plan, execute, and prove compliance — without manual intervention at any step.

01
Stage 01

SCAN

7-module cryptographic discovery across code, TLS, binaries, K8s Secrets, infra, dependencies, and legacy PDFs via Claude Vision AI.

FR-1.1 → FR-1.7
02
Stage 02

QUEUE

Kafka 3.5 async pipeline. API returns scan_id in <2s. Celery workers with 3-tier priority queues scale to national deployment. Dead Letter Queue — no silent failures.

Kafka · Celery · Redis
03
Stage 03

SCORE

QVS Engine: NumPy-vectorised scoring of every finding. Five decision-ready tiers. Claude Batch API explains each score in plain language.

Risk Scoring · QVS Engine
04
Stage 04

PLAN

liboqs generates ML-KEM-768, ML-DSA-65, SPHINCS+ key artifacts. Hybrid or PQC-Only strategy per asset. CAB approval workflow. Claude Extended Thinking for critical decisions.

NIST FIPS 203/204/205
05
Stage 05

EXECUTE

Go on-premise agent (<20MB, mTLS) deploys inside air-gapped networks. OPA Policy-as-Code blocks vulnerable crypto in every PR. Mandatory dry-run. Auto-rollback on failure.

OPA · mTLS · Zero-Touch
06
Stage 06

COMPLY

Digitally signed PDFs with RFC 3161 timestamp. Claude Citations API maps every finding to CERT-IN, RBI, ISO 27001 clauses with exact page references. 10-year immutable archive.

CERT-IN · RBI · ISO 27001

What KAVACH-Q Does

Discover. Analyze.Prepare for Quantum Security.

KAVACH-Q helps organizations understand where cryptography exists across their technology landscape and identifies assets that may be vulnerable in a post-quantum world.

The platform automatically discovers cryptographic implementations, evaluates security posture, highlights potential quantum-era risks, generates evidence-backed findings, and provides actionable guidance for future migration planning.

From applications and APIs to certificates, infrastructure, containers, dependencies, binaries, and legacy systems, KAVACH-Q provides a centralized view of cryptographic exposure and organizational readiness.

Discover

Identify cryptographic assets and security dependencies across enterprise environments.

Assess

Evaluate cryptographic exposure and understand potential quantum-related risks.

Prepare

Build a roadmap for future quantum-safe migration and compliance readiness.

01
01

6

Pipeline Stages

02
02

7

Scanner Modules

03
03

>=95%

Detection Accuracy

04
04

QVS

Quantum Risk Score

Stage 2 · Queue

Kafka Async Job Pipeline

The nervous system of KAVACH-Q — decoupling scan submission from execution, enabling national-scale parallel processing, real-time progress, fault recovery, and compliance-grade audit trails.

01Active

Kafka 3.5

Durable event backbone for scan-requests, scan-results, qvs-scores, audit-events, and dead-letter pipelines.

02Active

Celery Workers

Priority worker pools with retries, scheduling, fault recovery, timeout control, and async scan execution.

03Active

Redis + WebSocket

Live progress state, cancellation flags, real-time dashboard streaming, and instant scan visibility.

6
Kafka Topics
8
Queue Modules
15
Test Cases
11
Gap Fixes
<2s
API SLA
Priority Queues
Dead Letter Queue
Real-Time Progress
Auto Scaling
OpenTelemetry
Audit Trail
Kafka EOS
Scheduled Scans

The QVS Formula —quantum risk in one number.

Every cryptographic asset receives a Quantum Vulnerability Score between 0 and 100 — computed using a proprietary scoring methodology and environment-aware risk multipliers. Provisional patent filed with IP India before any external demo.

QVS = Proprietary Quantum Risk Intelligence

Discover

Scan Everything

Repositories, certificates, binaries, infrastructure, containers and cryptographic assets across the enterprise.

Analyse

Calculate Risk

Evaluate exposure, migration effort, data sensitivity and operational impact using the QVS methodology.

Prioritise

Take Action

Automatically classify findings into risk tiers and generate migration priorities with clear remediation timelines.

Risk Tiers & Mandated SLAs

85–100

CRITICAL

Block CI/CD · CISO alert within 4 hrs

30 days

65–84

HIGH

Current sprint · weekly check

90 days

40–64

MEDIUM

Next migration cycle · monthly review

6 months

20–39

LOW

Future refresh · quarterly review

12 months

0–19

NEGLIGIBLE

PQC-safe or non-critical · monitor

Live Operations

Real-time detection.
Zero-touch response.

WebSocket progress streams every 2 seconds. Scan resumes automatically after agent disconnect — AES-256-GCM encrypted checkpoints in Redis. 100,000-file repo completed in under 4 hours.

<2s API response via Kafka async pipeline

scan_id returned instantly — no browser timeout, no duplicate submissions

3-tier priority queues

Critical (80% capacity) · Standard (15%) · Background (5%)

Scan resume on disconnect

AES-256-GCM Redis checkpoint — restarts from last file batch in <5 min

Git-diff differential scanning

90% compute reduction — scan only files changed since last commit SHA

kavachq-scanner v1.0 · LIVE

scanner@kavachq:~$ scan --org MINISTRY_FIN --depth FULL

Initialising 7 scanner modules...

✓ tree-sitter AST · Java/Python/Go/C++/JS

✓ sslyze TLS · 1,247 endpoints queued

✓ Kafka scan-requests topic published

──────────────────────────────────

⚠ [M1] RSA-2048 · PaymentGateway.java:142

method: RSAKey.generate(2048) · AST · HIGH

✓ QVS: 91 → CRITICAL · SLA: 30 days

✗ [M2] TLS 1.1 + Expired cert · api.fin.gov.in

RSA-2048 · Expiry: 2025-03-14 · EXPIRED

✓ CERT-IN PKI §5.1 citation attached

⚠ [M6] Legacy PDF · SBI_1998_Mainframe.pdf

Claude Vision: DES-56 on p.14 · HIGH

✓ QVS: 98 → CRITICAL · Plan triggered

scanner@kavachq:~$

Stage 6 · Comply

Legally defensible reports.Zero manual mapping.

Claude Citations API maps every finding to the relevant regulatory clause, page, and section. Reports are digitally signed, timestamped, and archived for audit review.

Cyber Security Framework

CERT-IN

Crypto Policy, TLS Guidelines, PKI Guidelines, PQC Advisory, Hash Standards, SDLC Security, and Audit Framework.

IT & Cyber Security Framework

RBI

IT Framework, Cyber Security, PKI Policy, SDLC, and Future-Ready Security guidelines prepared for inspection.

Annex A Controls

ISO 27001:2022

A.10.1.1, A.10.1.2, A.14.1.2, and A.12.4.1 mapped automatically per finding.

India regulatory coverage

MeitY NQM · DPDPA

National Quantum Mission guidance and DPDPA 2023 Section 8(5) personal data protection requirements.

Compliance Mapping Matrix

Findings with clause-level traceability

FindingCERT-INRBI ClauseSeverity
RSA-1024 in production
Crypto Policy §3.1IT Framework §5.2CRITICAL
RSA-2048 in production
Crypto Policy §3.1IT Framework §5.2HIGH
TLS < 1.3 enabled
TLS Guidelines §2.4Cyber Sec §4.1HIGH
No PQC migration plan
PQC Advisory §1.3Future-Ready §3.2HIGH
Expired certificates
PKI Guidelines §5.1PKI Policy §7.3CRITICAL
SHA-1 in use
Hash Standards §4.2Crypto Baseline §2.1HIGH
Hardcoded keys in source
SDLC Security §4.3SDLC Framework §3.1CRITICAL
DPDPA data unencrypted
Data Privacy §2.3CRITICAL
ECDH without PQC upgrade
PQC Advisory §2.1Future-Ready §3.4MEDIUM
Target Sectors

Built for India's mostcritical institutions.

KAVACH-Q focuses on sectors where cryptographic failure has national, regulatory, or public-service impact, from government systems to finance and infrastructure.

Government

Central & State Government

NIC-hosted portals, ministry APIs, Aadhaar-linked services, and classified document systems, including legacy documents only readable through vision-assisted analysis.

  • CERT-IN and MeitY regulatory alignment
  • Private deployment and data residency controls
  • Legacy document and configuration discovery
Regulated Finance

BFSI — Banks, Insurance, Finance

RBI-regulated banks, SEBI-registered firms, insurance companies, and payment processors with clause-level reporting for regulatory review.

  • RBI cyber security framework coverage
  • Repository, API, TLS, and SBOM scanning
  • DPDPA 2023 encryption checks
National Assets

Critical Infrastructure

Power grids, telecom networks, water treatment, railways, and defence contractors where source access may be partial or unavailable.

  • Runtime, firmware, and binary inspection
  • SCADA and legacy component visibility
  • Controlled scanning with no data exfiltration
Secure Deployment

Built for privatenational-scale rollout.

KAVACH-Q is deployed as a controlled platform for government and regulated institutions: tenant isolation, SSO, data residency, scoped asset discovery, QVS scoring, migration controls, and audit-ready compliance evidence.

01

Tenant & Access

Configure the organization tenant, RBAC roles, SSO, data residency, retention policy, and immutable audit logging before scans begin.

02

Connect Assets

Register repositories, servers, APIs, binaries, TLS endpoints, SBOMs, and internal environments with scoped credentials or private connectors.

03

Scan & Score

All 7 scanner modules run against internal targets. QVS scores computed in real time. CRITICAL findings trigger CISO alerts within 4 hours. Coverage report flags <98% gaps.

04

Enforce & Report

Use CI/CD policy gates, dry-run migration controls, owner assignments, and compliance exports for CERT-IN, RBI, ISO 27001, and internal audits.

Start Today

India's quantum clockis ticking.

Start your crypto inventory today. KAVACH-Q gives you a complete cryptographic posture report, QVS scores for every asset, and a CERT-IN aligned remediation roadmap.

7
Scanner Modules
QVS
Quantum Risk Scoring
24h
Compliance Reporting
CERT-IN • RBI • ISO 27001 • NIST PQC • DPDPA 2023

Built in India.for India.