The governed agent already understands your cryptography, secrets, sensitive data, AI privacy boundaries, and ownership. It analyzes your environment and tells you exactly what stands between you and migration.
No configuration. No provider selection. No scan wizard. One click.
Discovering your environment…
✓ Assessment complete
Assessment completed in 2 minutes 14 seconds
391 assets analyzed across 8 connected systems.
Your environment is ready for post‑quantum migration.
2 systems need your approval before conversion.
Executive Summary
We analyzed your environment and found 391 cryptographic assets. Nearly all are ready for automated post-quantum migration. Two production systems require your approval because they could affect live traffic. Sensitive workloads and credentials have already been identified and will remain protected throughout the migration. No unauthorized agent activity occurred during the assessment.
Safe Assessment
✓ No production systems were modified
✓ No cryptography was changed
✓ No credentials were exposed
✓ This was a read-only assessment
Recommendation
Based on your environment, I recommend automatically migrating:
✓ Migrate automatically
✓ 284 RSA keys
✓ 67 ECC keys
✓ 389 certificates
These assets present low migration risk.
Before proceeding, I'd like your approval for:
⚠ Needs your approval
⚠ Customer Portal
⚠ VPN Gateway
Reason: these systems could affect production traffic.
Estimated Automation
389
Automatic
2
Requires approval
0
Manual
You only need to make two decisions.
Why I recommended this
Customer Portal
• Handles production traffic
• 4 dependent systems
• Certificate expires in 11 months
• Low migration risk
→ Recommended after your approval
VPN Gateway
• Terminates all remote production access
• 6 dependent systems
• Rekey requires a maintenance window
• Low migration risk
→ Recommended after your approval
What we found
391assets discovered
284 RSA keys, 67 ECC keys, and 389 certificates across your infrastructure. The vast majority are ready for automated migration with no action from you.
14credentials need to be secured before migration
These will automatically be protected by H33-Key during migration. Your applications keep working — the secret is simply never exposed again.
7workloads contain sensitive data
These workloads will execute without exposing plaintext to AI. The data stays encrypted end-to-end, even while it's being processed.
Recommended actions
ImmediateThese prevent migration today
Customer Portal · VPN Gateway — internet-facing, with regulated data behind them. Approve these first.
APQC is the coordinator of governed cryptographic-estate transformation. It exists because crypto migration is not one step but a lifecycle — discovery, planning, authorization, execution, verification, and continuous operation — that has to be orchestrated across many components without ever losing governance. Discover is the phase APQC coordinates to turn an unknown estate into a stated inventory: cryptography, secrets, sensitive data, privacy boundaries, and ownership, with coverage made explicit and known gaps named rather than hidden.
The APQC invariant. APQC coordinates the transition; it does not produce the evidence, govern the policy, render the verification verdict, or preserve authority. In this phase the read-only discovery role does the inventory under Agent-008 governance; the console coordinates and displays the result. Nothing is modified during assessment.
Who owns each adjacent responsibility:Agent-008 governs the discovery agent's authority · H33-74 produces the portable evidence · Verification renders the independent verdict (later, in Verify) · Authority Center preserves the governed operating state · HATS monitors continuously (later, in Sustain). When to use APQC vs. another capability: use APQC to coordinate the discovery transition inside the lifecycle; use the owning flagship directly when you need that capability on its own.
Common questions
Does APQC render the verdict on what it found?
No. APQC coordinates discovery; it does not render a verification verdict. The independent verdict is rendered by Verification in the Verify phase, from the evidence alone. Discover states an inventory with coverage — it does not certify it.
Does APQC do the monitoring?
No. Continuous monitoring is done by HATS in the Sustain phase. Discover is a point-in-time, read-only inventory; APQC coordinates it and hands the result forward.
Does Discover change anything in my environment?
No. Discover is read-only. The discovery role reviews the systems you connect and produces an inventory. No cryptography, credentials, or production systems are modified during assessment.
Who governs the discovery agent while it works?
Agent-008 governs the agent's authority and records that it acted within scope. APQC coordinates the transition and displays the activity; it does not itself decide whether an action was authorized.