The platform

How EQCore™ takes you from blind spots to quantum-safe

One control plane, four stages: connect EQCore to your estate, discover the cryptography you run, analyse the risk against NIST and operationalise the result in the tools your team already uses.

NIST-Aligned ISO 27001 AUKUS Authorised Available Now

The journey

Four stages, one control plane

EQCore is a single platform with three surfaces (CipherScout™, CipherForge™ and CipherWatch™) over a shared scanner and scoring engine. Here is how a programme moves through it.

01 · Connect

Deploy EQCore and reach your estate

Stand up EQCore as cloud SaaS, a sovereign on-premises box or fully air-gapped. For internal estates, the on-premises box runs discovery inside your network, and your data stays within your boundary.

02 · Discover

Map the cryptography you run

CipherScout’s ~50 proprietary scanners surface the protocols, keys, certificates and algorithms across your network, certificates, applications and data layer, consolidated into a Cryptographic Bill of Materials (CBOM).

03 · Analyse

Score the risk, plan and execute the fix

Each finding is scored for quantum risk and mapped to a NIST control, then classified as a KEM or signature swap. EQCore turns the CBOM into a framework-filtered remediation plan, which CipherForge then executes.

04 · Operationalise

Alert, route and keep watch

CipherWatch generates alerts on every scan and on your schedule, then routes them to Slack, ServiceNow and your SIEM (Splunk, QRadar or any HTTPS webhook).

Stage 01 · Connect

Deploy where your data must live

EQCore is sovereign by design. Choose the deployment that matches your data-residency rules, then reach the internal assets a cloud scan never could.

01

Three deployment modes

Run EQCore as cloud SaaS, as a sovereign on-premise box or fully air-gapped. The on-premise box installs from a signed bundle verified per-box.

02

On-premise discovery

The on-premise box discovers assets and maps topology inside your network - no cloud round-trip - so internal and air-gapped estates are in scope from day one.

03

Sovereign by default

Per-tenant isolation, central egress controls and target-bound, whitelisted scans keep discovery data-residency-preserving and within your boundary.

Stage 02 · Discover

See the cryptography across your estate

CipherScout detects cryptographic posture and inventory across your estate, mapping what you run rather than exploiting it, and emits a structured CBOM you can act on.

Network & transport

Protocols on the wire

TLS, SSH key exchange and host keys, certificate scans, security headers and network mapping.

Certificates & keys

Keys & crypto material

JWKS, PEM, TLSA, DNSKEY and CAA records, certificate revocation (OCSP/stapling), deprecated algorithms and DKIM key audit.

Applications & APIs

Crypto in your apps

API quantum-vulnerability scoring, CORS / SSRF / JWT exposure checks, OAuth audit and JWT weakness detection.

Data & cloud KMS

At rest & in the cloud

Authenticated probes for Postgres, MySQL, MSSQL, Oracle, Mongo and Redis, plus AWS KMS, Azure Key Vault and GCP KMS.

The output

CipherScout runs the full scanner sequence and emits a CycloneDX 1.7-aligned CBOM: a structured inventory of the cryptography you run, with each finding mapped to a NIST control.

Stage 03 · Analyse

From inventory to a prioritised plan

Findings do not just sit in a list. EQCore scores them for quantum risk, maps them to regulatory controls and filters the remediation plan by your compliance regime.

01

Scored and mapped

Each finding is scored for quantum risk by severity and mapped to a NIST control, so you can prioritise what to fix first and in what order.

02

KEM vs signature

Each asset is classified as needing a key-encapsulation or a signature swap, and the CBOM becomes a prioritised remediation plan.

03

Filtered by your regime

Recommendations are intersected with the approved-algorithm list for your framework, from NIST CSF, FedRAMP and CMMC to ISO 27001, Essential Eight (ASD) and NACSA.

Engineered end to end

EQCore is one platform: discovery, migration and monitoring, built end to end by ExeQuantum. From cryptographic posture to post-quantum remediation, it is our own technology, engineered for sovereign environments.

Stage 04 · Operationalise

Put the result to work in your SOC

The plan is only useful if it reaches the people who act on it. CipherWatch turns findings into alerts and routes them to the tools your team already uses.

01

Alerts on every scan

CipherWatch converts findings into severity-scored alerts on every scan and on your schedule (critical, high, medium or low), each carrying its NIST control reference.

02

Routed to your tools

Delivers to Slack, ServiceNow and your SIEM (Splunk, QRadar or any HTTPS webhook). Channels are marketplace add-ons, configured per tenant.

03

Track change over time

Compare scans over time to surface new or changed cryptographic exposure, with acknowledge, resolve and filtering on the dashboard.

What you get

Three things you can act on

By the end of the journey you hold a clear inventory, a prioritised plan and a way to keep watch as your estate and the standards both evolve.

Inventory

A Cryptographic Bill of Materials (CBOM)

A CycloneDX 1.7-aligned Cryptographic Bill of Materials of the cryptography you run, across network, certificates, apps and data.

Direction

A prioritised plan

A framework-filtered remediation plan that ranks exposure by quantum risk and classifies each asset as a KEM or signature swap.

Assurance

Ongoing assurance

Alerts on every scan and on your schedule, routed to Slack, ServiceNow and your SIEM, with scan-over-scan comparison to catch change.

In one view

How it all fits together

01 Connect Deploy on-premises or SaaS 02 Discover Scan to CBOM 03 Analyse Score + map to NIST 04 Operationalise Monitor + migrate EQCore sovereign control plane DISCOVER CipherScout Discovery + CBOM network, certificates, apps, data MIGRATE CipherForge Migration execution KEM + signature swaps MONITOR CipherWatch Monitoring + alerts severity-scored, on your schedule Shared scanner + scoring engine one inventory · one severity model · NIST control mapping ALGORITHM OPERATIONS CipherForge PQC service ML-KEM · ML-DSA · SLH-DSA SOVEREIGN BY DESIGN On-premises · air-gapped · SaaS: engineered end to end by ExeQuantum, your data stays in your boundary.

See the journey on your own estate

Start with a discovery scan and watch a CBOM, a prioritised plan and live alerts come together.