Proof LabStartEcosystemExplore (579)Live Systems (52)Pricing
APQC
APQC Terminal
Governed console · coordinates · displays · records

This console coordinates your modernization: the discovery role reviews your environment, the architect proposes an implementation plan under Agent-008 governance, and you approve it.

This takes about 30 minutes to connect and review. The analysis happens automatically after that.

To review your environment, the discovery role needs read-only permission on the systems you choose.

Read-only access. We do not modify anything during assessment.

The discovery role is reviewing your environment (read-only).

Your Infrastructure Assessment

Current posture

3 of 4 critical controls are protected. 1 area is exposed. 2 need attention.

What’s protected

Identity, access control, and backups are in good shape.

What’s exposed

Some systems still rely on cryptography that won’t hold up to quantum computers.

What needs attention

A few over-privileged accounts, and one aging key policy.

Recommended plan

Priority 1Modernize the cryptography on your exposed systems.
Priority 2Tighten the over-privileged accounts.
Priority 3Refresh the aging key policy.

Evidence package available — independently verifiable.

Would you like to implement this plan?

Download evidence package
Implementation Architecture · Recommended Plan

Your post-quantum implementation plan

A mapped architecture for the systems you connected. Every change is tied to a specific H33 service, a concrete endpoint, and independently verifiable evidence — and nothing executes until the conversion agent is governed.

Architecture
Your environment
AWS
KMS, ACM, TLS & workload crypto
Microsoft 365
Identity & policy posture
Okta
Access & entitlements
GitHub
Secrets & CI signing keys
H33 control plane
Agent-008
Governs the conversion agent — every change gated & replayable
PQ Conversions + H33-74
Modernize exposed crypto, attest each asset
H33-Key
Least-privilege machine identity
HATS
Continuous control verification
Outcome
Quantum-safe cryptography
RSA/ECC → NIST ML-KEM / ML-DSA
Least-privilege access
Over-privileged accounts closed
Every change governed
Replayable decision record
Insurance-grade proof
Continuous, signed evidence
Phased rollout
PHASE 0
Assess
Read-only review of the systems you connected. Nothing is modified.
/apqc/envelope
/apqc/connectors/*
PHASE 1
Govern the agent
Agent-008 governs the conversion agent before it touches anything.
/v1/agent-008/session
/v1/agent-008/decision
PHASE 2
Modernize crypto
Convert exposed RSA/ECC to NIST PQC; attest every converted asset.
/v1/pq/convert
/v1/h33-74/attest
PHASE 3
Least-privilege identity
Rotate exposed keys, revoke over-privileged access. Apps get authority; humans hold no secrets.
/v1/keys/rotate
/v1/keys/revoke
PHASE 4
Continuous verification
HATS proves controls stay in place — and the exact moment any drifts.
/v1/hats/controls
/v1/hats/attestation
Recommended endpoints
ServiceEndpointAccessProduces
Phase 0 · Assess (read-only)
AWS · crypto & KMS inventoryGET api.h33.ai/apqc/connectors/aws/inventoryRead-onlySigned asset inventory
Okta · identity & entitlementsGET api.h33.ai/apqc/connectors/okta/entitlementsRead-onlyPrivilege map
Microsoft 365 · policy postureGET api.h33.ai/apqc/connectors/m365/policiesRead-onlyPolicy findings
GitHub · secrets & CI keysGET api.h33.ai/apqc/connectors/github/secretsRead-onlyExposure list
APQC · assessment envelopePOST api.h33.ai/apqc/envelopeRead-onlyImmutable scope + report
Phase 1 · Govern the conversion agent — Agent-008
Agent-008 · governed sessionPOST api.h33.ai/v1/agent-008/sessionManagedSession of record
Agent-008 · gated decisionPOST api.h33.ai/v1/agent-008/decisionManagedAuthority·policy·evidence·precondition verdict
Agent-008 · decision replayGET api.h33.ai/v1/agent-008/replayRead-onlyReplayable decision log
Phase 2 · Modernize cryptography — PQ Conversions + H33-74
PQ · scan RSA/ECC in scopePOST api.h33.ai/v1/pq/scanRead-onlyQuantum-exposed inventory
PQ · convert to NIST PQCPOST api.h33.ai/v1/pq/convertManagedML-KEM / ML-DSA rollout
H33-74 · attest converted assetPOST api.h33.ai/v1/h33-74/attestManaged74-byte PQ attestation
H33-74 · verify attestationGET api.h33.ai/v1/h33-74/verifyRead-onlyIndependent proof
Phase 3 · Least-privilege identity — H33-Key
H33-Key · app authorityPOST api.h33.ai/v1/keys/resolveManagedSigned proof-of-use
H33-Key · rotate exposed keyPOST api.h33.ai/v1/keys/rotateManagedSigned rotation receipt
H33-Key · revoke over-privilegePOST api.h33.ai/v1/keys/revokeManagedSigned revocation
Phase 4 · Continuous verification — HATS
HATS · control checksGET api.h33.ai/v1/hats/controlsRead-onlyContinuous status
HATS · signed attestationPOST api.h33.ai/v1/hats/attestationManagedInsurance-grade evidence
HATS · drift transitionGET api.h33.ai/v1/hats/transitionsRead-onlySigned moment-of-drift
Commission & handoff — APQC lifecycle
APQC · grant authorityPOST api.h33.ai/apqc/grantManagedScoped, health-independent grant
APQC · commission planPOST api.h33.ai/apqc/commissionManagedApproved plan of record
APQC · derived reportGET api.h33.ai/apqc/reportRead-onlyDeterministic, hash-referenced report
APQC · HATS handoffPOST api.h33.ai/apqc/handoffManagedCustody transition to monitoring
Workstreams — mapped to your assessment
Priority 1
Modernize exposed cryptography
Convert the systems still relying on RSA/ECC to NIST post-quantum standards, and attest each converted asset so it can be proven quantum-safe.
PQ Conversions /v1/pq/convert · H33-74 /v1/h33-74/attest · verified by /v1/h33-74/verify
Priority 2
Tighten over-privileged accounts
Revoke standing over-privilege and move applications to short-lived, scoped authority — humans stop holding secrets.
H33-Key /v1/keys/revoke · /v1/keys/resolve · Okta entitlements connector
Priority 3
Refresh the aging key policy
Rotate the aging key material and place the new policy under continuous verification.
H33-Key /v1/keys/rotate · HATS /v1/hats/controls
Continue Monitoring Your Post-Quantum Conversion Here
Once the plan is implemented, HATS keeps verifying every converted control — and gives you signed, insurance-grade evidence, continuously.

This plan is generated from the systems you connected. Every step runs under a read-only or explicitly-granted scope, is governed by Agent-008 before it executes, and emits independently verifiable evidence. Endpoints shown are the integration points for each step.

Download evidence package

On your authorization, the performers make the approved changes under Agent-008 governance, and Verification records the evidence. This console coordinates and displays — it does not make the changes itself.

Your environment is now protected.

One last step — set up billing to keep your protection active.

Billing

Secure checkout

Billing setup goes here — placeholder for the demo.

Conversion complete. Continuous governance remains active.

The migration phase is complete. It does not end here — HATS monitors, Verification verifies, and Authority Center preserves the trusted baseline continuously.

What the Terminal is — and what it is not

APQC is the coordinator of governed cryptographic-estate transformation. It exists because crypto migration is a lifecycle — not a wizard — that must be orchestrated across many components without losing governance. This Terminal is the eight-phase reference console that runs that lifecycle: Govern → Discover → Architect → Validate → Commission → Supervise → Verify → Sustain. The console coordinates, displays, and records; the work of each phase is done by a named, external performer.

The APQC invariant. APQC coordinates each transition; it does not produce the evidence, govern the policy, render the verification verdict, or preserve authority. Read the phase steps above as coordination: the discovery role inventories, Agent-008 governs and authorizes, the cryptographic surfaces perform the ML‑KEM / ML‑DSA primitive, Verification renders the independent verdict, and HATS monitors continuously. The console never performs the primitive, decides authorization, or issues the verdict itself.

Who owns each adjacent responsibility: Agent-008 governs · H33-74 produces the portable evidence · Verification renders the verdict · Authority Center preserves authority · HATS records and monitors. When to use APQC vs. another capability: use APQC to coordinate the whole governed transformation; use the owning flagship directly when you need that one capability on its own. See the APQC specification suite for the vendor-neutral standard this console implements.

Common questions
Does the Terminal render the verdict?
No. The console coordinates and displays. The independent verdict is rendered by Verification in the Verify phase, from portable evidence alone — deliberately without trusting the console, the executor, or H33. This walkthrough shows a scripted reference engagement; the verdict shown is illustrative of that independent verification, not a live production result.
Does the Terminal do the monitoring?
No. Continuous monitoring is done by HATS in the Sustain phase. APQC coordinates the handoff and holds the trusted baseline; HATS watches the running estate and surfaces a recommendation only when something changes.
Does APQC perform the cryptographic conversion itself?
No. The ML‑KEM / ML‑DSA primitive is performed by the cryptographic surfaces, on a recorded human authorization, under Agent-008 governance. The console coordinates the operation and records it; it does not compute the primitive.
Is this walkthrough live or a demonstration?
This Terminal is a reference walkthrough of a single scripted engagement. It dramatizes timing and presentation so the eight phases read clearly; the underlying division of labor — who coordinates, who performs, who verifies — is exactly the production model described in the APQC standard.