The gate · Commercial line
KXCO Portcullisby Knightsbridge
Security for the estate, the release and the agent.
Status Live in parts
What it is
Portcullis brings KXCO's security work into one product. It finds quantum-vulnerable cryptography across an estate. It is also designed to record the fix with a re-scan showing that the finding is no longer detected, and to hold back releases that do not meet policy. It also assesses AI agents before they are trusted with work.
| For | Chief information security officers (CISOs), security leaders and platform engineering teams |
|---|
Start with the free scan
kxco-pq-scan checks JavaScript dependencies locally, without an account.
npx kxco-pq-scanModules
| Module | What it does |
|---|---|
| Portcullis Survey | Finds quantum-vulnerable cryptography across the estate and identifies the exposure. |
| Portcullis Fortify | Provides the remediation and a re-scan that records what changed. |
| Portcullis Hold | Hosts signed releases. By default, a release with a critical finding is blocked. |
| Portcullis Muster | Scores an AI agent's declared governance. It assesses declared posture, not runtime behaviour. |
Status
Availability
| Status | Live in parts |
|---|---|
| Available today | Live in parts. The quantum readiness scan, scoring of an agent's declared posture and the free kxco-pq-scan are live. |
Where it stops
A release signature establishes provenance. It does not prove the software is secure. The free scan covers JavaScript dependencies only.
In the House
Portcullis attestations are anchored on Armature. The free kxco-pq-scan, which checks JavaScript dependencies locally without an account, is the place to start.