Cloudflare Builds AI Tool to Drive Post-Quantum Migration
Cloudflare is leveraging artificial intelligence to map its vast cryptographic infrastructure and work toward a full post-quantum readiness goal by 2029.

Targeting Post-Quantum Readiness
As laboratories around the world work toward building a cryptographically relevant quantum computer, Cloudflare is pressing forward toward a 2029 target deadline for full post-quantum readiness. While the platform has already transitioned many of its products to post-quantum encryption, significant work remains to support post-quantum authentication and achieve complete readiness across the entire ecosystem.
The company maintains a maximalist stance regarding the transition, often summarized as "PQ everything!" As an infrastructure provider operating at a massive global scale, the firm aims to ensure that customer traffic is future-proofed against potential quantum adversaries. Cryptography serves as the foundational base layer for digital systems, networking protocols, and software services across the platform.

Goals for the Cryptographic Migration
To successfully guide this massive migration, the organization established three primary goals. First, the company wants to help product and engineering teams understand current cryptographic implementations and determine how to upgrade them. This involves addressing both post-quantum encryption and post-quantum authentication across systems.
While many products have already adopted post-quantum encryption over TLS 1.3, deployments of post-quantum authentication are still in early days. The migration roadmap also focuses on providing clear progress metrics, such as per-repository and per-product counts of classical and post-quantum cryptographic usage.

Introducing CryptoLabe
To solve the complex challenges of tracking cryptographic dependencies across its codebase, the team began developing an internal AI-powered tool called CryptoLabe. The system is named after the mariner’s astrolabe, a historical navigation instrument refined by Portuguese navigators to help sailors determine their location and chart a safe course.
CryptoLabe is tailored specifically to internal organizational systems, including source code repositories, ticketing platforms, and documentation workflows. Because it remains highly specialized and under active development, the company is not making the tool directly available to customers. Instead, the organization is sharing its learnings to assist other enterprises undertaking their own post-quantum migration journeys.
Overcoming Scale and Codebase Challenges
Most software powering Cloudflare products resides within a centralized source control management platform, making code discovery theoretically straightforward. However, the organization must still navigate several distinct scale-related obstacles. Cryptography frequently hides within shared libraries, default protocol configurations, separate configuration repositories, and deprecated or test-only code paths.
Traditional code searching methods like grepping for specific terms such as RSA or X25519 often fall short. Simple text matching tends to overcount by flagging unused code or undercount by missing indirect dependencies and protocol defaults. Furthermore, basic pattern matching cannot determine how a classical ECDSA signature is utilized within protocols like JWT, IPsec, TLS, or SSH.

How the AI Scanner Operates
Artificial intelligence models are capable of searching codebases, tracing evidence across multiple files, and generating structured analysis. The AI can also enrich its findings by pulling contextual data from internal documentation and ticketing systems to explain how cryptography is applied.
The current implementation of CryptoLabe scans repositories in two distinct stages. The initial discovery stage maps the codebase and searches for cryptographic elements across source files, manifests, lockfiles, scripts, configurations, and documentation. This phase produces a collection of raw observations for further review.

Analysis and Classification Stages
Each raw observation generated during the discovery phase feeds directly into the analysis stage. The model re-checks the observation against the source code, evaluates runtime usage, and inspects related code across other repositories when necessary to complete the evaluation.
Following this verification pass, the model assigns a specific classification to the finding. If available evidence is insufficient to make a definitive determination, CryptoLabe refrains from guessing, instead assigning classifications such as external dependency, unknown, or more evidence needed.
Sources
- Cloudflare BlogUsing AI to chart a course for our post-quantum migration