Your crypto inventory is finished.
Your agents just made it wrong.
Post-quantum migration is an inventory problem before it is an algorithm problem — most organisations will spend 2026 and 2027 mapping what cryptography they have. A server estate holds still while you map it. An agent fleet does not: it creates keys, sessions and channels continuously, so the inventory is obsolete the moment it is finished. PQ CENSUS measures the fleet again, every run, from evidence the platform already holds — and prints what it could not measure next to what it could.
Four measurements per agent — three states each, never a silent pass
Is the agent’s harness configuration post-quantum signed?
Every configuration we govern carries an ML-DSA-87 (FIPS 204, level 5) signature that is verified on each run — a signature that fails to verify is no signature. PQ · CLASSICAL · UNVERIFIED.
What does the agent authenticate with?
Registered credentials are classified: FIPS 203/204/205 schemes are PQ; symmetric keys at 256 bits (AES-256, HMAC-SHA-256 and up, ChaCha20) meet the house grade; 128-bit symmetric is adequate under NIST IR 8547 and is reported as such — adequate by the standard, not by our bar; RSA, ECDSA, Ed25519 and DH are CLASSICAL; an agent with nothing registered is UNVERIFIED, not clean.
Can the destinations it reaches do TLS 1.3 at all?
TLS 1.3 is the precondition for hybrid post-quantum key exchange. A destination stuck on 1.2 can never do it — that agent’s channel is CLASSICAL-LOCKED, whatever its keys look like.
Does the destination actually negotiate X25519MLKEM768?
Measured with a hybrid-only ClientHello: VERIFIED when the destination negotiates the ML-KEM hybrid, ABSENT when it completes TLS 1.3 without it, UNVERIFIED when it could not be probed. Not inferred from a vendor’s roadmap — observed on the wire.
The house rule: when a higher level exists, we take it. Our signatures are ML-DSA-87 — FIPS 204 level 5, the highest — and our symmetric bar is 256 bits, above the NIST minimum we quote. READY means the house grade on every dimension, not the minimum on any.
Verdict per agent is worst-of: any CLASSICAL → CLASSICAL; any gap → UNVERIFIED; all four
good → READY. The fleet wall prints MEASURED n/m agents and is never green while a single
agent is unverified. We ran it on our own house before we offered it to anyone: some of the largest edges on the internet already negotiate the hybrid today, and some widely used APIs do not yet. The census says which, per agent, per destination — and it says UNVERIFIED where it could not look.
What you get
Fleet readiness, with its denominator
How many agents are READY, PARTIAL, CLASSICAL, UNVERIFIED — and how many the run actually measured. Re-run daily; the fleet moved since yesterday.
Harvest-now, decrypt-later, dated
Which agents move data that is still sensitive in 2035 over anything not proven post-quantum. The CFO-legible version of the threat: a function of data lifetime, not of when the machine arrives.
Signed with ML-DSA-87 — it outlives the audit
Every run is hashed and post-quantum signed. Crypto-agility is attested, not promised: a change of algorithm is a re-sign, not a re-architecture.
Why nobody else sells this
Because nobody else holds the agent census to build it on. A crypto-inventory vendor sees certificates and keys on servers. AIM sees the agents — which one holds which credential, which destinations it was seen reaching, whether its harness is signed — and can therefore say, per agent, what is post-quantum and what is not, today, and again tomorrow.
PQ CENSUS is part of AIM — €450 / €2,250 / €10,800 per agent per year by passport class, minimum €45,000
One conversation with whoever owns your post-quantum migration plan. We bring the honest number and your fleet’s first census.
Talk to us AIM pricing · the passport ladder