A measurement study · Indian financial services · 2026
Quantum-safe,
in name only.
We actively measured the TLS cryptography behind 60+ Indian financial-services endpoints. Standard scanners call it 0% post-quantum. The real number is 60%, and it is a mirage: certificates stay 100% classical, and half of firms expose an origin that routes around the protection entirely.
pip install seqr · open research · built in India
Fig 1 — Hybrid PQC key exchange
The same endpoints (n = 53), asked two ways. Passive scanning cannot see hybrid post-quantum support. Active probing can.
01 · The mirage
The 60% is a default, not a decision.
The post-quantum key exchange lives only at the content-delivery edge, switched on by CloudFront and Cloudflare. Look past the edge and the picture inverts.
of certificates stay classical
RSA / ECDSA, forgeable by a quantum computer
of firms expose an origin
reachable outside the protected CDN edge
are end-to-end quantum-safe
across every endpoint we measured
Nobody in the data migrated on purpose. They inherited edge defaults that stop at the certificate, at the origin server, and at the cryptographic inventory that PCI DSS and SEBI now require.
↳ The origin bypass
The edge is armored. The origin is not.
The hybrid post-quantum handshake happens at the CDN edge — and that is all a scanner sees. But the origin server behind it answers on its own address, over classical RSA and ECDH, and anything that routes straight to it skips the protection entirely.
51% of the firms we measured expose a reachable origin outside the CDN — api., dev., sftp. and mail. subdomains on raw IPs. SeQr probes for them, so the inventory reflects the whole attack surface, not just the edge the auditor was shown.
Source — measurement paper §4.6, Origin exposure (n = 118, 95% CI 42–60) →02 · How it works
From a scan to an audit-ready inventory.
Scan
Point SeQr at a domain, mail server, SSH host, or codebase. It actively probes TLS and certificates for quantum-vulnerable cryptography. No agents, no special access.
Inventory
Every finding becomes a Cryptographic Bill of Materials in CycloneDX 1.6, the machine-readable inventory PCI DSS 12.3.3 and SEBI CSCRF now ask auditors to see.
Map
See what to fix and in what order, mapped to PCI DSS, SEBI CSCRF, RBI Q-SAFE, and the DST roadmap, with the correct post-quantum replacement for each algorithm.
Live demo
See what's actually running
Real scan results from real domains. No sign-up required.
$ seqr scan domain razorpay.com
──────────────────────────────────────
TLS Version: TLS_1_3 [MODERN]
Certificate: RSA-2048 [QUANTUM-VULNERABLE]
Key Exchange: X25519 [FORWARD SECRECY]
PQC (active): X25519MLKEM768 [HYBRID PQC]
Deployment: Level 3 / 4 — Hybrid Deployed
CDN: Amazon CloudFront (low migration effort)
Scanned: CDN edge — origin not directly assessed
Agility Score: 6.5 / 10 — Transition-ready
──────────────────────────────────────
Hybrid PQC detected at the CDN edge — but the certificate is classical and the origin server isn't directly assessed. Edge PQC is not end-to-end quantum-safe.
✓ Scan complete in 31.3s
03 · Why now
The inventory is already the deliverable.
Two of these are live today. The rest are dated, not hypothetical. Every one asks first for a cryptographic inventory.
PCI DSS 12.3.3
Mandatory nowSince 31 March 2025, card-data environments must keep a documented cryptographic inventory, reviewed annually. SeQr satisfies the control the moment your first scan completes.
SEBI CSCRF
Live for SEBI REsSince June 2025, regulated entities must inventory all cryptographic assets and prioritise post-quantum migration by risk. Exactly what a SeQr CBOM produces.
RBI Q-SAFE
Framework ~Nov 2026RBI's Q-SAFE committee is reviewing financial-sector cryptography through CBOM and crypto-agility. Banks should hold a standing inventory before guidance lands.
DST roadmap
CII inventory by 2027India's national PQC roadmap targets a cryptographic-asset inventory for critical infrastructure, which includes banking and finance, by 2027. Recommendatory; sectoral regulators enforce.
DPDP Act 2023
Enforceable May 2027Section 8 safeguards and penalties up to Rs 250 Cr become enforceable 13 May 2027. Quantum-vulnerable transport over personal data is a liability you can measure ahead of the deadline.
The research
Not a claim. A measurement.
Every number on this page comes from an independent study of Indian financial-services TLS endpoints, with open data and methodology. Read the paper, check the datasets, reproduce the scan.
04 · Pricing
Start free. Scale to on-premise.
Free CLI
- Passive TLS, SSH and mail scan
- Key exchange + forward-secrecy checks
- Runs anywhere, no sign-up
Professional
Popular- Active ML-KEM probe (the real number)
- CycloneDX 1.6 CBOM inventory
- PCI DSS 12.3.3 + SEBI CSCRF mapping
- Origin discovery, scan history, PDF reports
On-premise
- Zero data egress, runs on your infrastructure
- Offline license, no telemetry
- For banks, PSUs, and critical infrastructure
- Dedicated support + SLA
See what your scanners cannot.
Get your cryptographic inventory, actively measured and mapped to PCI DSS 12.3.3 and SEBI CSCRF. We reply within one business day.