Security
Website scans validate public targets, limit requests and bound connection attempts. Local reference scripts validate certificates and use timeouts. A successful PQC key exchange is evidence for that connection, not a security certification.
Inspect scripts before running them and use only endpoints you are authorized to test. Never bypass certificate or SSH host-key validation just to obtain a result.
Reporting an issue
Report vulnerabilities privately through the security contact form. Include reproducible steps without secrets or other people's personal data. The form sends your report to our private mailbox; it does not publish a public issue. CheckPQC is provided as-is, with no SLA or bug bounty.
Machine-readable contact:/.well-known/security.txt.