Discover Cryptographic Risks. From Your Terminal.
qtz-discovery-cli scans source code, network endpoints, and cloud infrastructure for quantum-vulnerable cryptography — and outputs a CycloneDX CBOM in seconds.
Download for your platform
Install via terminal
or download the binary below
Also available:
Scan your crypto attack surface. One tool.
Cover your entire cryptographic attack surface from a single CLI command.
Source Code Scan
SAST + SCA across 20+ languages. Detects hardcoded keys, weak algorithms, and vulnerable crypto libraries.
Network Scan
TLS/SSH endpoint analysis. Grades ciphers, detects deprecated protocols, checks quantum-safe key exchange.
Cloud Scan
Inventories AWS KMS, GCP KMS, Azure Key Vault, and HashiCorp Vault for key age, rotation, and algorithm.
CBOM Output
CycloneDX 1.7-compliant Cryptographic Bill of Materials. Also exports SARIF, JSON, CSV, and dashboard.
The CLI is your starting point.
The Quantizant portal adds AI risk scoring, a hybrid classical + PQC transition sidecar, governance reporting, and team collaboration — all without changing your application code.