Cryptographic discovery & migration for OT & critical infrastructure
See what cryptography actually runs across your network — starting with what isn't protected at all.
ClaveQ passively inventories the cryptography across your IT and OT estate — the plaintext, the ageing classical encryption, and the quantum-safe — and turns it into a standards-based Cryptography Bill of Materials and a migration plan you can act on. Without sending a single packet.
No agents. No decryption. Designed for live safety networks.
How it works
One mirror port. Four passive steps.
ClaveQ connects to a mirror port and listens. It never transmits, never decrypts, and never touches the devices it's protecting.
Listen passively
Traffic is mirrored from a switch SPAN or a network TAP. Zero packets are sent onto the network.
Read IT & OT protocols
A broad range of enterprise and industrial protocols are parsed, down to the cipher in use.
Rate what's exposed
Every connection is rated — unencrypted, quantum-vulnerable, or quantum-safe — with the evidence attached.
CBOM & compliance
A standards-based Cryptography Bill of Materials and a prioritised migration plan.
What it gives you
A complete cryptographic picture of a network nobody else will touch.
Completely passive
Zero packets transmitted, no decryption, no agents. Designed to run against live OT and safety-critical networks.
The real crypto in use
Sees the actual cipher suites, key exchange and certificates across IT and OT — not an inventory guess.
Quantum-risk classification
Rates every connection, and separates harvest-now-decrypt-later exposure from authentication risk.
A real, standards-based CBOM
A machine-readable Cryptography Bill of Materials in CycloneDX 1.7 (ECMA-424) — schema-validated, not a PDF that borrows the name.
Mapped to the frameworks
Findings align to major PQC-migration and industrial-security frameworks, including NCSC, NIST and IEC 62443.
A migration plan that tracks
A prioritised roadmap, re-measured over time, so you can show progress — and prove what's been fixed.
Honest coverage
Every scan tells you how completely it observed the traffic. No black boxes, nothing to take on faith.
Fits your estate
Deploy as an appliance or a container, with an air-gapped authentication mode and SIEM export.
See the real output
See it for yourself — an excerpt of the actual file.
This is a trimmed excerpt of a genuine ClaveQ CBOM, for the "Cloud historian sync" row shown above. The full file is schema-validated against the official CycloneDX 1.7 spec.
{
"bomFormat": "CycloneDX",
"specVersion": "1.7",
"components": [
{
"type": "cryptographic-asset",
"bom-ref": "crypto/algo/x25519mlkem768",
"name": "X25519MLKEM768",
"cryptoProperties": {
"assetType": "algorithm",
"algorithmProperties": {
"primitive": "key-agree",
"algorithmFamily": "ML-KEM",
"nistQuantumSecurityLevel": 1
}
}
},
{
"type": "cryptographic-asset",
"bom-ref": "crypto/protocol/cloud-historian-sync",
"name": "TLS 1.3 · cloud historian sync",
"cryptoProperties": {
"assetType": "protocol",
"protocolProperties": {
"cipherSuites": [{ "name": "TLS_AES_256_GCM_SHA384" }]
}
}
}
],
"dependencies": [
{ "ref": "crypto/protocol/cloud-historian-sync",
"dependsOn": ["crypto/algo/x25519mlkem768"] }
]
}
Machine-readable, not a summary
Every connection decomposes into protocol, algorithm and certificate components — the same structure a compliance tool or auditor's script can parse directly.
Schema-validated
Checked in our own test suite against the official CycloneDX 1.7 / ECMA-424 schema before it ever reaches a customer.
Why ClaveQ
Built for the networks you can't take risks with.
Nothing is sent
The safety case comes first. If a tool has to inject traffic or decrypt to see your crypto, it doesn't belong on a CNI network.
Results you can defend
Every verdict comes with the evidence behind it — the kind of answer you can put in front of an auditor or a regulator.
Portable by default
Your CBOM is an open standard, not our format. The audit trail is yours to keep, export and build on.
Why now
The clock starts when data is captured — not when quantum arrives.
Harvest now, decrypt later: traffic intercepted today can be stored and unlocked once a quantum computer can break classical encryption. For OT and critical-infrastructure data with a secrecy life measured in decades, that exposure is already real — and you can't migrate what you can't see.
A staged national timeline
The NCSC's migration guidance sets discovery by 2028, high-priority migration by 2031 and full migration by 2035. It's guidance rather than law — but it's the yardstick UK boards and regulators are adopting.
The target algorithms exist
NIST has finalised the post-quantum standards — ML-KEM, ML-DSA and SLH-DSA. What to migrate to is settled; the task now is finding where the vulnerable algorithms still run.
The baseline is rising
The EU Cyber Resilience Act is in force, with obligations landing from 2026. In the UK, the network-and-information-security rules covering essential-services operators are being strengthened. A cryptographic inventory is where that work starts.
Private beta
We're opening early access to a small number of CNI operators.
If you run operational technology in water, energy, healthcare or manufacturing and want an early look, we'd like to hear from you.
Required to reply to your enquiry. See our privacy notice.