The data you transmit today can be decrypted tomorrow.
Traffic protected by classical key exchange can be recorded now and decrypted once a quantum computer matures. That recording is happening today. SecretSpan connects to your internet-facing services, captures the cryptographic handshakes, and grades your exposure.
No signup, no domain entry. Look at exactly what you would receive before deciding.
What we inventory
Key exchange — the urgent one
Whether each host negotiates a classical group (x25519, secp256r1) or hybrid post-quantum X25519MLKEM768. This drives the headline grade, because it is the only axis where today’s traffic is retroactively decryptable.
Protocols, suites, certificates
Supported TLS versions including deprecated ones, weak and broken cipher suites, and the full certificate chain — signature algorithm, key type and size, and expiry.
Graded against where the standards are going
Findings are assessed against NIST FIPS 203/204/205 and the CNSA 2.0 direction. Our full grading rubric is published — every grade lists the exact rules that produced it.
Common questions
What is harvest now, decrypt later?
An attacker records encrypted traffic today and stores it. When a cryptographically relevant quantum computer exists, they decrypt the recording retroactively. Any session protected by classical key exchange — RSA, ECDH, X25519 — is exposed today, because the recording is happening now.
Do you need access to our systems?
No. Scanning is entirely external and agentless. We connect to your internet-facing services exactly as any client would, capture the cryptographic handshake, and inventory what we observe. Nothing is installed and no credentials are required.
Is this a certification?
No. SecretSpan issues its own attestation of what was observed, when, and in what scope. It is not a third-party certification and does not imply accreditation.