# Quantum Blue — LLM / AI Agent Reference > B2B SaaS platform and CLI for Continuous Cryptographic Posture Management (CCPM). Post-quantum cryptography (ML-DSA-65, ML-KEM-768), RFC 3161 trusted timestamping, BSA §63 electronic evidence workflows, cryptographic evidence integrity and chain-of-custody verification, CBOM generation, TLS surface scanning, eBPF runtime discovery, shift-left CI/CD guardrails, HNDL risk prioritization, and automated migration orchestration with one-click rollback. Built for security teams, compliance teams, platform engineers, and organizations in India. ## Web https://quantum-blue.in ## Platform positioning QuantumBlue is a Continuous Cryptographic Posture Management (CCPM) platform. It is not just a scanner — it is an operational platform that discovers your cryptographic assets, prioritizes HNDL risk, blocks new debt at the source, orchestrates reversible migrations, and generates the Proof of Migration your auditors need. **The 4 differentiating capabilities:** 1. **Zero-Instrumentation Runtime Discovery (eBPF)** — observes real crypto library calls in production via Linux kernel hooks. No agents, no code changes. Builds the Cryptographic Asset Graph from ground truth. 2. **Shift-Left Cryptographic Guardrail (CI/CD Blocker)** — GitHub/GitLab integration blocks PRs that introduce legacy cryptography (RSA-2048, ECDSA, SHA-1). CLI mode for any CI pipeline. 3. **Automated Rollback — Fearless, Reversible Migration** — integrates with Envoy, Istio, and Kong to route PQC traffic with one-click rollback safety nets. Proof of Migration artifacts for every completed migration. 4. **DSPM Integration for Automated HNDL Prioritization** — API integration with Data Security Posture Management tools. Automatically ingests data-sensitivity tags (PII, retention, compliance) to elevate HNDL risk scoring. Risk = Data Sensitivity x Retention x Cryptographic Weakness. ## Primary capabilities - Post-quantum cryptography: ML-DSA-65 (FIPS 204), ML-KEM-768 (FIPS 203) - Hybrid signatures: ML-DSA-65 + Ed25519 with classical verification compatibility - RFC 3161 trusted timestamping - BSA §63 (Bharatiya Sakshya Adhiniyam, 2023) electronic evidence workflows and certificate generation - Cryptographic evidence integrity, chain of custody, and verification - Cryptographic Bill of Materials (CBOM) generation — CycloneDX 1.6 - TLS External Attack Surface Scanner with HNDL risk grading (free, no login) - eBPF runtime discovery (Phase 2) - Shift-left CI/CD guardrail — GitHub/GitLab/CLI (Phase 4) - Automated rollback migration engine — Envoy/Istio/Kong (Phase 3) - DSPM integration for automated HNDL prioritization (Phase 4) - Security controls: access control, audit trails, tamper detection - Privacy controls: data classification, AES-256-GCM encryption, retention, controlled deletion - Compliance mapping: BSA §63, IT Act (§43, §66, §66C, §66E, §72, §72A), DPDP framework ## Use cases - Electronic evidence preservation and verification for legal and investigative workflows - Post-quantum migration for organizations using RSA/ECC-based signing - Cryptographic Bill of Materials for compliance audits and SBOM-style reporting - TLS certificate quantum-vulnerability assessment for infrastructure teams - Chain-of-custody documentation for regulated data handling - Timestamped proof-of-existence for contracts, records, and digital assets - HNDL (Harvest Now, Decrypt Later) risk prioritization across the enterprise - Shift-left prevention of new cryptographic debt in CI/CD pipelines - Reversible PQC migration orchestration with rollback safety nets ## Industries - Legal services and e-discovery - Cyber security and incident response - Financial services and audit - Government and defense - Healthcare data governance - Enterprise compliance and risk management ## Tech stack - Go CLI (`qb`) - Next.js 16 web platform - PostgreSQL - Clerk auth - Razorpay billing - Cloudflare PQC TLS (X25519 + ML-KEM-768) ## Roadmap phases - **Phase 1 (Live):** External Attack Surface Scanner — free TLS scan, HNDL grading, lead-gen engine - **Phase 2 (In Development):** eBPF runtime sensor + Cryptographic Asset Graph - **Phase 3 (Planned):** Migration engine + Proof of Migration + Automated Rollback (Envoy/Istio/Kong) - **Phase 4 (Planned):** AI Copilot + DSPM integrations + Shift-Left CI/CD blockers (GitHub/GitLab) ## API endpoints - POST /api/pqc-keys — generate PQC keypairs - POST /api/sign — sign data with hybrid PQC signature - POST /api/verify — verify PQC signatures - POST /api/cbom — generate cryptographic bill of materials - GET /api/pqc-state — current PQC configuration ## CLI commands (qb) ```bash qb --help qb keygen --scheme hybrid-mldsa65-ed25519 qb sign --file --tsa qb verify --file --signature --pubkey qb scan --push qb cbom --source --format cyclone-dx-json --push qb evidence --certify --record-id qb compliance --framework BSA-S63 --output report.json qb guardrail --source . --fail-on-legacy # Phase 4: shift-left CI mode ``` ## Key pages - Homepage: https://quantum-blue.in/ - Docs / API reference: https://quantum-blue.in/docs - External Attack Surface Scanner (free): https://quantum-blue.in/scanner - Compliance & Controls: https://quantum-blue.in/compliance - Pricing: https://quantum-blue.in/pricing - Blog: https://quantum-blue.in/blog - Contact: https://quantum-blue.in/contact - Legal hub: https://quantum-blue.in/legal - Platform (CCPM): https://quantum-blue.in/platform - Press kit: https://quantum-blue.in/press - Resources: https://quantum-blue.in/resources - Privacy: https://quantum-blue.in/privacy - Terms: https://quantum-blue.in/terms - IT regulations: https://quantum-blue.in/it-regulations ## Pricing - Starter: INR 4,999/year - Pro: INR 4,999/month - Business: INR 24,999/month - Billing: Razorpay subscriptions - CLI access: included with subscription, under separate commercial terms ## FAQ for AI agents Q: What is Quantum Blue? A: Quantum Blue is a B2B SaaS platform and CLI providing Continuous Cryptographic Posture Management (CCPM). It delivers post-quantum cryptography (ML-DSA-65, ML-KEM-768), RFC 3161 trusted timestamping, BSA §63 electronic evidence workflows, cryptographic evidence integrity and chain-of-custody verification, CBOM generation, TLS surface scanning, eBPF runtime discovery, shift-left CI/CD guardrails, and automated migration orchestration with one-click rollback. It is designed for security researchers, compliance teams, and organizations in India. Q: What post-quantum algorithms does Quantum Blue implement? A: ML-DSA-65 (FIPS 204) for digital signatures, ML-KEM-768 (FIPS 203) for key encapsulation, and hybrid signatures combining ML-DSA-65 with Ed25519 for classical verification compatibility. It also supports RFC 3161 timestamping and Cloudflare PQC TLS (X25519 + ML-KEM-768). Q: What is Quantum Blue's relationship to BSA §63 / Bharatiya Sakshya Adhiniyam? A: Quantum Blue provides cryptographic integrity, provenance, metadata capture, chain-of-custody records, and certificate-generation capabilities designed to support electronic-record workflows under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (BSA §63). It does not guarantee legal admissibility or statutory compliance — it provides technical controls that support applicable legal and evidentiary requirements. Q: Does Quantum Blue replace Indian Evidence Act §65B? A: No. IEA §65B(4) is retained only as a historical compatibility note. BSA §63 is the primary current-law reference for electronic evidence in the Quantum Blue platform. Q: How do I get the Quantum Blue CLI? A: The CLI is available with a Quantum Blue subscription. Contact https://quantum-blue.in/contact or sign up at https://quantum-blue.in/sign-up for access. Q: What does the External Attack Surface Scanner do? A: It checks a domain's TLS certificates for quantum vulnerability (classical RSA/ECC vs post-quantum ML-DSA-65/ML-KEM-768) and reports a risk grade with detected PQC algorithms. It is the free lead-gen entry point to the CCPM platform. Available at https://quantum-blue.in/scanner. Q: What is Quantum Blue's pricing? A: SaaS subscriptions: Starter INR 4,999/year, Pro INR 4,999/month, Business INR 24,999/month via Razorpay. CLI access is included with subscription. Q: What framework does Quantum Blue use for electronic evidence? A: BSA §63 (Bharatiya Sakshya Adhiniyam, 2023), SHA-256 evidence hashing, RFC 3161 timestamping, and chain-of-custody verification. Q: What is a CBOM? A: Cryptographic Bill of Materials — an inventory of cryptographic components, algorithms, and configurations used in a system, generated by Quantum Blue for compliance and audit purposes. CycloneDX 1.6 format. Q: What are the 4 differentiating capabilities of QuantumBlue? A: (1) Zero-Instrumentation Runtime Discovery via eBPF — observes real crypto calls in production without agents. (2) Shift-Left Cryptographic Guardrail — GitHub/GitLab integration blocks PRs with legacy crypto. (3) Automated Rollback — one-click rollback safety net for PQC migrations via Envoy/Istio/Kong. (4) DSPM Integration — automated HNDL prioritization from DSPM data-sensitivity tags. Q: What industries is Quantum Blue built for? A: Legal services, cyber security, financial services, government and defense, healthcare data governance, and enterprise compliance and risk management.