PQC Cyber Services
Quantum-safe security,delivered as a service.
Continuous vulnerability scanning, expert remediation, and bespoke post-quantum tooling for organisations that can't — and shouldn't have to — build a quantum security team in-house. Every fix ships with a verifiable ML-DSA-65 attestation.
ML-DSA-65 signed · CycloneDX 1.6 CBOM · Classical + quantum coverage · 7 language ecosystems
The post-quantum transition is an engineering programme, not a one-off scan. Most organisations face it without the in-house expertise to run it — and hiring specialist quantum and AI-security engineers is slow and expensive. KXCO PQC Cyber Services close that gap: managed scanning, expert remediation, and bespoke tooling, all cryptographically verifiable.
Which solution fits?
Three organisations. Three starting points.
Most teams arrive at the same problem from different directions. Find the one that sounds like you — each maps to a service line you can start this quarter.
“We need it watched, continuously.”
A regional bank runs 30+ microservices with no internal quantum or AI-security staff. It needs every service scanned on a quarterly cadence, with findings triaged and tracked — not a one-off report that ages out.
→ Managed PQC Vulnerability Scanning at ScaleScheduled scans, full triage and ticketing, configurable response SLAs. You own the roadmap; we run the scanning function.
“We know we’re exposed. We need it fixed.”
A fintech’s audit flagged RSA-2048 and ECDSA across its TLS termination and signing paths. It has the findings — what it lacks is the engineering capacity to author, test, and safely merge the quantum-safe migration.
→ Vulnerability Remediation as a ServiceWe author the patches, run regression tests, support the merge, and issue a verifiable Bastion attestation for each fix.
“We need our own tool, built right.”
A defence supplier must scan an air-gapped estate it can’t send to a SaaS scanner. It needs a tailored, quantum-resistant scanner it can run in-house, built to its stack and threat model.
→ Custom PQC Builds & Bespoke ScannersA scoped engagement to design and deliver the tool. You keep it and run it after we hand it over.
Not sure which? Scope an engagement and we'll map your estate to the right starting point.
What we deliver
The full lifecycle of quantum-safe defence.
Service line 01
Managed PQC Vulnerability Scanning at Scale
Scanning as a managed function — scheduled, triaged, and held to SLA.
What's included
Why it matters
Built on: KXCO Bastion · CBOM export · ML-DSA-65 attestations
Service line 02
Vulnerability Remediation as a Service
From finding to merged, attested fix — handled end to end.
What's included
Why it matters
Built on: Bastion remediation engine · ML-DSA-65 certificates · verifiable attestations
Service line 03
Custom PQC Builds & Bespoke Scanners
A quantum-resistant tool, scoped to your stack — and yours to keep.
What's included
Why it matters
Built on: KXCO PQC SDK · Bastion probe framework
Advanced services
For quantum risk at board level.
Senior-led, high-stakes engagements. Pricing is scoped per engagement.
Continuous Threat Exposure Management
A continuously maintained view of quantum and classical attack surface across your estate, with prioritised remediation — not point-in-time scans.
Red-teaming as a Service
Adversarial assessment focused on harvest-now-decrypt-later exposure and crypto-agility weaknesses, alongside conventional offensive testing.
Agentic SOC / SIEM augmentation
AI-assisted detection and triage layered onto your existing SOC/SIEM — augmenting analysts, not replacing your stack.
Pre-acquisition & M&A code review
High-stakes diligence: cryptographic and security review of a target codebase before you sign, delivered with signed attestations for the deal record.
One platform, end to end
Connected to everything else you run on KXCO.
A finding scanned in Bastion, fixed under Remediation-as-a-Service, signed with ML-DSA-65, and verifiable on verify.kxco.ai — one continuous, cryptographically provable chain.
KXCO Bastion →
The scanning and remediation engine behind Managed Scanning and Remediation-as-a-Service.
ML-DSA-65 attestations →
Every scan cycle and every fix is signed with the platform key and independently verifiable.
verify.kxco.ai ↗
Public, backend-free verification of any attestation we issue — for your auditors and regulators.
KnightsVault ↗
Quantum-safe custody software for institutions — secured by the same PQC primitives our services harden your estate with. KXCO provides the software; the licensed institution operates it.
Armature L1 ↗
The private PoA hybrid-PQC ledger. Attestations and CBOMs can be anchored for tamper-evident audit history.
PQC Host →
Deploy hardened, attested workloads on a post-quantum-native platform once they are remediated.
For engineering teams
Build it yourself, or build it with us.
Our services are built on the same public primitives you can use directly. Start with the SDKs, drop the scanner into CI, and reach for an engagement when you need scale, speed, or a bespoke build.
# Run a Bastion scan in CI. Fail the build on new
# quantum-vulnerable findings.
- uses: KnightsbridgeAIQ/bastion-action@v1
with:
kxco-token: ${{ secrets.KXCO_TOKEN }}Note: use kxco-pq-attest.verify for attestation envelopes — kxco-verify.verifyManifest expects a different schema.
Build Your Own — starting templates
Custom scanner skeleton
A minimal Bastion-style probe scaffold built on kxco-post-quantum, ready to extend to your stack.
Attestation pipeline
Sign build and remediation artefacts with kxco-pq-attest, publish the public key, and verify in CI.
CBOM-on-merge
Generate a CycloneDX 1.6 CBOM on every merge to main and store it as a signed build artefact.
Scope an engagement.We'll map it to the right start.
Tell us about your estate — services, languages, cadence, and constraints. We'll map it to the right starting point and a quote.
Classical + quantum coverage · Every fix ML-DSA-65 attested · Built on KXCO Bastion