Engraved plate of the gatehouse with its portcullis lowered. KXCO Portcullis: Security for the estate, the release and the agent.

The gate · Commercial line

KXCO Portcullisby Knightsbridge

Security for the estate, the release and the agent.

Status Live in parts

Run the free scan

What it is

Portcullis brings KXCO's security work into one product. It finds quantum-vulnerable cryptography across an estate. It is also designed to record the fix with a re-scan showing that the finding is no longer detected, and to hold back releases that do not meet policy. It also assesses AI agents before they are trusted with work.

ForChief information security officers (CISOs), security leaders and platform engineering teams

Start with the free scan

kxco-pq-scan checks JavaScript dependencies locally, without an account.

npx kxco-pq-scan

Modules

ModuleWhat it does
Portcullis SurveyFinds quantum-vulnerable cryptography across the estate and identifies the exposure.
Portcullis FortifyProvides the remediation and a re-scan that records what changed.
Portcullis HoldHosts signed releases. By default, a release with a critical finding is blocked.
Portcullis MusterScores an AI agent's declared governance. It assesses declared posture, not runtime behaviour.

Status

Availability

StatusLive in parts
Available todayLive in parts. The quantum readiness scan, scoring of an agent's declared posture and the free kxco-pq-scan are live.

Where it stops

A release signature establishes provenance. It does not prove the software is secure. The free scan covers JavaScript dependencies only.

In the House

Portcullis attestations are anchored on Armature. The free kxco-pq-scan, which checks JavaScript dependencies locally without an account, is the place to start.