Banks, agencies and defense primes now ask their suppliers for a post-quantum plan, and deals stall when there isn't one. Shorward scans your encryption, reports your readiness from Q0 to Q4, and re-checks it every month. It is self-serve: add your domains, and your reports and rating stay current on their own.
Instead of a new questionnaire for every customer, you share one rating backed by evidence from your real inventory. Each level is a state you reach and must hold: a rating lapses to Q0 after 90 days unless it is re-scanned, so buyers know it is current.
Request ratings from your vendors, see who is exposed, and retire your homegrown PQC questionnaire. Each rated supplier also feeds a shared registry of which libraries, HSMs and cloud services support post-quantum algorithms. Australia's signals agency began telling organizations to ask vendors these questions in July 2026.
It's called "harvest now, decrypt later". Security teams use Mosca's inequality to tell if they are already late: if your data's shelf life plus your migration time is longer than the time until a quantum computer can break it, you are exposed now. Try your own numbers.
The Global Risk Institute's expert panel puts the chance of such a machine within ten years at 28 to 49%. DARPA calls a utility-scale machine by 2033 likely.
On these numbers, data you send today would still need protecting after it could be decrypted.
Add your domains and Shorward scans, rates and reports on its own. We report what we measure. We don't advise or recommend changes: what to do with a finding is up to your team. Cancel any time.
Shorward is in private beta. Join the waitlist and we will invite you when there is room. Beta teams get the free Exposure Report first, then Monitor and Pro at these introductory prices. Prices in USD, billed monthly.
Every level is defined in the public Shorward Rating Method, so your buyers can check exactly what each one takes.
Enter the domains, APIs and login pages you want watched. On Pro, upload a CBOM or configuration exports too.
We check protocol versions, key-exchange groups and certificate algorithms on every endpoint, from the outside.
You get a one-page report and a level, with the evidence behind each finding. Facts only, no advice.
We re-scan on your plan's schedule and report every change: a new certificate, a new endpoint, a level that moved.
Each report shows what changed since the last scan and where your rating stands. It is written so you can forward it to a customer's security team as it is.
Because your customers and regulators have set dates that arrive before the computers do. CNSA 2.0 applies to new national-security purchases from 1 January 2027, and anything encrypted today can be recorded and decrypted later.
No. Scans only look at what is already public: your domains, APIs and certificates. To be rated Q1 and above, Pro customers can upload a CBOM or configuration exports themselves. We never log in to your systems.
No. Shorward only measures and reports. Each report states what we found and how it compares with published standards. What to change, and when, stays with your team.
It covers their side of the connection. Your own code, signing keys, VPNs, HSMs, partner integrations and third-party libraries are separate, and our scans report each one we can see.
That's ket notation, the way physicists write a quantum state. We use it because a rating is a state you reach and have to hold. It changes with every scan, and it lapses if it isn't re-scanned.
Yes. Plans are monthly and you can cancel any time. You keep every report.
Join the waitlist with your main domain. When your invite arrives, your first scan and one-page report are free.