FAQs
Straight answers to the technical and practical questions CISOs actually ask.
Browse by category, or search for exactly what you need.
Search
How is QVision different from a certificate scanner?
Certificate scanners find TLS certificates. QVision discovers your full cryptographic footprint — algorithms, keys, protocols, and configurations — across network, endpoint, source code, and runtime, then maps it to the business services it protects.
What layers does QVision scan — network, endpoint, source code, runtime?
Yes — all four. QVision’s sensors cover network traffic (active and passive), certificate and trust infrastructure (CLMs, CAs, KMS, HSMs), filesystems and configuration files, and source code. Everything reconciles into one five-layer model, from cryptographic primitive up to the business service it supports.
What is a CBOM, and what format does it ship in?
A Cryptographic Bill of Materials (CBOM) is a complete, structured inventory of every cryptographic asset in your environment — algorithms, key sizes, certificates, protocols, and configurations. QVision generates it in CycloneDX 1.6 format, the open industry standard, exportable as JSON, CSV, or PDF.
What deployment models are supported?
QVision deploys on-premises, in your cloud account, or hybrid — sensor binaries distribute via the patch management tools you already run, or as Kubernetes workloads through Helm. Either way, QVision Server stays inside your infrastructure, air-gapped by design.
What does a PQStation pilot or PoC actually involve?
A QVision Scoped Pilot is a fixed-scope, eight-week engagement covering one business unit or environment. QVision deploys sensors, discovers your cryptographic estate, and delivers a real CBOM, a risk-scored findings report, and a prioritized migration roadmap — a working pilot on your own infrastructure, not a sales demo.
How long does a full PQC migration take?
On average, enterprises take three to five years to complete a cryptographic migration. PQStation’s structured discovery-to-roadmap approach is designed to cut that down to months, not years, by replacing manual audits with continuous, automated visibility.
What's the difference between QVision (product) and QAlly (advisory)?
QVision is the platform — it discovers, scores, and helps you govern your cryptographic estate. QAlly is the advisory service for teams that want hands-on help running that process, from strategy through migration.
Does any data ever leave our environment?
No. QVision is air-gapped by design. The server, dashboard, and every finding it produces run and stay entirely inside your perimeter — there’s no outbound telemetry, no call-home, and no SaaS backend to route around.
Does QVision ever access our private keys?
No. QVision never reads, copies, transmits, or stores private key material. It captures key metadata only — algorithm, key size, usage, and rotation status — never the key itself.
Is QVision independently audited or certified?
Not yet — independent penetration testing and certifications including ISO 27001 and SOC 2 Type II are on our roadmap within the next 12 months. QVision’s air-gapped architecture means your findings and inventory never leave your environment regardless of certification status, and we provide full technical cooperation for customers running their own independent assessment.
What is post-quantum cryptography migration?
Post-quantum cryptography migration is the process of replacing encryption algorithms vulnerable to quantum computers — like RSA and ECC — with quantum-resistant alternatives standardized by NIST, before those algorithms can be broken.
What is "harvest now, decrypt later"?
Harvest-now-decrypt-later describes an attack already underway: adversaries collect encrypted data today — with no way to read it yet — betting a future quantum computer will let them decrypt it later. Any data that needs to stay confidential for more than five years is already exposed under this model, not just someday.
What is a Cryptographic Bill of Materials (CBOM)?
A Cryptographic Bill of Materials (CBOM) is the cryptographic equivalent of a software bill of materials — a complete inventory of every algorithm, key, certificate, and protocol in use. It’s the foundation of any PQC migration: you can’t migrate away from vulnerable cryptography you don’t know you have.