PQC Cyber Services

Quantum-safe security,delivered as a service.

Continuous vulnerability scanning, expert remediation, and bespoke post-quantum tooling for organisations that can't — and shouldn't have to — build a quantum security team in-house. Every fix ships with a verifiable ML-DSA-65 attestation.

ML-DSA-65 signed · CycloneDX 1.6 CBOM · Classical + quantum coverage · 7 language ecosystems

The post-quantum transition is an engineering programme, not a one-off scan. Most organisations face it without the in-house expertise to run it — and hiring specialist quantum and AI-security engineers is slow and expensive. KXCO PQC Cyber Services close that gap: managed scanning, expert remediation, and bespoke tooling, all cryptographically verifiable.

Which solution fits?

Three organisations. Three starting points.

Most teams arrive at the same problem from different directions. Find the one that sounds like you — each maps to a service line you can start this quarter.

We need it watched, continuously.

A regional bank runs 30+ microservices with no internal quantum or AI-security staff. It needs every service scanned on a quarterly cadence, with findings triaged and tracked — not a one-off report that ages out.

Managed PQC Vulnerability Scanning at Scale

Scheduled scans, full triage and ticketing, configurable response SLAs. You own the roadmap; we run the scanning function.

We know we’re exposed. We need it fixed.

A fintech’s audit flagged RSA-2048 and ECDSA across its TLS termination and signing paths. It has the findings — what it lacks is the engineering capacity to author, test, and safely merge the quantum-safe migration.

Vulnerability Remediation as a Service

We author the patches, run regression tests, support the merge, and issue a verifiable Bastion attestation for each fix.

We need our own tool, built right.

A defence supplier must scan an air-gapped estate it can’t send to a SaaS scanner. It needs a tailored, quantum-resistant scanner it can run in-house, built to its stack and threat model.

Custom PQC Builds & Bespoke Scanners

A scoped engagement to design and deliver the tool. You keep it and run it after we hand it over.

Not sure which? Scope an engagement and we'll map your estate to the right starting point.

What we deliver

The full lifecycle of quantum-safe defence.

Service line 01

Managed PQC Vulnerability Scanning at Scale

Scanning as a managed function — scheduled, triaged, and held to SLA.

What's included

Scans on a cadence you define — quarterly, monthly, per-release, or continuous
Coverage across codebases, microservices, and infrastructure — classical and quantum-vulnerable cryptography
Full triage: every finding validated, severity-ranked, and de-duplicated before it reaches your team
Findings routed into your ticketing workflow with configurable response SLAs
CycloneDX 1.6 CBOM per cycle, ML-DSA-65 signed
Quantum-exposure posture tracked over time — trend, not snapshot

Why it matters

A scanning function without the headcount — no specialist quantum/AI-security hires
Built on KXCO Bastion: 7 language ecosystems, IaC, Docker, CI, and Kubernetes scanned statically
Findings are signed and independently verifiable — auditors confirm them without trusting us

Built on: KXCO Bastion · CBOM export · ML-DSA-65 attestations

Service line 02

Vulnerability Remediation as a Service

From finding to merged, attested fix — handled end to end.

What's included

Patch authoring for flagged classical and quantum-vulnerable code paths
Validation and regression testing against your existing suite
Merge support — we work in your workflow, through review, to a clean merge
Quantum-safe migration guidance: which primitives, which sequence, which fallbacks
A verifiable Bastion attestation per remediation, anchored to repo, commit, and time

Why it matters

Closes the gap between knowing you are exposed and being fixed — the step most teams stall on
Every fix carries cryptographic proof of what changed and who verified it
Migration sequenced to preserve interoperability with systems still on classical crypto

Built on: Bastion remediation engine · ML-DSA-65 certificates · verifiable attestations

Service line 03

Custom PQC Builds & Bespoke Scanners

A quantum-resistant tool, scoped to your stack — and yours to keep.

What's included

Discovery and scoping against your architecture, threat model, and compliance constraints
Design and delivery of a tailored scanner or PQC tool — air-gapped, on-prem, or embedded in your CI
Handover: documentation, source, and run-in-house enablement
Optional retainer for updates as the PQC standards landscape evolves

Why it matters

For estates that cannot go to a SaaS scanner — air-gapped, classified, or contractually isolated
You own the artefact after the engagement; no lock-in to a hosted service
Built on proven primitives (kxco-post-quantum, kxco-pq-attest) — not bespoke, unreviewed crypto

Built on: KXCO PQC SDK · Bastion probe framework

Advanced services

For quantum risk at board level.

Senior-led, high-stakes engagements. Pricing is scoped per engagement.

Continuous Threat Exposure Management

A continuously maintained view of quantum and classical attack surface across your estate, with prioritised remediation — not point-in-time scans.

Red-teaming as a Service

Adversarial assessment focused on harvest-now-decrypt-later exposure and crypto-agility weaknesses, alongside conventional offensive testing.

Agentic SOC / SIEM augmentation

AI-assisted detection and triage layered onto your existing SOC/SIEM — augmenting analysts, not replacing your stack.

Pre-acquisition & M&A code review

High-stakes diligence: cryptographic and security review of a target codebase before you sign, delivered with signed attestations for the deal record.

One platform, end to end

Connected to everything else you run on KXCO.

A finding scanned in Bastion, fixed under Remediation-as-a-Service, signed with ML-DSA-65, and verifiable on verify.kxco.ai — one continuous, cryptographically provable chain.

For engineering teams

Build it yourself, or build it with us.

Our services are built on the same public primitives you can use directly. Start with the SDKs, drop the scanner into CI, and reach for an engagement when you need scale, speed, or a bespoke build.

kxco-post-quantumCore PQC primitives — ML-DSA-65 signing/verification, ML-KEM-768 encryption.npm · v1.0.0
kxco-pq-attestCreate and verify deployment / remediation attestation envelopes.npm
bastion-actionGitHub Action — runs a Bastion scan in CI and returns pass/fail.github.com/KnightsbridgeAIQ/bastion-action
.github/workflows/pqc-scan.yml
# Run a Bastion scan in CI. Fail the build on new
# quantum-vulnerable findings.
- uses: KnightsbridgeAIQ/bastion-action@v1
  with:
    kxco-token: ${{ secrets.KXCO_TOKEN }}

Note: use kxco-pq-attest.verify for attestation envelopes — kxco-verify.verifyManifest expects a different schema.

Build Your Own — starting templates

Custom scanner skeleton

A minimal Bastion-style probe scaffold built on kxco-post-quantum, ready to extend to your stack.

Attestation pipeline

Sign build and remediation artefacts with kxco-pq-attest, publish the public key, and verify in CI.

CBOM-on-merge

Generate a CycloneDX 1.6 CBOM on every merge to main and store it as a signed build artefact.

Scope an engagement.We'll map it to the right start.

Tell us about your estate — services, languages, cadence, and constraints. We'll map it to the right starting point and a quote.

Classical + quantum coverage · Every fix ML-DSA-65 attested · Built on KXCO Bastion

Trust & Compliance · Knightsbridge Financial Ltd · LEI 213800TMP5DQFDKOZ549