ClaveQ
Private beta · by invitation

Cryptographic discovery & migration for OT & critical infrastructure

See what cryptography actually runs across your network — starting with what isn't protected at all.

ClaveQ passively inventories the cryptography across your IT and OT estate — the plaintext, the ageing classical encryption, and the quantum-safe — and turns it into a standards-based Cryptography Bill of Materials and a migration plan you can act on. Without sending a single packet.

No agents. No decryption. Designed for live safety networks.

How it works

One mirror port. Four passive steps.

ClaveQ connects to a mirror port and listens. It never transmits, never decrypts, and never touches the devices it's protecting.

01 — Capture

Listen passively

Traffic is mirrored from a switch SPAN or a network TAP. Zero packets are sent onto the network.

02 — Decode

Read IT & OT protocols

A broad range of enterprise and industrial protocols are parsed, down to the cipher in use.

03 — Classify

Rate what's exposed

Every connection is rated — unencrypted, quantum-vulnerable, or quantum-safe — with the evidence attached.

04 — Report

CBOM & compliance

A standards-based Cryptography Bill of Materials and a prioritised migration plan.

What it gives you

A complete cryptographic picture of a network nobody else will touch.

Completely passive

Zero packets transmitted, no decryption, no agents. Designed to run against live OT and safety-critical networks.

The real crypto in use

Sees the actual cipher suites, key exchange and certificates across IT and OT — not an inventory guess.

Quantum-risk classification

Rates every connection, and separates harvest-now-decrypt-later exposure from authentication risk.

A real, standards-based CBOM

A machine-readable Cryptography Bill of Materials in CycloneDX 1.7 (ECMA-424) — schema-validated, not a PDF that borrows the name.

Mapped to the frameworks

Findings align to major PQC-migration and industrial-security frameworks, including NCSC, NIST and IEC 62443.

A migration plan that tracks

A prioritised roadmap, re-measured over time, so you can show progress — and prove what's been fixed.

Honest coverage

Every scan tells you how completely it observed the traffic. No black boxes, nothing to take on faith.

Fits your estate

Deploy as an appliance or a container, with an air-gapped authentication mode and SIEM export.

See the real output

See it for yourself — an excerpt of the actual file.

This is a trimmed excerpt of a genuine ClaveQ CBOM, for the "Cloud historian sync" row shown above. The full file is schema-validated against the official CycloneDX 1.7 spec.

cbom-excerpt.json · illustrative
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "components": [
    {
      "type": "cryptographic-asset",
      "bom-ref": "crypto/algo/x25519mlkem768",
      "name": "X25519MLKEM768",
      "cryptoProperties": {
        "assetType": "algorithm",
        "algorithmProperties": {
          "primitive": "key-agree",
          "algorithmFamily": "ML-KEM",
          "nistQuantumSecurityLevel": 1
        }
      }
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "crypto/protocol/cloud-historian-sync",
      "name": "TLS 1.3 · cloud historian sync",
      "cryptoProperties": {
        "assetType": "protocol",
        "protocolProperties": {
          "cipherSuites": [{ "name": "TLS_AES_256_GCM_SHA384" }]
        }
      }
    }
  ],
  "dependencies": [
    { "ref": "crypto/protocol/cloud-historian-sync",
      "dependsOn": ["crypto/algo/x25519mlkem768"] }
  ]
}

Machine-readable, not a summary

Every connection decomposes into protocol, algorithm and certificate components — the same structure a compliance tool or auditor's script can parse directly.

Schema-validated

Checked in our own test suite against the official CycloneDX 1.7 / ECMA-424 schema before it ever reaches a customer.

Download sample CBOM (.json) real file · downloads locally · nothing sent anywhere

Why ClaveQ

Built for the networks you can't take risks with.

Passive by design

Nothing is sent

The safety case comes first. If a tool has to inject traffic or decrypt to see your crypto, it doesn't belong on a CNI network.

Explainable

Results you can defend

Every verdict comes with the evidence behind it — the kind of answer you can put in front of an auditor or a regulator.

Evidence you own

Portable by default

Your CBOM is an open standard, not our format. The audit trail is yours to keep, export and build on.

Why now

The clock starts when data is captured — not when quantum arrives.

Harvest now, decrypt later: traffic intercepted today can be stored and unlocked once a quantum computer can break classical encryption. For OT and critical-infrastructure data with a secrecy life measured in decades, that exposure is already real — and you can't migrate what you can't see.

NCSC · guidance

A staged national timeline

The NCSC's migration guidance sets discovery by 2028, high-priority migration by 2031 and full migration by 2035. It's guidance rather than law — but it's the yardstick UK boards and regulators are adopting.

NCSC migration roadmap ↗

NIST · standards

The target algorithms exist

NIST has finalised the post-quantum standards — ML-KEM, ML-DSA and SLH-DSA. What to migrate to is settled; the task now is finding where the vulnerable algorithms still run.

NIST PQC standards ↗

Regulation · law

The baseline is rising

The EU Cyber Resilience Act is in force, with obligations landing from 2026. In the UK, the network-and-information-security rules covering essential-services operators are being strengthened. A cryptographic inventory is where that work starts.

EU CRA ↗·UK CSR Bill ↗

Private beta

We're opening early access to a small number of CNI operators.

If you run operational technology in water, energy, healthcare or manufacturing and want an early look, we'd like to hear from you.

Thanks — we'll be in touch within a couple of days.