Using AI to chart a course for our post-quantum migration
Cloudflare describes using AI to map cryptography usage and identify post-quantum migration prerequisites across its platform. The internal tool tracks per-repository metrics and surfaces dependencies lacking post-quantum standards. This supports the company's 2029 readiness target by helping engineering teams understand upgrade paths for encryption and authentication protocols.

Quantum computers capable of breaking current public‑key schemes are progressing in laboratories worldwide, creating a future risk that today’s encryption could be rendered insecure. Cloudflare has set a 2029 deadline to achieve full post‑quantum readiness, meaning every encryption and authentication method must resist quantum attacks. The uncertainty lies in how many existing components still rely on classical algorithms such as RSA or X25519, which lack quantum‑resistant replacements. All of Cloudflare’s products and the customers that route traffic through its network depend on the same cryptographic foundations, so any weakness impacts the broader internet ecosystem. Internally, the codebase spans many repositories, and cryptographic usage is often hidden in libraries, configuration files, or indirect dependencies, making discovery difficult. The scale of the problem means that even unused code fragments can inflate risk assessments, while unseen defaults may leave critical pathways unprotected. Cloudflare is employing an AI‑driven internal tool called CryptoLabe to map cryptography across every repository, capture per‑product metrics, and flag dependencies that lack post‑quantum standards. The tool scans source, manifests, lockfiles, scripts, tests and documentation, then produces structured analysis to guide engineering teams toward upgrading to post‑quantum TLS 1.3 and future authentication schemes. Ongoing collaboration with standards bodies and ecosystem stakeholders is intended to close the remaining gaps before the 2029 target is reached.