V-1.0 · Living Whitepaper · 2026

Check your code is
quantum-ready.
Without showing your code to anyone.

zkAssess scans your codebase for quantum-vulnerable and classically weak cryptography, then issues a signed, cryptographically committed attestation. The analysis runs entirely inside your trust boundary — only a redacted score ever leaves it.

Product Demo ● 2 min
The Problem

Most organizations don't know what cryptography they're running — or where.

Hidden risk, revealed

zkAssess surfaces the quantum-vulnerable and classically weak cryptography that's already running in production — the risk you can't fix because no one's found it yet.

Scattered pieces, one picture

Findings across every repository and service are pulled into a single, reproducible inventory — not a pile of disconnected scan results nobody has time to reconcile.

Guesswork, automated away

Deterministic, versioned pattern matching replaces manual code review and best-guess audits with something any verifier can reproduce.

Continuous, not one-time

Run zkAssess in CI on every commit, and your cryptographic inventory stays current instead of going stale the moment something changes.

How It Works

"Zero-knowledge" isn't a slogan here. We mean it in the most literal sense: we never take your code or your data.

0

We don't take your code. We don't take your data.

zkAssess doesn't upload your repository, doesn't cache your source, and doesn't retain a copy anywhere on our side — because it never runs on our side. The scanner executes entirely inside your machine, your CI runner, or your TEE. The only thing that ever reaches us is a signed, redacted attestation: a score, which pattern IDs matched, and a cryptographic proof that each finding is real.

We can't leak what we never had. That's not a policy promise — it's the architecture.

◐

We search blind. Then we plan around your company.

The pattern engine doesn't read your business logic, your comments, or your architecture to understand what your product does — it only matches lines against a fixed, versioned list of known cryptographic patterns.

Once that blind scan produces findings, that's where your company enters the picture: your scoring policy, your compliance profile, your risk tolerance decide what the findings mean and what happens next — never the other way around.

01 · The Two Phases

We look at everything. We only ever hand over a receipt.

In plain terms

Finding a problem in your code means actually reading the code — there's no way around that. So that part happens privately, on your own machine. Once something is found, we only need to prove that one specific thing is real — like showing a notarized receipt instead of your whole bank statement.

PHASE 1

Look (stays private)

A scanner checks every line of your code against a public list of known-risky and known-safe patterns. This step needs to see everything, so it never leaves your computer, your CI pipeline, or your own secure environment.

PHASE 2

Prove (what leaves)

For each thing found, we generate a small, provable receipt — "this exact (redacted) line really exists at this file and line number." That receipt is mathematically checkable without ever showing anyone the file itself.

02 · What We Look For

A checklist, not a guess.

"This codebase uses RSA" is a fact you can check. "This codebase is insecure" is a judgment call. zkAssess sticks to the checkable part: matching code against a public, versioned list — nothing guessed, nothing subjective.

CategoryExamplesWhy it matters
QUANTUM-VULNERABLE RSA, ECDSA / ECDH / EdDSA and named curves, Diffie-Hellman, DSA Breakable by Shor's algorithm on a sufficiently large quantum computer
CLASSICALLY WEAK MD5, SHA-1, DES, 3DES, RC4, RC2 Already broken or impractically weak, independent of quantum computing
CONFIGURATION ECB mode, RSA keys under 2048 bits, static IVs / salts The primitive may be sound but the usage pattern undermines it
QUANTUM-SAFE AES-256, ChaCha20-Poly1305, SHA-256/3, BLAKE2/3, ML-KEM, ML-DSA, SLH-DSA, Falcon Positive confirmation of already-good cryptographic hygiene
03 · What We Share, Exactly

A little goes out. Almost everything stays in.

This is the whole privacy design in one sentence: keep a tiny, bounded snippet per finding, replace everything else with an unreadable fingerprint, and let that fingerprint be checked mathematically — never by handing over the file.

What we receive

  • The overall quantum-readiness score
  • Which pattern IDs matched, and how many times
  • A short, bounded redacted snippet per finding
  • The file path and line number of each finding
  • A cryptographic proof that each finding is real
  • The pattern-set version, for reproducibility

What we never receive

  • The repository itself, in any form
  • The full contents of any scanned file
  • Surrounding code, business logic, or comments
  • Any file that contains zero findings
  • Secrets or proprietary logic incidentally present
  • Your identity, unless you disclose it out of band
04 · Beyond the Scanner

Automated scanning finds patterns. Some risk only a human audit can find.

zkAssess is deterministic pattern matching — it tells you what cryptography exists and where. It doesn't evaluate whether your protocol architecture is sound, whether your threat model is tight, or whether an implementation faithfully realizes its design. For that, engagements are led by a senior cryptography expert, not a scanner report.

01 / Protocol architecture

Protocol design review

Key exchange, authentication flows, session management, state machines. We evaluate the architecture before the first line of implementation code.

02 / Cryptographic design

Primitive selection & composition

Are the chosen primitives appropriate for the threat model? Do they compose correctly? AEAD, KDF, signature, KEM — every choice scrutinized.

03 / Threat modeling

Adversary capability assessment

What did the design assume the adversary can do? Are those assumptions tight? AI bug-finders cannot challenge threat models — humans must.

04 / Implementation fidelity

Cross-language code review

Does the code correctly realize the design? Go, Rust, TypeScript, Swift, Java, .NET, C, Solidity. Full-source audits, not scanner reports.

05 / Post-quantum readiness

PQ migration assessment

Is your system positioned to survive the next decade of cryptanalytic advances? KEM hybridisation, signature strategy, library and protocol fitness.

06 / Formal verification

Machine-checked proofs

Symbolic verification of protocol correctness in Verifpal, ProVerif, or Tamarin — and critical review of formal-verification claims others have made about code you depend on.

Run zkAssess to build your cryptographic inventory continuously in CI. Bring in a design-level audit when you need someone to challenge the architecture and threat model behind it — not just list what's in the code.

Talk to us about an audit →
Simple, Transparent Pricing

The price is the point.

No sales call required to get a number. Start free, scale as your repository count grows, and see exactly what changes at each tier.

Hacker
Free
No credit card needed
Best for trying it out
  • 3 repositories scanned per month
  • Baseline compliance profile only
  • Community support
Start free →
Team
$499/mo
25 repositories included
Best for a single engineering org
  • 25 repositories, re-scanned every commit
  • All 5 preset compliance profiles
  • CI/CD integration
  • Email support
Integrate now →
Enterprise
Custom
Unlimited repositories
Best for full-scale deployments
  • Unlimited repositories
  • On-prem / TEE deployment option
  • 24-hour SLA, 7 days a week
  • Custom compliance profiles
Speak to founder →
All tiers: source code never leaves your boundary — pricing scales with repositories scanned, not with what we see.
Get Started

Assess your codebase. Keep it yours.

Run the analysis inside your own boundary. Share only what a verifier needs to trust the result.

No sales call to start
3 repositories free every month
Published pricing, no hidden tiers