Scan, host and prove your software against the quantum threat — before it ships, not after.
Sentinel is the quantum-resistant layer of the KXCO cloud. Bastion finds the breakable, quantum-vulnerable cryptography hiding in your code, dependencies and live endpoints — paste a URL or a repo — and hands you the exact fix; PQC Host ships every deploy quantum-proof, with an ML-DSA-65 signature anyone can verify. Post-quantum by default — not a migration bolted on later.
Connect a repository and Bastion carries it through seven stages: detect the breakable cryptography, score it, generate the post-quantum fix, and seal the result with a signature anyone can verify — then keep watching.
The RSA and ECC sitting in most software stacks is exactly what a cryptographically relevant quantum computer is expected to break. It rides along into production every time you deploy, and "we'll deal with it later" means shipping the exposure today and discovering it under a deadline later.
Existing hosting and scanning platforms don't fix that. They surface findings, generate a PDF, and walk away — no fix, no proof, and no way for a third party to confirm anything was actually done. None of them make the cloud itself quantum-resistant.
What's missing isn't another report. It's a cloud that catches the weakness before deploy, applies the post-quantum fix, and hands anyone a proof they can check themselves.
Bastion traces every dependency down to the cryptographic primitive it uses — and lights up what a quantum computer can break. Hover a node to isolate its relationships; run the scan to trace the path from repo to risk.
A scan or deployment isn't a report you have to take on faith — it's a signed manifest. Follow how a build becomes a proof any third party can verify, with no access to KXCO.
Two products, one job: find the weak cryptography and prove it's gone. Here's how each stacks up against the tools you already know.
| Feature | Enterprise scanners | KXCO Bastion |
|---|---|---|
| Setup required | SPAN port + Linux LD_PRELOAD agent | Zero — paste any file or URL |
| Time to first result | Infrastructure deployment required | Under 10 seconds |
| Pricing | Enterprise contract only | Free tier — self-serve |
| Detects RSA / ECC / SHA-1 / weak TLS | ✓ | ✓ 7 language ecosystems |
| Dockerfile / Terraform / Kubernetes | Not documented natively | ✓ all three, zero setup |
| GitHub Actions CI/CD | Custom integration required | ✓ JackKXCO/bastion-action@v1 |
| CBOM export | ✓ (2 specific generators only) | ✓ CycloneDX 1.6, ML-DSA-65 signed |
| Migration code per finding | Impact simulation dashboard | ✓ Before/after code + npm commands |
| Proof of assessment | Proprietary control plane | ✓ ML-DSA-65 — independently verifiable |
| PQ-native standards | PQ migration on classical stack | ✓ NIST FIPS 203/204 from day one |
| Feature | Vercel / Netlify / Fly | KXCO Cloud |
|---|---|---|
| Static + Node.js hosting | ✓ | ✓ |
| GitHub auto-deploy | ✓ | ✓ |
| Free TLS | ✓ | ✓ |
| Pre-deploy security scan | Some | ✓ KXCO Bastion |
| Quantum-vulnerability detection | ✗ | ✓ |
| ML-DSA-65 deployment attestation | ✗ | ✓ |
| Independently verifiable proof | ✗ | ✓ |
Every signature roots to a single post-quantum key, published openly at a well-known address. See how signing authority is delegated — and why verification needs nothing but that public key.
Two products, both live on the KXCO Cloud platform.
Sentinel's capabilities line up against the post-quantum standards and government mandates. Hover a capability or a framework to see what connects to what.
Sentinel serves teams that need to find, fix and evidence quantum-vulnerable cryptography — for auditors, regulators, or their own peace of mind.
The questions we hear most — answered straight.
/.well-known/kxco-pq-pubkey — with no account and no connection to KXCO required. The proof is mathematical, so it stands on its own and cannot be quietly rewritten.Sentinel scans your code, containers, AI agents and MCP servers for quantum-vulnerable cryptography and agent-trust risks — free, self-serve, no card. Or talk to us about quantum-resistant hosting and Bastion in your CI/CD pipeline. New: read why BlackRock's quantum warning makes post-quantum an infrastructure requirement.