
KavachQ is a quantum-safe migration platform that helps Indian enterprises and Critical Information Infrastructure operators transition to post-quantum cryptography (PQC) ahead of National Quantum Mission deadlines. It provides end-to-end cryptographic discovery, quantum-risk scoring, and phased migration planning aligned to NIST standards and the DST Task Force roadmap, with evidence deliverables built for Indian regulators.
Funding
Funding not disclosed
Founders
Product
Problem
Most Indian organizations lack a complete inventory of their cryptographic assets, leaving quantum-vulnerable algorithms like RSA and ECC hidden across TLS endpoints, certificates, and legacy systems. With the DST Task Force recommending CII achieve full PQC adoption by 2029 and enterprises by 2033, organizations face compressed timelines to migrate before quantum computers can break current encryption—yet most have no executive owner or credible plan in place.
Solution
KavachQ provides a single platform covering the entire quantum-safe migration journey, from cryptographic discovery to board-ready evidence. The platform builds a signed Cryptographic Bill of Materials (CBOM) in CycloneDX 1.6 format across an organization's estate, scores every asset with a 0–100 quantum-risk score and T1–T4 tier, and generates a phased, impact-aware migration plan to NIST-standard algorithms ML-KEM, ML-DSA, and SLH-DSA. It operates read-only, never touching production keys or making changes, and can be deployed in-VPC, on-premises, or air-gapped. The final output includes a board-ready PDF and machine-readable CBOM tagged to DST/NQM milestones and RBI/SEBI/CERT-In references, ensuring auditors and regulators can reproduce the evidence.
Target Audience
Primary customers are Critical Information Infrastructure operators (defence, power, telecom, banking) and large Indian enterprises in regulated sectors such as financial services and healthcare, along with CISOs and migration teams needing DST-aligned quantum-readiness evidence.
Features
- Automated crypto discovery covering public TLS, source and config scanning with file-path-level findings, and cloud estate discovery via read-only AWS/Azure CLI exports
- CBOM generation in open CycloneDX 1.6 with linkage across six asset categories: algorithms, protocols, keys, certificates, libraries, and hardware tokens
- Quantum-risk scoring (0–100) with T1–T4 tiering weighted by algorithm strength, internet exposure, criticality, cert expiry, and harvest-now risk
- Phased migration planning with crypto-agility patterns (layered interfaces, policy-driven algorithm selection) enabling future algorithm swaps as config changes
- Signed, provenance-tracked CBOM exports in CycloneDX 1.6 or SPDX 2.3, plus Jira/CSV handoff for execution tracking
- Free public TLS scan for instant risk assessment without sign-in; deployment options include managed scan, in-VPC, on-prem, or air-gapped Docker