Start free. Upgrade when you need depth.
Run public TLS and certificate scans for free, no signup. Join the private preview when you need organization history, or Enterprise when you need internal inventory across Kubernetes and cloud KMS, hybrid signing, and policy enforcement.
Free
For a first look at your public-facing post-quantum exposure.
- Public TLS & certificate scans (fair-use limits)
- 0–100 risk score with severity findings
- Shareable report URL
- Recommended migration steps
- postq CLI + public ingestion API
Team
Most popularFor security teams tracking PQC readiness over time.
- Everything in Free
- Organization-scoped scan history
- Asset and key inventory views
- API keys + official SDKs
- Multiple targets and organization members
- Private-preview engineering support
Enterprise
For internal inventory, signing, and policy across your stack.
- Everything in Team
- Internal inventory: Kubernetes agent, AWS and Azure scanners
- Hybrid signing (Vault) + PostQ Ledger audit trail
- Customer-owned AWS, Azure, or Google Cloud KMS custody
- Policy engine & enforcement
- Deployment architecture and security review
- Contracted onboarding, support, retention, and SLA options
Team pricing is an introductory private-preview offer and is provisioned manually; no automatic checkout is implied. Enterprise scope and terms are confirmed in an order form. The free public scan requires no card.
What you grow into
Free and Team focus on discovery — the scanner, scoring, and reports. Enterprise unlocks the rest of the platform as you move from finding exposure to fixing and proving it.
Quantum Risk Scanner
Continuous discovery of classical cryptography across endpoints, certificates, KMS, and code.
Hybrid Signing API
Production-grade hybrid signatures (ML-DSA + classical) with safe rollout and verification.
Policy Engine
Define and enforce cryptographic policies across your stack from a central control plane.
SDKs & CLI
Official SDKs for TypeScript, Python, and .NET, plus the postq CLI for CI/CD pipelines.
Observability
Organization dashboards, signature audit rows, Ledger proofs, and downloadable verifiable bundles.
Support & onboarding
Direct engineering access during private-preview rollout; production support terms are defined in the signed order form.
Common questions
How is PostQ priced?
Pricing is based on your deployment model (cloud, self-hosted, or hybrid), the number of assets under management, and signing volume. Book a demo to discuss your environment and receive a tailored quote.
Is there a free tier?
Yes. The Free plan provides public TLS and certificate scans under fair-use limits with a shareable report and 0–100 risk score — no signup or card. Private-preview plans add organization history and API access; internal inventory and signing are scoped with Enterprise customers.
How is the score calculated?
Each finding gets a severity (Critical/High/Medium/Low) and the 0–100 score is a top-heavy weighted aggregate where the worst finding dominates. The full method and known limitations are published on our methodology page.
Do you offer self-hosted deployments?
The Kubernetes, AWS, and Azure scanners run inside your environment and send metadata outward over HTTPS. A fully self-hosted control plane is not a one-click GA offering; regulated deployment requirements are evaluated as a scoped enterprise engagement.
What about compliance and procurement?
We provide technical architecture and security-review materials. Any MSA, DPA, SLA, residency, retention, or sector-specific agreement must be reviewed and signed for the applicable customer; the website does not itself create those commitments.
See PostQ in your environment
Book a tailored walkthrough of scanning, hybrid signing, policy, and deployment options for your stack.