QVAPT — Quantum-Ready VAPT for Web, DLT & PQC
We assess what is taking money today, and what will take it in 2030.
Enterprise VAPT and post-quantum cryptography assurance from Aurigraph DLT Corp: NIST SP 800-115 programmes, smart-contract and wallet security, and independently verifiable, hash-anchored scorecards. Every engagement closes on a deterministic score with no AI in the scoring path.
Six-module assessment scope
- M1 — Signer & key-custody topology (MVP): signer/quorum, hardware vs hot-key split, rotation age, approval-flow social-engineering resistance.
- M2 — Bridge & cross-chain trust-path: counts independent verifiers; single-verifier designs flagged critical.
- M3 — Emerging trust boundaries: EIP-7702 delegation, AI-agent signing authority, off-chain prover / ZK.
- M4 — Legacy & deprecated-code sweep: live-but-sunset contracts still holding funds.
- M5 — Crypto inventory, CBOM & quantum exposure: FIPS 203/204/205, SLH-DSA posture (the Q1–Q12 engine).
- M6 — Detection-to-containment latency: continuous posture-of-record.
Grading scale
Two scales, deliberately separate. Every cryptographic asset in the CBOM carries an asset grade: A quantum-safe · B monitor · F Shor-broken · X already broken.
The engagement then closes on one readiness grade from the weighted pass ratio across the twelve quantum cases: A ≥ 90% · B ≥ 80% · C ≥ 70% · D ≥ 60% · F below 60%. Ceilings apply on top and the worst one wins: a FAIL on any of the five critical cases caps the grade at F, a PARTIAL on a critical case caps at C, and a FAIL on a non-critical case caps at D. A capped grade is always reported with the case that caused it.
See a real one: redacted sample scorecard — ungated, no form.
Read the full methodology · what we do ·
whitepaper. Results are Ed25519-signed and hash-anchored — verifiable
against the pinned public key at /api/attestation/pubkey, with published digests
in the anchor manifest
(how to verify).