ClaveQ
Private beta

Cryptographic discovery & migration for OT & critical infrastructure

See what cryptography actually runs across your network — starting with what isn't protected at all.

ClaveQ passively inventories the cryptography across your IT and OT estate — the plaintext, the ageing classical encryption, and the quantum-safe — and turns it into a standards-based Cryptography Bill of Materials and a migration plan you can act on. Without sending a single packet.

No agents. No decryption. Designed for live safety networks.

How it works

One mirror port. Four passive steps.

ClaveQ connects to a mirror port and listens. It never transmits, never decrypts, and never touches the devices it's protecting.

01 — Capture

Listen passively

Traffic is mirrored from a switch SPAN or a network TAP. Zero packets are sent onto the network.

02 — Decode

Read IT & OT protocols

A broad range of enterprise and industrial protocols are parsed, down to the cipher in use.

03 — Classify

Rate what's exposed

Every connection is rated — unencrypted, quantum-vulnerable, or quantum-safe — with the evidence attached.

04 — Report

CBOM & compliance

A standards-based Cryptography Bill of Materials and a prioritised migration plan.

What it gives you

A complete cryptographic picture of a network nobody else will touch.

Completely passive

Zero packets transmitted, no decryption, no agents. Designed to run against live OT and safety-critical networks.

The real crypto in use

Sees the actual cipher suites, key exchange and certificates across IT and OT — not an inventory guess.

Quantum-risk classification

Rates every connection, and separates harvest-now-decrypt-later exposure from authentication risk.

A real, standards-based CBOM

A machine-readable Cryptography Bill of Materials in CycloneDX 1.7 (ECMA-424) — schema-validated, not a PDF that borrows the name.

Mapped to the frameworks

Findings align to major PQC-migration and industrial-security frameworks, including NCSC, NIST and IEC 62443.

A migration plan that tracks

A prioritised roadmap, re-measured over time, so you can show progress — and prove what's been fixed.

Honest coverage

Every scan tells you how completely it observed the traffic. No black boxes, nothing to take on faith.

Fits your estate

Deploy as an appliance or a container, with an air-gapped authentication mode and SIEM export.

See the real output

See it for yourself — an excerpt of the actual file.

This is a trimmed excerpt of a genuine ClaveQ CBOM, for the "Cloud historian sync" row shown above. The full file is schema-validated against the official CycloneDX 1.7 spec.

cbom-excerpt.json · illustrative
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "components": [
    {
      "type": "cryptographic-asset",
      "bom-ref": "crypto/algo/x25519mlkem768",
      "name": "X25519MLKEM768",
      "cryptoProperties": {
        "assetType": "algorithm",
        "algorithmProperties": {
          "primitive": "key-agree",
          "algorithmFamily": "ML-KEM",
          "nistQuantumSecurityLevel": 1
        }
      }
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "crypto/protocol/cloud-historian-sync",
      "name": "TLS 1.3 · cloud historian sync",
      "cryptoProperties": {
        "assetType": "protocol",
        "protocolProperties": {
          "cipherSuites": ["TLS_AES_256_GCM_SHA384"]
        }
      }
    }
  ],
  "dependencies": [
    { "ref": "crypto/protocol/cloud-historian-sync",
      "dependsOn": ["crypto/algo/x25519mlkem768"] }
  ]
}

Machine-readable, not a summary

Every connection decomposes into protocol, algorithm and certificate components — the same structure a compliance tool or auditor's script can parse directly.

Schema-validated

Checked in our own test suite against the official CycloneDX 1.7 / ECMA-424 schema before it ever reaches a customer.

Download sample CBOM (.json) real file · downloads locally · nothing sent anywhere

Why ClaveQ

Built for the networks you can't take risks with.

Passive by design

Nothing is sent

The safety case comes first. If a tool has to inject traffic or decrypt to see your crypto, it doesn't belong on a CNI network.

Explainable

Results you can defend

Every verdict comes with the evidence behind it — the kind of answer you can put in front of an auditor or a regulator.

Evidence you own

Portable by default

Your CBOM is an open standard, not our format. The audit trail is yours to keep, export and build on.

Why now

The clock starts when data is captured — not when quantum arrives.

Harvest now, decrypt later: traffic intercepted today can be stored and unlocked once a quantum computer can break classical encryption. For OT and critical-infrastructure data with a secrecy life measured in decades, that exposure is already real — and you can't migrate what you can't see.

NCSC · guidance

A staged national timeline

The NCSC's migration guidance sets discovery by 2028, high-priority migration by 2031 and full migration by 2035. It's guidance rather than law — but it's the yardstick UK boards and regulators are adopting.

NCSC migration roadmap ↗

NIST · standards

The target algorithms exist

NIST has finalised the post-quantum standards — ML-KEM, ML-DSA and SLH-DSA. What to migrate to is settled; the task now is finding where the vulnerable algorithms still run.

NIST PQC standards ↗

Regulation · law

The baseline is rising

The EU Cyber Resilience Act is in force, with obligations landing from 2026. In the UK, the network-and-information-security rules covering essential-services operators are being strengthened. A cryptographic inventory is where that work starts.

EU CRA ↗·UK CSR Bill ↗

Private beta

We're opening early access to a small number of CNI operators.

If you run operational technology in water, energy, healthcare or manufacturing and want an early look, we'd like to hear from you.

Thanks — we'll be in touch within a couple of days.

Website privacy notice

What happens to your information if you fill in a form on this site.

This notice explains what happens to your information if you use a form on this website — for example, "Request early access." It does not cover data the ClaveQ Scan appliance itself observes when scanning a customer's network — that's covered separately by our Data Processing Agreement (available on request).

Who we are

ClaveQ is a trading name of QUANTUM CLAVE LTD, a company registered in England & Wales, no. 17340121. Registered office: 49 Jamaica Street, Liverpool, England, L1 0AH. We are the "data controller" for the information described here — meaning we decide what it's used for and are responsible for looking after it.

What we collect

When you submit the "Request early access" form, we collect:

  • your work email address
  • your organisation's name, if you give it
  • what you tell us you're looking to scan
  • whether you've ticked the box to receive product updates
  • your approximate location and browser/device, which Forminit derives automatically from your IP address at the time of submission

If you email us directly instead, we hold whatever you choose to put in that email.

Why we use it, and on what basis

WhatWhyLegal basis
Email, organisation, enquiry detailTo reply to your enquiryLegitimate interest — you contacted us first
Marketing tick-box (if ticked)To send occasional product updatesYour consent — withdraw it any time

We never use it for anything else, and we don't sell it.

Who we share it with

  • Cloudflare, Inc. — our website hosting provider, which handles ordinary technical logs (like your IP address) for any visit to this site.
  • Forminit (operated by UXPLUS LTD, a UK company) — the form-processing service that receives and stores your submission on our behalf, and automatically derives approximate location and browser/device from your IP address.

We don't share your information with anyone else, other than organisations we're legally obliged to share it with (for example, a court order or a statutory request from a regulator) — something true of any company, not a description of anything that's happened.

Where it's processed

Forminit is UK-incorporated and stores submissions on AWS's Ireland region, so that part of your information stays within the UK/EEA — no international-transfer safeguard is needed for it. Cloudflare is US-headquartered, so hosting the site with them does mean your technical logs (like your IP address) are processed outside the UK. That transfer is covered by the Addendum to the EU Standard Contractual Clauses — Cloudflare's own data processing agreement's standard safeguard for exactly this situation.

How long we keep it

Up to 12 months after our last contact with you, then deleted — unless you ask us to delete it sooner, or we're in an active, ongoing conversation with you, in which case we keep it for as long as that continues.

Your rights

You have the following rights over your information, though which ones apply depends on why we're using it (see the table above):

  • Access — ask us for a copy of what we hold about you.
  • Rectification — ask us to correct or delete anything inaccurate or incomplete.
  • Erasure — ask us to delete your information.
  • Restriction — ask us to limit how we use it.
  • Object — object to our use of your information where we rely on legitimate interest (this applies to replying to your enquiry, not to marketing — for marketing, withdrawing consent achieves the same thing).
  • Portability — ask us to transfer the information you gave us to another organisation, or to you (this applies where we rely on consent — i.e. the marketing tick-box — not to legitimate interest).
  • Withdraw consent — withdraw your marketing consent at any time, with no effect on the legitimate-interest basis we use to reply to your enquiry.

To use any of these, email hello@claveq.com and we'll respond within a month. If you're unhappy with how we've handled your data, you can also complain to the UK Information Commissioner's Office — we'd appreciate the chance to put it right first, but the choice is yours: ico.org.uk/make-a-complaint ↗, 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Cookies and tracking

This website does not use cookies, analytics, or any third-party tracking scripts.

↑ Back to top