SCAN
7-module cryptographic discovery across code, TLS, binaries, K8s Secrets, infra, dependencies, and legacy PDFs via Claude Vision AI.
KAVACH-Q discovers vulnerable cryptography, calculates Quantum Vulnerability Scores, and helps enterprises migrate to post-quantum-safe algorithms with audit-ready compliance.
End-to-End Automation
Each stage hands off to the next automatically — scan, prioritise, score, plan, execute, and prove compliance — without manual intervention at any step.
7-module cryptographic discovery across code, TLS, binaries, K8s Secrets, infra, dependencies, and legacy PDFs via Claude Vision AI.
Kafka 3.5 async pipeline. API returns scan_id in <2s. Celery workers with 3-tier priority queues scale to national deployment. Dead Letter Queue — no silent failures.
QVS Engine: NumPy-vectorised scoring of every finding. Five decision-ready tiers. Claude Batch API explains each score in plain language.
liboqs generates ML-KEM-768, ML-DSA-65, SPHINCS+ key artifacts. Hybrid or PQC-Only strategy per asset. CAB approval workflow. Claude Extended Thinking for critical decisions.
Go on-premise agent (<20MB, mTLS) deploys inside air-gapped networks. OPA Policy-as-Code blocks vulnerable crypto in every PR. Mandatory dry-run. Auto-rollback on failure.
Digitally signed PDFs with RFC 3161 timestamp. Claude Citations API maps every finding to CERT-IN, RBI, ISO 27001 clauses with exact page references. 10-year immutable archive.
What KAVACH-Q Does
KAVACH-Q helps organizations understand where cryptography exists across their technology landscape and identifies assets that may be vulnerable in a post-quantum world.
The platform automatically discovers cryptographic implementations, evaluates security posture, highlights potential quantum-era risks, generates evidence-backed findings, and provides actionable guidance for future migration planning.
From applications and APIs to certificates, infrastructure, containers, dependencies, binaries, and legacy systems, KAVACH-Q provides a centralized view of cryptographic exposure and organizational readiness.
Identify cryptographic assets and security dependencies across enterprise environments.
Evaluate cryptographic exposure and understand potential quantum-related risks.
Build a roadmap for future quantum-safe migration and compliance readiness.
Pipeline Stages
Scanner Modules
Detection Accuracy
Quantum Risk Score
The nervous system of KAVACH-Q — decoupling scan submission from execution, enabling national-scale parallel processing, real-time progress, fault recovery, and compliance-grade audit trails.
Durable event backbone for scan-requests, scan-results, qvs-scores, audit-events, and dead-letter pipelines.
Priority worker pools with retries, scheduling, fault recovery, timeout control, and async scan execution.
Live progress state, cancellation flags, real-time dashboard streaming, and instant scan visibility.
Every cryptographic asset receives a Quantum Vulnerability Score between 0 and 100 — computed using a proprietary scoring methodology and environment-aware risk multipliers. Provisional patent filed with IP India before any external demo.
Repositories, certificates, binaries, infrastructure, containers and cryptographic assets across the enterprise.
Evaluate exposure, migration effort, data sensitivity and operational impact using the QVS methodology.
Automatically classify findings into risk tiers and generate migration priorities with clear remediation timelines.
85–100
Block CI/CD · CISO alert within 4 hrs
65–84
Current sprint · weekly check
40–64
Next migration cycle · monthly review
20–39
Future refresh · quarterly review
0–19
PQC-safe or non-critical · monitor
WebSocket progress streams every 2 seconds. Scan resumes automatically after agent disconnect — AES-256-GCM encrypted checkpoints in Redis. 100,000-file repo completed in under 4 hours.
scan_id returned instantly — no browser timeout, no duplicate submissions
Critical (80% capacity) · Standard (15%) · Background (5%)
AES-256-GCM Redis checkpoint — restarts from last file batch in <5 min
90% compute reduction — scan only files changed since last commit SHA
scanner@kavachq:~$ scan --org MINISTRY_FIN --depth FULL
Initialising 7 scanner modules...
✓ tree-sitter AST · Java/Python/Go/C++/JS
✓ sslyze TLS · 1,247 endpoints queued
✓ Kafka scan-requests topic published
──────────────────────────────────
⚠ [M1] RSA-2048 · PaymentGateway.java:142
method: RSAKey.generate(2048) · AST · HIGH
✓ QVS: 91 → CRITICAL · SLA: 30 days
✗ [M2] TLS 1.1 + Expired cert · api.fin.gov.in
RSA-2048 · Expiry: 2025-03-14 · EXPIRED
✓ CERT-IN PKI §5.1 citation attached
⚠ [M6] Legacy PDF · SBI_1998_Mainframe.pdf
Claude Vision: DES-56 on p.14 · HIGH
✓ QVS: 98 → CRITICAL · Plan triggered
scanner@kavachq:~$
Stage 6 · Comply
Claude Citations API maps every finding to the relevant regulatory clause, page, and section. Reports are digitally signed, timestamped, and archived for audit review.
Cyber Security Framework
Crypto Policy, TLS Guidelines, PKI Guidelines, PQC Advisory, Hash Standards, SDLC Security, and Audit Framework.
IT & Cyber Security Framework
IT Framework, Cyber Security, PKI Policy, SDLC, and Future-Ready Security guidelines prepared for inspection.
Annex A Controls
A.10.1.1, A.10.1.2, A.14.1.2, and A.12.4.1 mapped automatically per finding.
India regulatory coverage
National Quantum Mission guidance and DPDPA 2023 Section 8(5) personal data protection requirements.
Compliance Mapping Matrix
| Finding | CERT-IN | RBI Clause | Severity |
|---|---|---|---|
RSA-1024 in production | Crypto Policy §3.1 | IT Framework §5.2 | CRITICAL |
RSA-2048 in production | Crypto Policy §3.1 | IT Framework §5.2 | HIGH |
TLS < 1.3 enabled | TLS Guidelines §2.4 | Cyber Sec §4.1 | HIGH |
No PQC migration plan | PQC Advisory §1.3 | Future-Ready §3.2 | HIGH |
Expired certificates | PKI Guidelines §5.1 | PKI Policy §7.3 | CRITICAL |
SHA-1 in use | Hash Standards §4.2 | Crypto Baseline §2.1 | HIGH |
Hardcoded keys in source | SDLC Security §4.3 | SDLC Framework §3.1 | CRITICAL |
DPDPA data unencrypted | — | Data Privacy §2.3 | CRITICAL |
ECDH without PQC upgrade | PQC Advisory §2.1 | Future-Ready §3.4 | MEDIUM |
KAVACH-Q focuses on sectors where cryptographic failure has national, regulatory, or public-service impact, from government systems to finance and infrastructure.
NIC-hosted portals, ministry APIs, Aadhaar-linked services, and classified document systems, including legacy documents only readable through vision-assisted analysis.
RBI-regulated banks, SEBI-registered firms, insurance companies, and payment processors with clause-level reporting for regulatory review.
Power grids, telecom networks, water treatment, railways, and defence contractors where source access may be partial or unavailable.
KAVACH-Q is deployed as a controlled platform for government and regulated institutions: tenant isolation, SSO, data residency, scoped asset discovery, QVS scoring, migration controls, and audit-ready compliance evidence.
Configure the organization tenant, RBAC roles, SSO, data residency, retention policy, and immutable audit logging before scans begin.
Register repositories, servers, APIs, binaries, TLS endpoints, SBOMs, and internal environments with scoped credentials or private connectors.
All 7 scanner modules run against internal targets. QVS scores computed in real time. CRITICAL findings trigger CISO alerts within 4 hours. Coverage report flags <98% gaps.
Use CI/CD policy gates, dry-run migration controls, owner assignments, and compliance exports for CERT-IN, RBI, ISO 27001, and internal audits.
Start your crypto inventory today. KAVACH-Q gives you a complete cryptographic posture report, QVS scores for every asset, and a CERT-IN aligned remediation roadmap.
Built in India.for India.