Infrastructure Pillar

KXCO Sentinel

The quantum-resistant cloud, for building security resilience. Scan, host and prove your software against the quantum threat, before it ships, not after.

Sentinel is the quantum-resistant layer of the KXCO cloud. Bastion finds the breakable, quantum-vulnerable cryptography hiding in your code, dependencies and live endpoints, paste a URL or a repo, and hands you the exact fix; PQC Host ships every deploy quantum-proof, with an ML-DSA-65 signature anyone can verify. Post-quantum by default, not a migration bolted on later.

One product, three modules. Bastion finds and fixes the breakable cryptography across twenty-three target kinds. PQC Host refuses a critical deploy and signs the release. Agent Certainty scores an agent on nine dimensions of governance before it acts. Every report is signed with ML-DSA-65 and checkable at pqc.kxco.ai/verify, no account, no call.

Live Post-quantum by default ML-DSA-65 attested
Illustrative report
The Pipeline

Every scan runs the same path, from repo to verifiable proof.

Connect a repository and Bastion carries it through seven stages: detect the breakable cryptography, score it, generate the post-quantum fix, and seal the result with a signature anyone can verify, then keep watching.

GitHub
Paste any repo, public or private
Bastion
Auto-detects the stack in seconds
Crypto Scan
Finds RSA, ECC, SHA-1, weak TLS
Risk Score
0–100 with per-finding severity
PQ Fix
Before/after code + packages
Attestation
ML-DSA-65 signed, verifiable
Monitoring
Daily rescans, drift alerts
The Problem

Your cloud isn't quantum-resistant, and every scanner just hands you a report.

The RSA and ECC sitting in most software stacks is exactly what a cryptographically relevant quantum computer is expected to break. It rides along into production every time you deploy, and "we'll deal with it later" means shipping the exposure today and discovering it under a deadline later.

Existing hosting and scanning platforms don't fix that. They surface findings, generate a PDF, and walk away, no fix, no proof, and no way for a third party to confirm anything was actually done. None of them make the cloud itself quantum-resistant.

What's missing isn't another report. It's a cloud that catches the weakness before deploy, applies the post-quantum fix, and hands anyone a proof they can check themselves.

The Dependency Graph

See exactly where the breakable crypto lives.

Bastion traces every dependency down to the cryptographic primitive it uses, and lights up what a quantum computer can break. Hover a node to isolate its relationships; run the scan to trace the path from repo to risk.

Illustrative dependency graph. A Node.js repository, checkout-service on branch main, with 3 critical findings, depends on four packages: jsonwebtoken 8.5.1 (auth tokens), node-forge 0.10.0 (TLS and PKI), openssl-wrapper 1.1.1w (transport), and @kxco/pqc 1.0.0 (post-quantum). Those packages use five cryptographic primitives. Three are quantum-vulnerable or weak: RSA-2048, a signature and KEM primitive whose post-quantum fix is ML-KEM-768; ECDSA-P256, a signature primitive whose post-quantum fix is ML-DSA-65; and SHA-1, a deprecated hash whose fix is SHA-3-256. AES-256-GCM remains classically secure. The @kxco/pqc package provides the two post-quantum replacements, ML-KEM-768 (NIST FIPS 203, key encapsulation) and ML-DSA-65 (NIST FIPS 204, signature), which replace RSA-2048 and ECDSA-P256 respectively.

Why It Matters

A cloud built for the age of AI and quantum.

Quantum-resistant
Direct and immediate
This cloud exists because the RSA and ECC in the current stack is exactly what's exposed. Bastion detects RSA, ECC, SHA-1 and weak TLS across eight language ecosystems, and NIST post-quantum standards, FIPS 203/204, are native from day one, not a migration bolted onto a classical stack.
Provable
Proof with no vendor lock-in
Attestations are independently verifiable, the verification is mathematical, depending only on the ML-DSA-65 signature and the platform public key published at /.well-known/kxco-pq-pubkey. Verifiable by anyone, with no account and no connection to KXCO required.
AI
Optimize for AI
Most sites accidentally block the crawlers that feed AI answer engines. The Optimize for AI service fixes the technical foundation, robots.txt configuration, llms.txt, JSON-LD schema, and citation monitoring across the major AI models. See Optimize for AI →
Chain of Proof

Every result carries a proof that stands on its own.

A scan or deployment isn't a report you have to take on faith, it's a signed manifest. Follow how a build becomes a proof any third party can verify, with no access to KXCO.

Illustrative chain of proof. Build and Deploy takes a commit and source and runs the Bastion pre-deploy scan, producing a Deployment Manifest that binds the commit SHA, timestamp, scan result and live URL. That manifest is signed by an ML-DSA-65 signature (NIST FIPS 204). The signature is presented to any verifier, who needs only the Published Public Key at /.well-known/kxco-pq-pubkey, which is open and requires no account. Verification yields a Verifiable Proof that is tamper-evident and requires no trust in KXCO.

The Tech

How the quantum-resistant cloud compares, and how it works.

Two products, one job: find the weak cryptography and prove it's gone. Here's how each stacks up against the tools you already know.

KXCO Bastion vs. enterprise scanners
FeatureEnterprise scannersKXCO Bastion
Setup requiredSPAN port + Linux LD_PRELOAD agentZero, paste any file or URL
Time to first resultInfrastructure deployment requiredUnder 10 seconds
Detects RSA / ECC / SHA-1 / weak TLS✓✓ eight language ecosystems
Dockerfile / Terraform / KubernetesNot documented natively✓ all three, zero setup
CBOM export✓ (2 specific generators only)✓ CycloneDX 1.6, ML-DSA-65 signed
Migration code per findingImpact simulation dashboard✓ Before/after code + npm commands
Proof of assessmentProprietary control plane✓ ML-DSA-65, independently verifiable
PQ-native standardsPQ migration on classical stack✓ NIST FIPS 203/204 from day one
Quantum-resistant hosting vs. Vercel / Netlify / Fly
FeatureVercel / Netlify / FlyKXCO Cloud
Static + Node.js hosting✓✓
GitHub auto-deploy✓✓
Free TLS✓✓
Pre-deploy security scanSome✓ KXCO Bastion
Quantum-vulnerability detection✗✓
ML-DSA-65 deployment attestation✗✓
Independently verifiable proof✗✓

Bastion

Scan → risk score → fix
01
Submit any target
Twenty-three target kinds, no setup for any of them. URL/TLS, package.json, requirements.txt, go.mod, Gemfile, Cargo.toml, pom.xml, nginx/OpenSSL config, Dockerfile, Terraform HCL, GitHub Actions YAML, Kubernetes manifests. Auto-detected.
02
Receive your ML-DSA-65 attested report
Risk score (0–100), per-finding severity, blast radius estimate, and the exact KXCO package command for every fix. Every report is ML-DSA-65 signed and exports as a CycloneDX 1.6 CBOM.
03
Apply the PQC fix
One click generates before/after code and npm commands for every finding. Confirming produces an ML-DSA-65 certificate of remediation, independently verifiable forever.

PQC Host

Connect repo → pre-deploy scan → attestation
01
Connect your GitHub repo
Paste any public or private GitHub URL. Framework auto-detected in under 3 seconds, Next.js, React, Vue, Svelte, static, Node.js all supported.
02
Bastion scans before we build
Before a single line compiles, Bastion checks your package.json for quantum-vulnerable dependencies. Critical findings block the deploy.
03
ML-DSA-65 attestation issued
The moment your build completes, the platform signs a deployment manifest: commit SHA, build timestamp, Bastion result, and live URL. Verifiable forever.
Signing Authority

One key. Anyone can check it. No account required.

Every signature roots to a single post-quantum key, published openly at a well-known address. See how signing authority is delegated, and why verification needs nothing but that public key.

Illustrative signing-authority tree. The KXCO Root Authority uses ML-DSA-65 and is held in offline custody. It delegates to a Platform Signing Key, which is rotated on a schedule. That platform key signs three things: the Scan Report Signature covering every Bastion report, the Deployment Signature covering every PQC Host deploy, and the CBOM Signature covering the CycloneDX 1.6 export. All three are verified by the Published Public Key at /.well-known/kxco-pq-pubkey, which any third party can check using the public key alone.

Capabilities

What the quantum-resistant cloud does.

Two products, both live on the KXCO Cloud platform.

Compliance

Mapped to the standards regulators actually cite.

Sentinel's capabilities line up against the post-quantum standards and government mandates. Hover a capability or a framework to see what connects to what.

Illustrative standards map. KXCO Sentinel, the quantum-resistant cloud, implements four capabilities: Crypto Detection (finds RSA, ECC, SHA-1 and TLS weaknesses), PQ Remediation (applies ML-KEM and ML-DSA fixes), ML-DSA-65 Attestation (emits signed, verifiable proof), and CBOM Export (CycloneDX 1.6 format). These align to six standards and mandates. PQ Remediation aligns to NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). Attestation aligns to FIPS 204, to the NSA's CNSA 2.0 (2030 deadline) and to NSM-10 (US Federal, 2035 deadline). Crypto Detection aligns to CNSA 2.0 and NSM-10. CBOM Export aligns to the CycloneDX CBOM standard.

Who It's For

Anyone who has to prove their software is quantum-resistant.

Sentinel serves teams that need to find, fix and evidence quantum-vulnerable cryptography, for auditors, regulators, or their own peace of mind.

Engineering teams Security & compliance Regulated platforms CI/CD pipelines Auditors Agencies shipping client sites
FAQ

Quantum-resistant cloud, in plain terms.

The questions we hear most, answered straight.

What is a quantum-resistant cloud?
A quantum-resistant cloud, also called a quantum-safe, quantum-proof or post-quantum cloud, is hosting and tooling engineered to withstand attacks from future quantum computers. KXCO Sentinel is that cloud: it scans your code and dependencies for quantum-vulnerable cryptography such as RSA and ECC, hosts your software with a quantum-proof pre-deploy scan, and proves every release with an ML-DSA-65 signature anyone can verify. It implements the NIST post-quantum standards FIPS 203 and FIPS 204. PQC Host hosts software you deploy. It does not host models, and KXCO never holds your weights.
Does KXCO run a quantum computer?
No. KXCO does not operate quantum computers or offer quantum processing. Sentinel is a quantum-resistant cloud, it protects conventional software from the quantum threat using NIST-standardised post-quantum cryptography (ML-KEM / FIPS 203 and ML-DSA / FIPS 204). The goal is defence against quantum attacks, not quantum computation.
What makes cloud hosting quantum-proof?
On KXCO PQC Host, every deployment is scanned by Bastion before it builds, quantum-vulnerable dependencies can block the deploy, and the moment the build completes the platform signs a deployment manifest (commit SHA, timestamp, scan result and live URL) with an ML-DSA-65 post-quantum signature. That signed, independently verifiable proof is what makes the hosting quantum-proof rather than merely quantum-aware.
Which cryptography is vulnerable to quantum computers?
RSA, elliptic-curve cryptography (ECC/ECDSA), Diffie-Hellman key exchange, SHA-1 and weak TLS configurations are all breakable by a cryptographically relevant quantum computer. KXCO Bastion detects these across eight language ecosystems plus Dockerfiles, Terraform, Kubernetes manifests and CI/CD configuration, and returns the exact post-quantum fix for each finding.
How do you prove software is quantum-resistant?
KXCO signs each scan report and deployment manifest with an ML-DSA-65 (NIST FIPS 204) signature. Anyone can verify that signature against the platform public key published at /.well-known/kxco-pq-pubkey, with no account and no connection to KXCO required. The proof is mathematical, so it stands on its own and cannot be quietly rewritten.
When do organisations need to migrate to post-quantum cryptography?
NIST finalised the post-quantum standards FIPS 203, 204 and 205 in August 2024. The NSA's CNSA 2.0 timeline makes post-quantum signing mandatory for national security systems by 2030, and US federal systems target the removal of quantum-vulnerable algorithms by 2035 (NSM-10). Because encrypted data can be harvested now and decrypted later, sensitive data is already at risk today.
Who You Are Dealing With

A scan that can't be placed in an organisation is only a PDF.

The group, the filed entity, the counsel and the mathematics are on this page so a counterpart doesn't have to ask.

The group
Knightsbridge Group
Operating presence in Bangkok, Doha, Paris and London. KXCO is the software company of the group, and Sentinel is a KXCO product.
The filed entity
Knightsbridge Financial Ltd
England & Wales, Company No. 15684975, incorporated 27 April 2024. LEI 213800TMP5DQFDKOZ549. ICO data-controller reference C1961692.
Counsel and access
Knightsbridge Law
Group counsel, inside the group rather than a hired panel. Access is granted on approval: admin@kxco.ai. KXCO holds no financial licence and does not custody assets. Licensed institutions that deploy the software hold those relationships.
Connected Rails

Sentinel is not an orphaned scanner.

The same identity, authority and signature layer carries the deals, the money and the agents.

Associations

Not a client wall. The rooms and records that verify without us.

Working groups first. Developer programmes are memberships, and are named as such.

Where Knightsbridge Financial Ltd sits, and what to check
AssociationStatusCheck
PKI ConsortiumMember: Knightsbridge Financial Ltd. Working groups PQC, CBOM, CM, PKIMM, TCWGpkic.org/members →
Cloud Security AllianceQuantum-Safe Security Working Group, memberCSA working group →
DIF / Linux FoundationContributor member M-018609, to 26 August 2027identity.foundation →
CoSAI / OASIS OpenOpen Project participant, from 26 August 2026coalitionforsecureai.org →
IETF LAMPS WGParticipant. Post-quantum X.509 certificate workIETF datatracker →
NIST FIPS 203 / 204 / 205Implemented in production: ML-KEM-768, ML-DSA-65, SLH-DSA. ACVTS credentials active. Implemented, not endorsedNIST FIPS 204 →
IBM Quantum NetworkMember. Programme membership, not a joint ventureIBM Quantum Network →
NVIDIA Developer ProgramMemberdeveloper.nvidia.com →
Visa Developer ProgramMemberdeveloper.visa.com →
xAI Developer ProgramMemberx.ai →

Aligned to NSA CNSA 2.0 and the US federal 2035 path. Further developer-programme memberships are listed on the company page.

Proof Anyone Can Run

Every institutional sentence here has a number or a URL you can open.

No account, and no call to us.

Don't just find it. Fix it, and prove it.

Sentinel scans your code, containers, AI agents and MCP servers for quantum-vulnerable cryptography and agent-trust risks, returning a signed report you can hand to an auditor. Or talk to us about quantum-resistant hosting and Bastion in your CI/CD pipeline. New: read why BlackRock's quantum warning makes post-quantum an infrastructure requirement.