private beta · waitlist open

Rated beforethey ask.

Banks, agencies and defense primes now ask their suppliers for a post-quantum plan, and deals stall when there isn't one. Shorward scans your encryption, reports your readiness from Q0 to Q4, and re-checks it every month. It is self-serve: add your domains, and your reports and rating stay current on their own.

step 1 of 2 · beta waitlist
Who is asking about your post-quantum plan?
Private beta. Your first scan is free when your invite arrives. Public endpoints only, no access to your systems.
Behind this page: a two-dimensional lattice. ML-KEM (FIPS 203) protects keys with hard problems in lattices of hundreds of dimensions.
  • CNSA 2.0new national-security purchases must support PQCin — days
  • FIPS 140-2moved to the historical list21 Sep 2026
  • EO 14412quantum readiness becomes a federal buying factor22 Jun 2026
  • 2029Google and Cloudflare target full PQC migration
  • NIST IR 8547RSA and ECC deprecated2030
  • NIST IR 8547RSA and ECC disallowed2035
  • FIPS 203 · 204 · 205ML-KEM · ML-DSA · SLH-DSA
7%of organizations have post-quantum crypto deployed across most certificatesDigiCert survey · n=1,001 · 2026
68%say managing their cryptographic assets is very or extremely difficultIndustry survey · 2026
54%of companies have lost a deal over a security questionnaireWhistic
48×larger signatures with ML-DSA than ECDSA, which breaks older PKI and HSMsFIPS 204 parameter sizes
the shorward rating

Five states of readiness. One answer for every buyer.

Instead of a new questionnaire for every customer, you share one rating backed by evidence from your real inventory. Each level is a state you reach and must hold: a rating lapses to Q0 after 90 days unless it is re-scanned, so buyers know it is current.

readiness levels · climb by evidencestate: Q3
Q3

Protected in transit

Your external traffic uses hybrid post-quantum key exchange, verified by our scan.

    Shorward Rated
    Q3
    Trust-page badge · exampleVerified 14 Sep 2026 · valid to 13 Dec 2026
    for banks, agencies and primes

    See every supplier's quantum state in one place. Free.

    Request ratings from your vendors, see who is exposed, and retire your homegrown PQC questionnaire. Each rated supplier also feeds a shared registry of which libraries, HSMs and cloud services support post-quantum algorithms. Australia's signals agency began telling organizations to ask vendors these questions in July 2026.

    buyer portal Q3 Q1 Q0 · lapsed Q2 Q4 Q2
    the risk

    Your traffic is being recorded today, to be decrypted later.

    It's called "harvest now, decrypt later". Security teams use Mosca's inequality to tell if they are already late: if your data's shelf life plus your migration time is longer than the time until a quantum computer can break it, you are exposed now. Try your own numbers.

    The Global Risk Institute's expert panel puts the chance of such a machine within ten years at 28 to 49%. DARPA calls a utility-scale machine by 2033 likely.

    Exposed for 4 years
    7 + 4 > 7

    On these numbers, data you send today would still need protecting after it could be decrypted.

    plans

    Self-serve. Monthly. Reports only.

    Add your domains and Shorward scans, rates and reports on its own. We report what we measure. We don't advise or recommend changes: what to do with a finding is up to your team. Cancel any time.

    start here

    Exposure Report

    $0
    • One domain, scanned once
    • Public endpoints only, no access needed
    • One-page report of what we found
    • Estimated level from public evidence
    Join the waitlist
    most teams
    monthly

    Monitor

    $49 /month
    • Up to 5 domains
    • Re-scanned and reported every month
    • Email alert when anything changes
    • Shareable rating page and badge for buyers
    • Every past report kept
    Join the waitlist
    monthly

    Pro

    $149 /month
    • Up to 25 domains, scanned weekly
    • Upload a CBOM or config exports to be rated up to Q4
    • Quarterly report formatted for buyer security reviews
    • Supplier view for up to 10 of your own vendors
    Join the waitlist

    Shorward is in private beta. Join the waitlist and we will invite you when there is room. Beta teams get the free Exposure Report first, then Monitor and Pro at these introductory prices. Prices in USD, billed monthly.

    the method

    Add. Scan. Report. Monitor.

    Every level is defined in the public Shorward Rating Method, so your buyers can check exactly what each one takes.

    |data⟩|crypto⟩ H ×12
    1. day 1

      Add

      Enter the domains, APIs and login pages you want watched. On Pro, upload a CBOM or configuration exports too.

    2. first scan

      Scan

      We check protocol versions, key-exchange groups and certificate algorithms on every endpoint, from the outside.

    3. with every scan

      Report

      You get a one-page report and a level, with the evidence behind each finding. Facts only, no advice.

    4. monthly or weekly

      Monitor

      We re-scan on your plan's schedule and report every change: a new certificate, a new endpoint, a level that moved.

    your monthly report

    Every change, reported. Nothing sold to you.

    Each report shows what changed since the last scan and where your rating stands. It is written so you can forward it to a customer's security team as it is.

    summaryYour level. Your current level, the date it was measured and when it lapses.
    changesWhat moved. New, removed or changed endpoints, certificates and algorithms since the last scan.
    findingsWhat we found. Each quantum-vulnerable algorithm, where it runs and the evidence.
    deadlinesWhere it stands. How your findings line up with CNSA 2.0 and NIST IR 8547 dates.
    shareFor buyers. A link and badge showing your level and scan date.
    quantum readiness score · example account
    82 /100
    +44 in 10 months · Q1 → Q3
    1,284assets tracked
    27reports shared
    0expired certificates
    sample findings

    Every algorithm we find, where it runs, and when we saw it.

    every report includes
    • Your level. From Q0 to Q4, with the evidence behind it.
    • Findings. Each quantum-vulnerable algorithm and where it runs.
    • Change log. Everything that moved since the last scan.
    • Deadline map. Your findings against CNSA 2.0 and NIST dates.
    • Share link. A page your buyers can open to check your level.
    questions

    Before you start

    Quantum computers can't break encryption yet. Why monitor now?

    Because your customers and regulators have set dates that arrive before the computers do. CNSA 2.0 applies to new national-security purchases from 1 January 2027, and anything encrypted today can be recorded and decrypted later.

    Do you need access to our systems?

    No. Scans only look at what is already public: your domains, APIs and certificates. To be rated Q1 and above, Pro customers can upload a CBOM or configuration exports themselves. We never log in to your systems.

    Will you tell us what to fix?

    No. Shorward only measures and reports. Each report states what we found and how it compares with published standards. What to change, and when, stays with your team.

    Our cloud provider says it already supports PQC. Isn't that enough?

    It covers their side of the connection. Your own code, signing keys, VPNs, HSMs, partner integrations and third-party libraries are separate, and our scans report each one we can see.

    Why is the rating written like |Q3⟩?

    That's ket notation, the way physicists write a quantum state. We use it because a rating is a state you reach and have to hold. It changes with every scan, and it lapses if it isn't re-scanned.

    Can we cancel?

    Yes. Plans are monthly and you can cancel any time. You keep every report.

    private beta · waitlist open

    Know your state before a customer measures it.

    Join the waitlist with your main domain. When your invite arrives, your first scan and one-page report are free.