One platform to grade every asset for TLS strength, map its quantum-migration phase, and watch the whole estate move - scan by scan.
DRISHTI-PQC scans live TLS endpoints - not source code - so everything it reports is the cryptography actually negotiated in production. A quick scan grades one host in seconds; organise hosts into banks and the platform rolls the same evidence up into estate-wide posture, a quantum-migration map, and a single ranked backlog. Every number traces back to a real, observed handshake.
Each value - protocol, key exchange, cipher, certificate - comes from a real connection. What can't be checked safely is marked “not assessed,” never guessed.
Every probe is wrapped so one failed field becomes “Unknown” instead of breaking a scan. A partial answer always beats no answer.
“Here is the RSA genuinely running on your netbanking portal right now” - production truth, not a code import found in a repo.
DRISHTI-PQC scores each host the way a Qualys- or SSL Labs-style report does, weighing protocol support, key exchange and cipher strength into a single letter your leadership already understands. No interpretation needed: a grade, four sub-scores, and the reasons behind it.
A full A+ through F scale — strongest to weakest — with four sub-scores behind every letter.
Look past the grade and the full handshake is laid out - the SSLv3–TLS 1.3 protocol matrix, the per-version cipher list with forward-secrecy and strength flags, secure renegotiation, session resumption, OCSP stapling, HSTS, the negotiated key-exchange group, and the certificate's serial, fingerprint, key type and full SAN list. Each value is observed from a real handshake, never assumed.
SSLv3 / TLS 1.0 / 1.1 / 1.2 / 1.3 support, each confirmed live - with RC4, SSLv3 and TLS_FALLBACK_SCSV checks.
ObservedThe full list per TLS version, with forward secrecy, strength and a per-cipher quantum flag.
ObservedThe exact key-exchange group negotiated, down to x25519 and the P-curves.
ObservedIssuer, serial, SHA-256 fingerprint, key type and size, validity window and every subject alternative name.
ObservedA deterministic findings engine turns what was observed into a clear list: severity, the CVE where one genuinely applies, and the remediation step. What can't be checked without an active exploit probe is marked “not assessed” - honestly, never guessed.
DRISHTI-PQC detects post-quantum key exchange - ML-KEM and hybrid groups - so you can see, asset by asset, where the bank already stands against “harvest-now, decrypt-later.” It is the same lens behind PNB's readiness benchmarking.
A grade says how strong a host is today; a phase says where it sits in the quantum migration and what single step moves it forward. DRISHTI-PQC classifies each asset into one of five phases from real handshake fields - and rolls them into a bank-wide waterfall with a readiness percentage. Two hosts that both read “not PQC” can be a config flip apart or a new-appliance apart; the phase tells them apart.
Every scan into a bank is captured automatically, so posture builds its own history. Change-tracking shows a score-over-time trend, a “what changed since last scan” delta feed, and a per-asset movement trail - every grade promotion or demotion and every PQC-readiness flip, with the host named and dated. When a host crosses into hybrid key exchange it's recorded as “became PQC-ready”; if it slips back, that's recorded too. It's the dated, screenshot-ready evidence of progress for leadership.
A machine-readable inventory of every cryptographic asset in use - algorithms, protocols, certificates and keys - flagging which are quantum-vulnerable, when they break, and what to replace them with. Because DRISHTI-PQC reads live endpoints, this CBOM records the cryptography genuinely negotiated across the bank's real estate: the more credible artifact for a regulator than anything a source-code scanner can produce.
Every protocol, key exchange, cipher and certificate signature actually seen in production.
Quantum-flaggedWhich assets are quantum-vulnerable and the migration urgency against the NIST timeline.
Quantum-flaggedEach tool answers a focused question about a domain or a host. The Attack Surface console unifies every finding across every bank into one posture, one phase map and one prioritised backlog.
Grade any host on demand - full handshake, findings and quantum readiness in seconds.
LiveEnumerate a domain's public subdomains and hosts - alive, stale or dead.
LiveIs each host up, stale or dead - reachability at a glance.
LiveExpiry watchlist and chain health, RAG-flagged across the estate.
LiveFull record lookup plus a graded DNS hygiene score.
LiveSPF, DKIM and DMARC parsed and graded - with a group posture board.
LiveProbe non-443 TLS, STARTTLS and SSH crypto across a bank's hosts.
Cryptographic Bill of Materials, built from live production endpoints.
LiveFold in CSV exports from the bank's external VM scanner to enrich the estate.
One DRISHTI score for the whole bank, with trend and a velocity-based path to quantum-safe.
Exposed docs, GraphQL introspection, CORS and auth checks on API hosts.
Organise hosts by bank and rescan whenever you need. Each asset keeps a single entry that always reflects its latest scan - so the inventory stays the source of truth, never a pile of duplicates - while an append-only history quietly preserves every past scan for the trend and movement trails.
DRISHTI-PQC was designed and engineered within the Cyber & Information Security Division, as part of the bank's cryptographic resilience programme.