AIR
Proof LabStartEcosystemExplore (579)Live Systems (52)Pricing
M
Michael
Modernization Specialist

I’ll help you understand your current environment, identify what should change, and create an implementation plan.

This takes about 30 minutes to connect and review. The analysis happens automatically after that.

To understand your environment, I need permission to review the systems you choose.

Read-only access. We do not modify anything during assessment.

I’m reviewing your environment.

Your Infrastructure Assessment

Current posture

3 of 4 critical controls are protected. 1 area is exposed. 2 need attention.

What’s protected

Identity, access control, and backups are in good shape.

What’s exposed

Some systems still rely on cryptography that won’t hold up to quantum computers.

What needs attention

A few over-privileged accounts, and one aging key policy.

Recommended plan

Priority 1Modernize the cryptography on your exposed systems.
Priority 2Tighten the over-privileged accounts.
Priority 3Refresh the aging key policy.

Evidence package available — independently verifiable.

Would you like to implement this plan?

Download evidence package
Implementation Architecture · Recommended Plan

Your post-quantum implementation plan

A mapped architecture for the systems you connected. Every change is tied to a specific H33 service, a concrete endpoint, and independently verifiable evidence — and nothing executes until the conversion agent is governed.

Architecture
Your environment
AWS
KMS, ACM, TLS & workload crypto
Microsoft 365
Identity & policy posture
Okta
Access & entitlements
GitHub
Secrets & CI signing keys
H33 control plane
Agent-008
Governs the conversion agent — every change gated & replayable
PQ Conversions + H33-74
Modernize exposed crypto, attest each asset
H33-Key
Least-privilege machine identity
HATS
Continuous control verification
Outcome
Quantum-safe cryptography
RSA/ECC → NIST ML-KEM / ML-DSA
Least-privilege access
Over-privileged accounts closed
Every change governed
Replayable decision record
Insurance-grade proof
Continuous, signed evidence
Phased rollout
PHASE 0
Assess
Read-only review of the systems you connected. Nothing is modified.
/apqc/envelope
/apqc/connectors/*
PHASE 1
Govern the agent
Agent-008 governs the conversion agent before it touches anything.
/v1/agent-008/session
/v1/agent-008/decision
PHASE 2
Modernize crypto
Convert exposed RSA/ECC to NIST PQC; attest every converted asset.
/v1/pq/convert
/v1/h33-74/attest
PHASE 3
Least-privilege identity
Rotate exposed keys, revoke over-privileged access. Apps get authority; humans hold no secrets.
/v1/keys/rotate
/v1/keys/revoke
PHASE 4
Continuous verification
HATS proves controls stay in place — and the exact moment any drifts.
/v1/hats/controls
/v1/hats/attestation
Recommended endpoints
ServiceEndpointAccessProduces
Phase 0 · Assess (read-only)
AWS · crypto & KMS inventoryGET api.h33.ai/apqc/connectors/aws/inventoryRead-onlySigned asset inventory
Okta · identity & entitlementsGET api.h33.ai/apqc/connectors/okta/entitlementsRead-onlyPrivilege map
Microsoft 365 · policy postureGET api.h33.ai/apqc/connectors/m365/policiesRead-onlyPolicy findings
GitHub · secrets & CI keysGET api.h33.ai/apqc/connectors/github/secretsRead-onlyExposure list
APQC · assessment envelopePOST api.h33.ai/apqc/envelopeRead-onlyImmutable scope + report
Phase 1 · Govern the conversion agent — Agent-008
Agent-008 · governed sessionPOST api.h33.ai/v1/agent-008/sessionManagedSession of record
Agent-008 · gated decisionPOST api.h33.ai/v1/agent-008/decisionManagedAuthority·policy·evidence·precondition verdict
Agent-008 · decision replayGET api.h33.ai/v1/agent-008/replayRead-onlyReplayable decision log
Phase 2 · Modernize cryptography — PQ Conversions + H33-74
PQ · scan RSA/ECC in scopePOST api.h33.ai/v1/pq/scanRead-onlyQuantum-exposed inventory
PQ · convert to NIST PQCPOST api.h33.ai/v1/pq/convertManagedML-KEM / ML-DSA rollout
H33-74 · attest converted assetPOST api.h33.ai/v1/h33-74/attestManaged74-byte PQ attestation
H33-74 · verify attestationGET api.h33.ai/v1/h33-74/verifyRead-onlyIndependent proof
Phase 3 · Least-privilege identity — H33-Key
H33-Key · app authorityPOST api.h33.ai/v1/keys/resolveManagedSigned proof-of-use
H33-Key · rotate exposed keyPOST api.h33.ai/v1/keys/rotateManagedSigned rotation receipt
H33-Key · revoke over-privilegePOST api.h33.ai/v1/keys/revokeManagedSigned revocation
Phase 4 · Continuous verification — HATS
HATS · control checksGET api.h33.ai/v1/hats/controlsRead-onlyContinuous status
HATS · signed attestationPOST api.h33.ai/v1/hats/attestationManagedInsurance-grade evidence
HATS · drift transitionGET api.h33.ai/v1/hats/transitionsRead-onlySigned moment-of-drift
Commission & handoff — APQC lifecycle
APQC · grant authorityPOST api.h33.ai/apqc/grantManagedScoped, health-independent grant
APQC · commission planPOST api.h33.ai/apqc/commissionManagedApproved plan of record
APQC · derived reportGET api.h33.ai/apqc/reportRead-onlyDeterministic, hash-referenced report
APQC · HATS handoffPOST api.h33.ai/apqc/handoffManagedCustody transition to monitoring
Workstreams — mapped to your assessment
Priority 1
Modernize exposed cryptography
Convert the systems still relying on RSA/ECC to NIST post-quantum standards, and attest each converted asset so it can be proven quantum-safe.
PQ Conversions /v1/pq/convert · H33-74 /v1/h33-74/attest · verified by /v1/h33-74/verify
Priority 2
Tighten over-privileged accounts
Revoke standing over-privilege and move applications to short-lived, scoped authority — humans stop holding secrets.
H33-Key /v1/keys/revoke · /v1/keys/resolve · Okta entitlements connector
Priority 3
Refresh the aging key policy
Rotate the aging key material and place the new policy under continuous verification.
H33-Key /v1/keys/rotate · HATS /v1/hats/controls
Continue Monitoring Your Post-Quantum Conversion Here
Once the plan is implemented, HATS keeps verifying every converted control — and gives you signed, insurance-grade evidence, continuously.

This plan is generated from the systems you connected. Every step runs under a read-only or explicitly-granted scope, is governed by Agent-008 before it executes, and emits independently verifiable evidence. Endpoints shown are the integration points for each step.

Download evidence package

I’ll make the approved changes and keep a record of every decision.

Your environment is now protected.

One last step — set up billing to keep your protection active.

Billing

Secure checkout

Billing setup goes here — placeholder for the demo.

Welcome.

To monitor your connections, here’s your dashboard link. Have a wonderful day!