A real handshake, not a lookup
The server opens a TCP connection to port 443 and reads the certificate chain the endpoint actually presents, then walks its issuerCertificate links. If a host is down, the assay fails and says so.
Post-quantum migration triage
Every TLS session an adversary records today becomes readable the day a cryptographically relevant quantum computer exists — if the key it protects has not been replaced by then. Rotating the certificate does not help, because the captured traffic is already in their hands. Keyassay names the year each of your public endpoints stops being secret, and certifies the answer with a sealed, replayable record.
0 assays in this session · open the ledger
How a grade is struck
A post-quantum signature is already deployed, or the key cannot plausibly be broken before your data must expire.
Adequate strength with margin. Migration fits the normal replacement cycle rather than an emergency.
A CRQC is modelled to break the key inside the confidentiality horizon you set. Start planning the hybrid migration.
Traffic captured today is assumed to be readable before it must expire. Treat it as a harvest-now-decrypt-later incident.
The server opens a TCP connection to port 443 and reads the certificate chain the endpoint actually presents, then walks its issuerCertificate links. If a host is down, the assay fails and says so.
Exposure is measured against the year your data must stay secret. A certificate that expires in ninety days does not protect a session captured today from being decrypted in twenty years.
Every mutation appends to a SHA-384 hash chain. Download the certificate, replay the chain months later, and prove the grade was never quietly edited.
Everything runs in the open
Nine MCP tools over one service layer: read the ledger, assay a live host, re-rate against a different risk position, seal a decision, verify a chain, export a certificate. No API keys, no accounts, no third party to sign up for.
NIST IR 8547 (ipd), Transition to Post-Quantum Cryptography Standards: 112-bit-strength public keys deprecated after 2030; all quantum-vulnerable public key algorithms disallowed after 2035 · default horizon 2040 · cost anchor Base physical qubit count anchored to publicly announced processor sizes (IBM Condor 1,121 qubits, Dec 2023); annual growth is a user-set assumption, not a forecast.