Pricing

Start free. Upgrade when you need depth.

Run public TLS and certificate scans for free, no signup. Join the private preview when you need organization history, or Enterprise when you need internal inventory across Kubernetes and cloud KMS, hybrid signing, and policy enforcement.

Free

$0

For a first look at your public-facing post-quantum exposure.

  • Public TLS & certificate scans (fair-use limits)
  • 0–100 risk score with severity findings
  • Shareable report URL
  • Recommended migration steps
  • postq CLI + public ingestion API
Run a free scan

Team

Most popular
$99/month

For security teams tracking PQC readiness over time.

  • Everything in Free
  • Organization-scoped scan history
  • Asset and key inventory views
  • API keys + official SDKs
  • Multiple targets and organization members
  • Private-preview engineering support
Request access

Enterprise

Custom

For internal inventory, signing, and policy across your stack.

  • Everything in Team
  • Internal inventory: Kubernetes agent, AWS and Azure scanners
  • Hybrid signing (Vault) + PostQ Ledger audit trail
  • Customer-owned AWS, Azure, or Google Cloud KMS custody
  • Policy engine & enforcement
  • Deployment architecture and security review
  • Contracted onboarding, support, retention, and SLA options
Book a demo

Team pricing is an introductory private-preview offer and is provisioned manually; no automatic checkout is implied. Enterprise scope and terms are confirmed in an order form. The free public scan requires no card.

The platform

What you grow into

Free and Team focus on discovery — the scanner, scoring, and reports. Enterprise unlocks the rest of the platform as you move from finding exposure to fixing and proving it.

Quantum Risk Scanner

Continuous discovery of classical cryptography across endpoints, certificates, KMS, and code.

Hybrid Signing API

Production-grade hybrid signatures (ML-DSA + classical) with safe rollout and verification.

Policy Engine

Define and enforce cryptographic policies across your stack from a central control plane.

SDKs & CLI

Official SDKs for TypeScript, Python, and .NET, plus the postq CLI for CI/CD pipelines.

Observability

Organization dashboards, signature audit rows, Ledger proofs, and downloadable verifiable bundles.

Support & onboarding

Direct engineering access during private-preview rollout; production support terms are defined in the signed order form.

FAQ

Common questions

How is PostQ priced?

Pricing is based on your deployment model (cloud, self-hosted, or hybrid), the number of assets under management, and signing volume. Book a demo to discuss your environment and receive a tailored quote.

Is there a free tier?

Yes. The Free plan provides public TLS and certificate scans under fair-use limits with a shareable report and 0–100 risk score — no signup or card. Private-preview plans add organization history and API access; internal inventory and signing are scoped with Enterprise customers.

How is the score calculated?

Each finding gets a severity (Critical/High/Medium/Low) and the 0–100 score is a top-heavy weighted aggregate where the worst finding dominates. The full method and known limitations are published on our methodology page.

Do you offer self-hosted deployments?

The Kubernetes, AWS, and Azure scanners run inside your environment and send metadata outward over HTTPS. A fully self-hosted control plane is not a one-click GA offering; regulated deployment requirements are evaluated as a scoped enterprise engagement.

What about compliance and procurement?

We provide technical architecture and security-review materials. Any MSA, DPA, SLA, residency, retention, or sector-specific agreement must be reviewed and signed for the applicable customer; the website does not itself create those commitments.

See PostQ in your environment

Book a tailored walkthrough of scanning, hybrid signing, policy, and deployment options for your stack.