About

The harvest-now-decrypt-later risk quantification company.

Cipherwake builds tools that measure how much of your data becomes plaintext when quantum computers arrive. We invented Decryption Blast Radius — the first continuous metric for harvest-now risk — and we ship it for free at cipherwake.io.

What we do

Adversaries are recording encrypted internet traffic today, with the explicit intent of decrypting it once cryptographically-relevant quantum computers exist. NIST projects this threshold between 2030 and 2040. Records harvested today and decrypted in that window remain sensitive if your data has a long lifetime — medical records, financial transactions, identity documents, intellectual property, government records.

Every other TLS scanner answers a binary question: "is post-quantum cryptography enabled?" We answer the question that actually matters: “how much past + future data unlocks if one private key is compromised?” The answer is a continuous score combining session-state analysis, key rotation, certificate lifetime, subject scale, and adversary attention.

What we ship

cipherwake.io

Free public scanner — type any domain, get a Decryption Blast Radius score + grade + plain-English impact.

npx pqcheck

Same scanner from your terminal. Zero install — runs via npx.

Public leaderboards

Rankings across 11 sectors — banks, healthcare, SaaS, government, telecom, and more.

Methodology

Open and citable scoring methodology. Read the paper →

Who we are

Cipherwake is a stealth-mode venture in 2026. The founding team combines clinical-medicine and cryptographic-systems backgrounds, with healthcare as the initial vertical focus. The underlying hybrid handshake protocol is patent-protected via a US provisional application; non-provisional conversion is in progress. Public team identification will follow product launch.

What's free, what's paid (eventually)

Free, forever: the public scanner at cipherwake.io, the npx pqcheck CLI, the public leaderboards, the methodology, and per-domain shareable reports. These are the public-utility brand contract — they stay free.

Paid (eventually): internal-network scanning, vertical SKUs (banking-tuned, healthcare-tuned, defense-tuned), 24/7 SLA, high-volume API access, SOC tool integrations, and SDK licensing. These are net-new value not currently available — when they ship, they ship as paid from day one.

We don't run "free during beta, paid later" rug-pulls. What's free today stays free forever.

What we explicitly don't do

Cipherwake quantifies HNDL risk — it does not produce regulatory compliance reports. We don't ship HIPAA / PCI / SOX / CMMC mappings, audit-ready PDFs, or compliance migration roadmaps. Those are different products from different vendors. We're not in the compliance-reporting category.

Press / journalist contact

For press inquiries, methodology questions, or data-licensing inquiries:

Leaderboard removal
remove@cipherwake.io

See also: Privacy Policy · Terms of Service