foss.violetskysecurity.com / tools

PQChecker.

Every other post-quantum checker answers one question about one host: does it speak ML-KEM. This one runs eight steps against every hop a transaction actually traverses, separates the two clocks that PQ migration runs on, and fails closed at the exact step. Posture is not inherited: a quantum-safe front door in front of a classical hop is classical end to end. Verification runs entirely in your browser — the handshakes happen in a local probe, this page only verifies and renders the receipt. The one exception is the optional live scan, which sends the hostname you type to this site and performs the handshakes there.

Sample chain

synthetic · agentic payment path
inject a fault

Pick a fault and watch the engine stop at the step that catches it. The same eight steps run whether the endpoint is a VASP settlement rail or an agent's tool endpoint — the check does not care who holds the connection, only what the handshake proves.

Select a chain to run the engine.

Exposure horizon

two clocks · one axis
anchor

Chain

verdict = weakest hop

Engine

Downgrade ladder

Withholds capabilities from the client side, one rung at a time, and records the worst handshake this hop will still complete. Nothing is intercepted or injected — each rung is an ordinary outbound connection with a restricted ClientHello, which is the only thing a client can measure.

Receipt

unsigned · synthetic