Cryptographic discovery & migration for OT & critical infrastructure
See what cryptography actually runs across your network — starting with what isn't protected at all.
ClaveQ passively inventories the cryptography across your IT and OT estate — the plaintext, the ageing classical encryption, and the quantum-safe — and turns it into a standards-based Cryptography Bill of Materials and a migration plan you can act on. Without sending a single packet.
No agents. No decryption. Designed for live safety networks.
How it works
One mirror port. Four passive steps.
ClaveQ connects to a mirror port and listens. It never transmits, never decrypts, and never touches the devices it's protecting.
Listen passively
Traffic is mirrored from a switch SPAN or a network TAP. Zero packets are sent onto the network.
Read IT & OT protocols
A broad range of enterprise and industrial protocols are parsed, down to the cipher in use.
Rate what's exposed
Every connection is rated — unencrypted, quantum-vulnerable, or quantum-safe — with the evidence attached.
CBOM & compliance
A standards-based Cryptography Bill of Materials and a prioritised migration plan.
What it gives you
A complete cryptographic picture of a network nobody else will touch.
Completely passive
Zero packets transmitted, no decryption, no agents. Designed to run against live OT and safety-critical networks.
The real crypto in use
Sees the actual cipher suites, key exchange and certificates across IT and OT — not an inventory guess.
Quantum-risk classification
Rates every connection, and separates harvest-now-decrypt-later exposure from authentication risk.
A real, standards-based CBOM
A machine-readable Cryptography Bill of Materials in CycloneDX 1.7 (ECMA-424) — schema-validated, not a PDF that borrows the name.
Mapped to the frameworks
Findings align to major PQC-migration and industrial-security frameworks, including NCSC, NIST and IEC 62443.
A migration plan that tracks
A prioritised roadmap, re-measured over time, so you can show progress — and prove what's been fixed.
Honest coverage
Every scan tells you how completely it observed the traffic. No black boxes, nothing to take on faith.
Fits your estate
Deploy as an appliance or a container, with an air-gapped authentication mode and SIEM export.
See the real output
See it for yourself — an excerpt of the actual file.
This is a trimmed excerpt of a genuine ClaveQ CBOM, for the "Cloud historian sync" row shown above. The full file is schema-validated against the official CycloneDX 1.7 spec.
{
"bomFormat": "CycloneDX",
"specVersion": "1.7",
"components": [
{
"type": "cryptographic-asset",
"bom-ref": "crypto/algo/x25519mlkem768",
"name": "X25519MLKEM768",
"cryptoProperties": {
"assetType": "algorithm",
"algorithmProperties": {
"primitive": "key-agree",
"algorithmFamily": "ML-KEM",
"nistQuantumSecurityLevel": 1
}
}
},
{
"type": "cryptographic-asset",
"bom-ref": "crypto/protocol/cloud-historian-sync",
"name": "TLS 1.3 · cloud historian sync",
"cryptoProperties": {
"assetType": "protocol",
"protocolProperties": {
"cipherSuites": ["TLS_AES_256_GCM_SHA384"]
}
}
}
],
"dependencies": [
{ "ref": "crypto/protocol/cloud-historian-sync",
"dependsOn": ["crypto/algo/x25519mlkem768"] }
]
}
Machine-readable, not a summary
Every connection decomposes into protocol, algorithm and certificate components — the same structure a compliance tool or auditor's script can parse directly.
Schema-validated
Checked in our own test suite against the official CycloneDX 1.7 / ECMA-424 schema before it ever reaches a customer.
Why ClaveQ
Built for the networks you can't take risks with.
Nothing is sent
The safety case comes first. If a tool has to inject traffic or decrypt to see your crypto, it doesn't belong on a CNI network.
Results you can defend
Every verdict comes with the evidence behind it — the kind of answer you can put in front of an auditor or a regulator.
Portable by default
Your CBOM is an open standard, not our format. The audit trail is yours to keep, export and build on.
Why now
The clock starts when data is captured — not when quantum arrives.
Harvest now, decrypt later: traffic intercepted today can be stored and unlocked once a quantum computer can break classical encryption. For OT and critical-infrastructure data with a secrecy life measured in decades, that exposure is already real — and you can't migrate what you can't see.
A staged national timeline
The NCSC's migration guidance sets discovery by 2028, high-priority migration by 2031 and full migration by 2035. It's guidance rather than law — but it's the yardstick UK boards and regulators are adopting.
The target algorithms exist
NIST has finalised the post-quantum standards — ML-KEM, ML-DSA and SLH-DSA. What to migrate to is settled; the task now is finding where the vulnerable algorithms still run.
The baseline is rising
The EU Cyber Resilience Act is in force, with obligations landing from 2026. In the UK, the network-and-information-security rules covering essential-services operators are being strengthened. A cryptographic inventory is where that work starts.
Private beta
We're opening early access to a small number of CNI operators.
If you run operational technology in water, energy, healthcare or manufacturing and want an early look, we'd like to hear from you.
Required to reply to your enquiry. See our privacy notice.
Website privacy notice
What happens to your information if you fill in a form on this site.
This notice explains what happens to your information if you use a form on this website — for example, "Request early access." It does not cover data the ClaveQ Scan appliance itself observes when scanning a customer's network — that's covered separately by our Data Processing Agreement (available on request).
Who we are
ClaveQ is a trading name of QUANTUM CLAVE LTD, a company registered in England & Wales, no. 17340121. Registered office: 49 Jamaica Street, Liverpool, England, L1 0AH. We are the "data controller" for the information described here — meaning we decide what it's used for and are responsible for looking after it.
What we collect
When you submit the "Request early access" form, we collect:
- your work email address
- your organisation's name, if you give it
- what you tell us you're looking to scan
- whether you've ticked the box to receive product updates
- your approximate location and browser/device, which Forminit derives automatically from your IP address at the time of submission
If you email us directly instead, we hold whatever you choose to put in that email.
Why we use it, and on what basis
| What | Why | Legal basis |
|---|---|---|
| Email, organisation, enquiry detail | To reply to your enquiry | Legitimate interest — you contacted us first |
| Marketing tick-box (if ticked) | To send occasional product updates | Your consent — withdraw it any time |
We never use it for anything else, and we don't sell it.
Who we share it with
- Cloudflare, Inc. — our website hosting provider, which handles ordinary technical logs (like your IP address) for any visit to this site.
- Forminit (operated by UXPLUS LTD, a UK company) — the form-processing service that receives and stores your submission on our behalf, and automatically derives approximate location and browser/device from your IP address.
We don't share your information with anyone else, other than organisations we're legally obliged to share it with (for example, a court order or a statutory request from a regulator) — something true of any company, not a description of anything that's happened.
Where it's processed
Forminit is UK-incorporated and stores submissions on AWS's Ireland region, so that part of your information stays within the UK/EEA — no international-transfer safeguard is needed for it. Cloudflare is US-headquartered, so hosting the site with them does mean your technical logs (like your IP address) are processed outside the UK. That transfer is covered by the Addendum to the EU Standard Contractual Clauses — Cloudflare's own data processing agreement's standard safeguard for exactly this situation.
How long we keep it
Up to 12 months after our last contact with you, then deleted — unless you ask us to delete it sooner, or we're in an active, ongoing conversation with you, in which case we keep it for as long as that continues.
Your rights
You have the following rights over your information, though which ones apply depends on why we're using it (see the table above):
- Access — ask us for a copy of what we hold about you.
- Rectification — ask us to correct or delete anything inaccurate or incomplete.
- Erasure — ask us to delete your information.
- Restriction — ask us to limit how we use it.
- Object — object to our use of your information where we rely on legitimate interest (this applies to replying to your enquiry, not to marketing — for marketing, withdrawing consent achieves the same thing).
- Portability — ask us to transfer the information you gave us to another organisation, or to you (this applies where we rely on consent — i.e. the marketing tick-box — not to legitimate interest).
- Withdraw consent — withdraw your marketing consent at any time, with no effect on the legitimate-interest basis we use to reply to your enquiry.
To use any of these, email hello@claveq.com and we'll respond within a month. If you're unhappy with how we've handled your data, you can also complain to the UK Information Commissioner's Office — we'd appreciate the chance to put it right first, but the choice is yours: ico.org.uk/make-a-complaint ↗, 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Cookies and tracking
This website does not use cookies, analytics, or any third-party tracking scripts.
↑ Back to top