Post-quantum readiness
0dq
You cannot migrate cryptography you cannot see.
Every institution knows it will have to move to post-quantum cryptography. Almost none can answer the first question a regulator will ask. That inventory does not exist, because no scanner has ever produced it — they look for vulnerabilities, not for cryptography.
0dq scores six pillars as one number with the arithmetic shown: quantum readiness at 30%, then code, dependencies, secrets, infrastructure and licences. Five of those you already have from other tools. The first one you do not, and it is the one a post-quantum programme starts with.
Findings carry a reachability verdict — called, not called, dead code, dev only — so the list is ordered by what can actually run rather than by severity alone. Where a fix is mechanical, it opens the pull request. Point it at a repository and it answers in minutes: no agent, no integration project.
The question it answers
Which cryptography are we running, in which systems, protecting what?
Asked by: The regulator
What is known
Every figure below carries its source. Where we have not measured something, we do not have a figure for it.
NIST published ML-KEM, ML-DSA and SLH-DSA in August 2024. What to migrate to is no longer an open question — only what to migrate, and in what order.
NISTThird-party, publishedCryptography and key management are already named control domains under the CBUAE Information Security Regulation and Operational Risk Standard.
CBUAEThird-party, publishedSix pillars, weighted into one score: quantum readiness 30%, code 18%, dependencies 17%, secrets 13%, infrastructure 12%, licences 10%.
0dq scoring modelProduct behaviourStatic analysis runs 2,452 rules across OWASP Top Ten and CWE Top 25. Secrets are found in commit history, not only the working tree.
0dq scannerProduct behaviourEvery finding carries a reachability verdict — called, not called, dead code, dev only — so the queue is ordered by what can run, not by severity alone.
0dq findings viewProduct behaviourRuns in the browser, on the command line, as a pipeline gate, and as a pre-commit hook that stops a credential locally in under a second.
0dq surfacesProduct behaviour