A measurement study · Indian financial services · 2026

Quantum-safe,
in name only.

We actively measured the TLS cryptography behind 60+ Indian financial-services endpoints. Standard scanners call it 0% post-quantum. The real number is 60%, and it is a mirage: certificates stay 100% classical, and half of firms expose an origin that routes around the protection entirely.

pip install seqr · open research · built in India

Fig 1 — Hybrid PQC key exchange

Passive probe0%
Active ML-KEM probe60%

The same endpoints (n = 53), asked two ways. Passive scanning cannot see hybrid post-quantum support. Active probing can.

01 · The mirage

The 60% is a default, not a decision.

The post-quantum key exchange lives only at the content-delivery edge, switched on by CloudFront and Cloudflare. Look past the edge and the picture inverts.

0%

of certificates stay classical

RSA / ECDSA, forgeable by a quantum computer

0%

of firms expose an origin

reachable outside the protected CDN edge

0%

are end-to-end quantum-safe

across every endpoint we measured

Nobody in the data migrated on purpose. They inherited edge defaults that stop at the certificate, at the origin server, and at the cryptographic inventory that PCI DSS and SEBI now require.

↳ The origin bypass

The edge is armored. The origin is not.

The hybrid post-quantum handshake happens at the CDN edge — and that is all a scanner sees. But the origin server behind it answers on its own address, over classical RSA and ECDH, and anything that routes straight to it skips the protection entirely.

ClientTLS 1.3 handshakeasks for PQCCDN edgeCloudFront · CloudflareX25519MLKEM768 · hybridWhat scanners seeedge-terminated TLS✓ quantum-safeExposed originorigin.examplebank.in · 13.x.x.xRSA-2048 · X25519 · classical
Edge path — hybrid ML-KEM, quantum-safeOrigin bypass — classical, quantum-vulnerable

51% of the firms we measured expose a reachable origin outside the CDN — api., dev., sftp. and mail. subdomains on raw IPs. SeQr probes for them, so the inventory reflects the whole attack surface, not just the edge the auditor was shown.

Source — measurement paper §4.6, Origin exposure (n = 118, 95% CI 42–60) →

02 · How it works

From a scan to an audit-ready inventory.

01

Scan

Point SeQr at a domain, mail server, SSH host, or codebase. It actively probes TLS and certificates for quantum-vulnerable cryptography. No agents, no special access.

02

Inventory

Every finding becomes a Cryptographic Bill of Materials in CycloneDX 1.6, the machine-readable inventory PCI DSS 12.3.3 and SEBI CSCRF now ask auditors to see.

03

Map

See what to fix and in what order, mapped to PCI DSS, SEBI CSCRF, RBI Q-SAFE, and the DST roadmap, with the correct post-quantum replacement for each algorithm.

Live demo

See what's actually running

Real scan results from real domains. No sign-up required.

Sample output
seqr — scan result

$ seqr scan domain razorpay.com

──────────────────────────────────────

TLS Version: TLS_1_3 [MODERN]

Certificate: RSA-2048 [QUANTUM-VULNERABLE]

Key Exchange: X25519 [FORWARD SECRECY]

PQC (active): X25519MLKEM768 [HYBRID PQC]

Deployment: Level 3 / 4 — Hybrid Deployed

CDN: Amazon CloudFront (low migration effort)

Scanned: CDN edge — origin not directly assessed

Agility Score: 6.5 / 10Transition-ready

──────────────────────────────────────

Hybrid PQC detected at the CDN edge — but the certificate is classical and the origin server isn't directly assessed. Edge PQC is not end-to-end quantum-safe.

✓ Scan complete in 31.3s

or try your own

03 · Why now

The inventory is already the deliverable.

Two of these are live today. The rest are dated, not hypothetical. Every one asks first for a cryptographic inventory.

PCI DSS 12.3.3

Mandatory now

Since 31 March 2025, card-data environments must keep a documented cryptographic inventory, reviewed annually. SeQr satisfies the control the moment your first scan completes.

SEBI CSCRF

Live for SEBI REs

Since June 2025, regulated entities must inventory all cryptographic assets and prioritise post-quantum migration by risk. Exactly what a SeQr CBOM produces.

RBI Q-SAFE

Framework ~Nov 2026

RBI's Q-SAFE committee is reviewing financial-sector cryptography through CBOM and crypto-agility. Banks should hold a standing inventory before guidance lands.

DST roadmap

CII inventory by 2027

India's national PQC roadmap targets a cryptographic-asset inventory for critical infrastructure, which includes banking and finance, by 2027. Recommendatory; sectoral regulators enforce.

DPDP Act 2023

Enforceable May 2027

Section 8 safeguards and penalties up to Rs 250 Cr become enforceable 13 May 2027. Quantum-vulnerable transport over personal data is a liability you can measure ahead of the deadline.

The research

Not a claim. A measurement.

Every number on this page comes from an independent study of Indian financial-services TLS endpoints, with open data and methodology. Read the paper, check the datasets, reproduce the scan.

60+
endpoints actively measured
Open
datasets and methodology
n = 53
primary corpus, with 95% CIs
Read the paper and datasets

04 · Pricing

Start free. Scale to on-premise.

Free CLI

0pip install seqr
  • Passive TLS, SSH and mail scan
  • Key exchange + forward-secrecy checks
  • Runs anywhere, no sign-up
Get the CLI

Professional

Popular
Contactannual license
  • Active ML-KEM probe (the real number)
  • CycloneDX 1.6 CBOM inventory
  • PCI DSS 12.3.3 + SEBI CSCRF mapping
  • Origin discovery, scan history, PDF reports
Request access

On-premise

Customair-gapped
  • Zero data egress, runs on your infrastructure
  • Offline license, no telemetry
  • For banks, PSUs, and critical infrastructure
  • Dedicated support + SLA
Talk to us

See what your scanners cannot.

Get your cryptographic inventory, actively measured and mapped to PCI DSS 12.3.3 and SEBI CSCRF. We reply within one business day.