# KXCO Sentinel

Sentinel is a quantum-resistant cloud that scans, hosts and attests software.
It applies the NIST post-quantum standards to the software supply chain.

Canonical HTML: https://kxco.ai/sentinel
Last modified: 2026-09-14

---

Infrastructure Pillar

# KXCO Sentinel

The quantum-resistant cloud, for building security resilience. Scan, host and prove your software against the quantum threat, before it ships, not after.

Sentinel is the quantum-resistant layer of the KXCO cloud. Bastion finds the breakable, quantum-vulnerable cryptography hiding in your code, dependencies and live endpoints, paste a URL or a repo, and hands you the exact fix; PQC Host ships every deploy quantum-proof, with an ML-DSA-65 signature anyone can verify. Post-quantum by default, not a migration bolted on later.

One product, three modules. Bastion finds and fixes the breakable cryptography across twenty-three target kinds. PQC Host refuses a critical deploy and signs the release. Agent Certainty scores an agent on nine dimensions of governance before it acts. Every report is signed with ML-DSA-65 and checkable at pqc.kxco.ai/verify , no account, no call.

Request access →
Request a briefing →

Live
Post-quantum by default
ML-DSA-65 attested

Illustrative report

Quantum Trust Report

checkout-service · main

LIVE

96 /100

Quantum
Readiness

Cryptography 94

Dependencies 91

Transport 100

Attestation 100

Findings, resolved 0 critical

RSA-2048 CRIT → ML-KEM-768 ✓

ECDSA-P256 CRIT → ML-DSA-65 ✓

SHA-1 HIGH → SHA-3-256 ✓

TLS 1.2 MED → TLS 1.3 +PQ ✓

◈ ML-DSA-65 attested · independently verifiable

The Pipeline

## Every scan runs the same path, from repo to verifiable proof.

Connect a repository and Bastion carries it through seven stages: detect the breakable cryptography, score it, generate the post-quantum fix, and seal the result with a signature anyone can verify, then keep watching.

GitHub

Paste any repo, public or private

Bastion

Auto-detects the stack in seconds

Crypto Scan

Finds RSA, ECC, SHA-1, weak TLS

Risk Score

0–100 with per-finding severity

PQ Fix

Before/after code + packages

Attestation

ML-DSA-65 signed, verifiable

Monitoring

Daily rescans, drift alerts

The Problem

## Your cloud isn't quantum-resistant, and every scanner just hands you a report.

The RSA and ECC sitting in most software stacks is exactly what a cryptographically relevant quantum computer is expected to break. It rides along into production every time you deploy, and "we'll deal with it later" means shipping the exposure today and discovering it under a deadline later.

Existing hosting and scanning platforms don't fix that. They surface findings, generate a PDF, and walk away, no fix, no proof, and no way for a third party to confirm anything was actually done. None of them make the cloud itself quantum-resistant.

What's missing isn't another report. It's a cloud that catches the weakness before deploy, applies the post-quantum fix, and hands anyone a proof they can check themselves.

The Dependency Graph

## See exactly where the breakable crypto lives.

Bastion traces every dependency down to the cryptographic primitive it uses, and lights up what a quantum computer can break. Hover a node to isolate its relationships; run the scan to trace the path from repo to risk.

Illustrative dependency graph. A Node.js repository, checkout-service on branch main, with 3 critical findings, depends on four packages: jsonwebtoken 8.5.1 (auth tokens), node-forge 0.10.0 (TLS and PKI), openssl-wrapper 1.1.1w (transport), and @kxco/pqc 1.0.0 (post-quantum). Those packages use five cryptographic primitives. Three are quantum-vulnerable or weak: RSA-2048, a signature and KEM primitive whose post-quantum fix is ML-KEM-768; ECDSA-P256, a signature primitive whose post-quantum fix is ML-DSA-65; and SHA-1, a deprecated hash whose fix is SHA-3-256. AES-256-GCM remains classically secure. The @kxco/pqc package provides the two post-quantum replacements, ML-KEM-768 (NIST FIPS 203, key encapsulation) and ML-DSA-65 (NIST FIPS 204, signature), which replace RSA-2048 and ECDSA-P256 respectively.

Why It Matters

## A cloud built for the age of AI and quantum.

Quantum-resistant

Direct and immediate

This cloud exists because the RSA and ECC in the current stack is exactly what's exposed. Bastion detects RSA, ECC, SHA-1 and weak TLS across eight language ecosystems, and NIST post-quantum standards, FIPS 203/204, are native from day one, not a migration bolted onto a classical stack.

Provable

Proof with no vendor lock-in

Attestations are independently verifiable, the verification is mathematical, depending only on the ML-DSA-65 signature and the platform public key published at /.well-known/kxco-pq-pubkey . Verifiable by anyone, with no account and no connection to KXCO required.

AI

Optimize for AI

Most sites accidentally block the crawlers that feed AI answer engines. The Optimize for AI service fixes the technical foundation, robots.txt configuration, llms.txt, JSON-LD schema, and citation monitoring across the major AI models. See Optimize for AI →

Chain of Proof

## Every result carries a proof that stands on its own.

A scan or deployment isn't a report you have to take on faith, it's a signed manifest. Follow how a build becomes a proof any third party can verify, with no access to KXCO.

Illustrative chain of proof. Build and Deploy takes a commit and source and runs the Bastion pre-deploy scan, producing a Deployment Manifest that binds the commit SHA, timestamp, scan result and live URL. That manifest is signed by an ML-DSA-65 signature (NIST FIPS 204). The signature is presented to any verifier, who needs only the Published Public Key at /.well-known/kxco-pq-pubkey, which is open and requires no account. Verification yields a Verifiable Proof that is tamper-evident and requires no trust in KXCO.

The Tech

## How the quantum-resistant cloud compares, and how it works.

Two products, one job: find the weak cryptography and prove it's gone. Here's how each stacks up against the tools you already know.

KXCO Bastion vs. enterprise scanners

Feature Enterprise scanners KXCO Bastion

Setup required SPAN port + Linux LD_PRELOAD agent Zero, paste any file or URL

Time to first result Infrastructure deployment required Under 10 seconds

Detects RSA / ECC / SHA-1 / weak TLS ✓ ✓ eight language ecosystems

Dockerfile / Terraform / Kubernetes Not documented natively ✓ all three, zero setup

CBOM export ✓ (2 specific generators only) ✓ CycloneDX 1.6, ML-DSA-65 signed

Migration code per finding Impact simulation dashboard ✓ Before/after code + npm commands

Proof of assessment Proprietary control plane ✓ ML-DSA-65, independently verifiable

PQ-native standards PQ migration on classical stack ✓ NIST FIPS 203/204 from day one

Quantum-resistant hosting vs. Vercel / Netlify / Fly

Feature Vercel / Netlify / Fly KXCO Cloud

Static + Node.js hosting ✓ ✓

GitHub auto-deploy ✓ ✓

Free TLS ✓ ✓

Pre-deploy security scan Some ✓ KXCO Bastion

Quantum-vulnerability detection ✗ ✓

ML-DSA-65 deployment attestation ✗ ✓

Independently verifiable proof ✗ ✓

### Bastion

Scan → risk score → fix

01

Submit any target

Twenty-three target kinds, no setup for any of them. URL/TLS, package.json, requirements.txt, go.mod, Gemfile, Cargo.toml, pom.xml, nginx/OpenSSL config, Dockerfile, Terraform HCL, GitHub Actions YAML, Kubernetes manifests. Auto-detected.

02

Receive your ML-DSA-65 attested report

Risk score (0–100), per-finding severity, blast radius estimate, and the exact KXCO package command for every fix. Every report is ML-DSA-65 signed and exports as a CycloneDX 1.6 CBOM.

03

Apply the PQC fix

One click generates before/after code and npm commands for every finding. Confirming produces an ML-DSA-65 certificate of remediation, independently verifiable forever.

### PQC Host

Connect repo → pre-deploy scan → attestation

01

Connect your GitHub repo

Paste any public or private GitHub URL. Framework auto-detected in under 3 seconds, Next.js, React, Vue, Svelte, static, Node.js all supported.

02

Bastion scans before we build

Before a single line compiles, Bastion checks your package.json for quantum-vulnerable dependencies. Critical findings block the deploy.

03

ML-DSA-65 attestation issued

The moment your build completes, the platform signs a deployment manifest: commit SHA, build timestamp, Bastion result, and live URL. Verifiable forever.

Signing Authority

## One key. Anyone can check it. No account required.

Every signature roots to a single post-quantum key, published openly at a well-known address. See how signing authority is delegated, and why verification needs nothing but that public key.

Illustrative signing-authority tree. The KXCO Root Authority uses ML-DSA-65 and is held in offline custody. It delegates to a Platform Signing Key, which is rotated on a schedule. That platform key signs three things: the Scan Report Signature covering every Bastion report, the Deployment Signature covering every PQC Host deploy, and the CBOM Signature covering the CycloneDX 1.6 export. All three are verified by the Published Public Key at /.well-known/kxco-pq-pubkey, which any third party can check using the public key alone.

Capabilities

## What the quantum-resistant cloud does.

Two products, both live on the KXCO Cloud platform.

Bastion

Find every weak cipher. Fix it in minutes.

Scan code, dependencies, config and connections for quantum-vulnerable cryptography across eight language ecosystems. Other tools hand you a PDF report, KXCO gives you the exact code, npm packages, and an ML-DSA-65 attested certificate to fix every finding.

Open Bastion →

Quantum-resistant hosting, PQC Host

Host with proof. Scan. Fix. Attest.

Deploy from GitHub with a quantum-proof pre-deploy Bastion scan and an ML-DSA-65 attestation on every release, a signed deployment manifest binding commit, timestamp and URL, so you have a build history nobody can quietly rewrite.

Open PQC Host →

Compliance

## Mapped to the standards regulators actually cite.

Sentinel's capabilities line up against the post-quantum standards and government mandates. Hover a capability or a framework to see what connects to what.

Illustrative standards map. KXCO Sentinel, the quantum-resistant cloud, implements four capabilities: Crypto Detection (finds RSA, ECC, SHA-1 and TLS weaknesses), PQ Remediation (applies ML-KEM and ML-DSA fixes), ML-DSA-65 Attestation (emits signed, verifiable proof), and CBOM Export (CycloneDX 1.6 format). These align to six standards and mandates. PQ Remediation aligns to NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). Attestation aligns to FIPS 204, to the NSA's CNSA 2.0 (2030 deadline) and to NSM-10 (US Federal, 2035 deadline). Crypto Detection aligns to CNSA 2.0 and NSM-10. CBOM Export aligns to the CycloneDX CBOM standard.

Who It's For

## Anyone who has to prove their software is quantum-resistant.

Sentinel serves teams that need to find, fix and evidence quantum-vulnerable cryptography, for auditors, regulators, or their own peace of mind.

Engineering teams
Security & compliance
Regulated platforms
CI/CD pipelines
Auditors
Agencies shipping client sites

FAQ

## Quantum-resistant cloud, in plain terms.

The questions we hear most, answered straight.

What is a quantum-resistant cloud?

A quantum-resistant cloud, also called a quantum-safe, quantum-proof or post-quantum cloud, is hosting and tooling engineered to withstand attacks from future quantum computers. KXCO Sentinel is that cloud: it scans your code and dependencies for quantum-vulnerable cryptography such as RSA and ECC, hosts your software with a quantum-proof pre-deploy scan, and proves every release with an ML-DSA-65 signature anyone can verify. It implements the NIST post-quantum standards FIPS 203 and FIPS 204. PQC Host hosts software you deploy. It does not host models, and KXCO never holds your weights.

Does KXCO run a quantum computer?

No. KXCO does not operate quantum computers or offer quantum processing. Sentinel is a quantum- resistant cloud, it protects conventional software from the quantum threat using NIST-standardised post-quantum cryptography (ML-KEM / FIPS 203 and ML-DSA / FIPS 204). The goal is defence against quantum attacks, not quantum computation.

What makes cloud hosting quantum-proof?

On KXCO PQC Host, every deployment is scanned by Bastion before it builds, quantum-vulnerable dependencies can block the deploy, and the moment the build completes the platform signs a deployment manifest (commit SHA, timestamp, scan result and live URL) with an ML-DSA-65 post-quantum signature. That signed, independently verifiable proof is what makes the hosting quantum-proof rather than merely quantum-aware.

Which cryptography is vulnerable to quantum computers?

RSA, elliptic-curve cryptography (ECC/ECDSA), Diffie-Hellman key exchange, SHA-1 and weak TLS configurations are all breakable by a cryptographically relevant quantum computer. KXCO Bastion detects these across eight language ecosystems plus Dockerfiles, Terraform, Kubernetes manifests and CI/CD configuration, and returns the exact post-quantum fix for each finding.

How do you prove software is quantum-resistant?

KXCO signs each scan report and deployment manifest with an ML-DSA-65 (NIST FIPS 204) signature. Anyone can verify that signature against the platform public key published at /.well-known/kxco-pq-pubkey , with no account and no connection to KXCO required. The proof is mathematical, so it stands on its own and cannot be quietly rewritten.

When do organisations need to migrate to post-quantum cryptography?

NIST finalised the post-quantum standards FIPS 203, 204 and 205 in August 2024. The NSA's CNSA 2.0 timeline makes post-quantum signing mandatory for national security systems by 2030, and US federal systems target the removal of quantum-vulnerable algorithms by 2035 (NSM-10). Because encrypted data can be harvested now and decrypted later, sensitive data is already at risk today.

Who You Are Dealing With

## A scan that can't be placed in an organisation is only a PDF.

The group, the filed entity, the counsel and the mathematics are on this page so a counterpart doesn't have to ask.

The group

Knightsbridge Group

Operating presence in Bangkok, Doha, Paris and London. KXCO is the software company of the group, and Sentinel is a KXCO product.

The filed entity

Knightsbridge Financial Ltd

England & Wales, Company No. 15684975 , incorporated 27 April 2024. LEI 213800TMP5DQFDKOZ549 . ICO data-controller reference C1961692 .

Counsel and access

Knightsbridge Law

Group counsel, inside the group rather than a hired panel. Access is granted on approval: admin@kxco.ai . KXCO holds no financial licence and does not custody assets. Licensed institutions that deploy the software hold those relationships.

Connected Rails

## Sentinel is not an orphaned scanner.

The same identity, authority and signature layer carries the deals, the money and the agents.

Armature L1

Public record and settlement.

Permissioned settlement with ML-DSA-65 verification on-chain. A deployment manifest can be anchored so the attestation outlives the vendor relationship.

PQC Host

The same engine as a pre-deploy gate.

A critical finding can block the build, and every release carries an ML-DSA-65 deployment manifest.

Meridian and Treasury

Same identity, authority and signature layer.

Where Members run their deals, and the economic operating system beside it, on the layer Sentinel uses for agents. Knightsbridge Financial runs its own book on Meridian as a Member, not as the house.

Secure Messaging

One verification model for code and correspondence.

Outbound mail signed today with ML-DSA-65, the same standard as a Sentinel report.

Associations

## Not a client wall. The rooms and records that verify without us.

Working groups first. Developer programmes are memberships, and are named as such.

Where Knightsbridge Financial Ltd sits, and what to check

Association Status Check

PKI Consortium Member: Knightsbridge Financial Ltd. Working groups PQC, CBOM, CM, PKIMM, TCWG pkic.org/members →

Cloud Security Alliance Quantum-Safe Security Working Group, member CSA working group →

DIF / Linux Foundation Contributor member M-018609, to 26 August 2027 identity.foundation →

CoSAI / OASIS Open Open Project participant, from 26 August 2026 coalitionforsecureai.org →

IETF LAMPS WG Participant. Post-quantum X.509 certificate work IETF datatracker →

NIST FIPS 203 / 204 / 205 Implemented in production: ML-KEM-768, ML-DSA-65, SLH-DSA. ACVTS credentials active. Implemented, not endorsed NIST FIPS 204 →

IBM Quantum Network Member. Programme membership, not a joint venture IBM Quantum Network →

NVIDIA Developer Program Member developer.nvidia.com →

Visa Developer Program Member developer.visa.com →

xAI Developer Program Member x.ai →

Aligned to NSA CNSA 2.0 and the US federal 2035 path. Further developer-programme memberships are listed on the company page .

Proof Anyone Can Run

## Every institutional sentence here has a number or a URL you can open.

No account, and no call to us.

Check a report

Paste it, and check the signature yourself.

Any Sentinel attestation is checked against the platform key. No account, and no call to us.

Check the key

The platform public key is published openly.

Verification depends only on the ML-DSA-65 signature and this key.

Check the entity

The filed company, on the public registers.

Companies House 15684975 → · GLEIF 213800TMP5DQFDKOZ549 → · ICO C1961692 →

Check the inventory

A signed CycloneDX 1.6 CBOM with every scan.

The cryptographic bill of materials ships alongside the report, signed with the same key.

## Don't just find it. Fix it, and prove it.

Sentinel scans your code, containers, AI agents and MCP servers for quantum-vulnerable cryptography and agent-trust risks, returning a signed report you can hand to an auditor. Or talk to us about quantum-resistant hosting and Bastion in your CI/CD pipeline. New: read why BlackRock's quantum warning makes post-quantum an infrastructure requirement .

Request access → Bring us your question →

---

This Markdown mirrors https://kxco.ai/sentinel. The HTML page is canonical.
Site index for AI clients: https://kxco.ai/llms.txt

Copyright (c) 2026 Knightsbridge Group and KXCO. All rights reserved. Read it, retrieve it, answer questions from it, and quote it with attribution and a link to the source URL: that is what it is published for, and no permission is needed. Not permitted without written permission: copying, mirroring or republishing it, using it to build a competing product, or reverse engineering any KXCO product from it. Those are terms of use at https://kxco.ai/terms and rights under copyright and database law. Full notice: https://kxco.ai/llms.txt
