Policy updated 25 September 2026

How this resource is maintained

CheckPQC is maintained by Aegyrix LLC. Our goal is practical, inspectable evidence for the systems you use. The methodology explains what each check establishes.

Evidence has a scope

We distinguish an observed connection, a local capability, a vendor-documented feature and an unknown result. Work completion is a separate status. A green connection result is not a device, organization, compliance or security certification.

Sources and technical review

Guides reference standards bodies and the product's own documentation. We separate algorithms, protocol standards, product capabilities and actual deployments. A documentation review date does not mean we executed every command on every supported platform. Each expanded walkthrough labels illustrative output and its validation limits.

Software and vendor defaults change. Before applying a configuration change, match the guide to your deployed version, test in a controlled environment, retain a working configuration and verify the actual negotiated result.

Review cadence and validation

High-change browser, cloud and runtime documentation is due for review every 90 days; other guide sources every 180 days. Automated checks can detect broken links, expired review dates and script drift. They cannot establish that a vendor statement is true for your deployment. A human or technical documentation review must update the date after checking the substance.

Our script suite exercises recognized hybrid/classical results, unknown groups, certificate failures, timeout and output limits. Platform prerequisites are listed on the scripts page. Builds and automated fixtures are distinct from successful handshakes on your exact system.

Guide review register
GuideDocumentation reviewedValidation scope
Android2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Apache HTTP Server2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
AWS2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Azure2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
BoringSSL2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Caddy2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
CDNs and hosted websites2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Google Chrome2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
ChromeOS2026-09-25Documentation reviewed; see guide for executed checks and illustrative examples.
Cloudflare2026-09-25Official documentation reviewed; example output is illustrative. See guide for prerequisites and execution limits.
curl2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
.NET2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Microsoft Edge2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Email transport2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Mozilla Firefox2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Google Cloud2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Go crypto/tls2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
iMessage and PQ32026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
iOS and iPadOS2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Java and JSSE2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Linux2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
macOS2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
nginx2026-09-25Official documentation reviewed; example output is illustrative. See guide for prerequisites and execution limits.
Node.js2026-09-25Syntax checked; available Node 25.9.0 executed against owned endpoint. Missing high-level group stayed unknown; TLS trace confirmed hybrid. No platform matrix claimed.
Network Security Services (NSS)2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
OpenSSH2026-09-25Official documentation reviewed; example output is illustrative. See guide for prerequisites and execution limits.
Check post-quantum TLS with OpenSSL2026-09-25Official documentation reviewed; example output is illustrative. See guide for prerequisites and execution limits.
OpenVPN2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
PHP2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Python2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
rustls2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Safari2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Signal2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
WhatsApp2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
Windows2026-09-25PowerShell snippets parsed on macOS. No Windows or Schannel runtime execution claimed.
WireGuard2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.
wolfSSL and embedded devices2026-09-24Documentation reviewed; see guide for executed checks and illustrative examples.

Script integrity and changes

Downloads are readable source. We publish a version and SHA-256 manifest, a checksum file and script change notes. Compare the hash to detect a changed or incomplete download. A hash served by the same website is not independent proof of publisher identity. Review source and obtain tools through your normal trusted distribution process.

Corrections and security reports

Send a correction with the page URL, the statement or command, your platform/version, a primary source and the expected behavior. Remove hostnames, logs and other sensitive details that are not necessary. Do not send keys, tokens or session secrets.

Use the private security contact form for vulnerabilities and the general contact form for other questions. Our change history records material resource updates.

Privacy and independence

The guide library and worksheet require no account. Worksheet data stays on your device; saving and exporting are explicit. We do not add advertising or behavioral analytics. See privacy details for hosted checks and operational logs.