AI Briefing
Sign in

Cloudflare Uses Internal AI Tool CryptoLabe to Chart Post-Quantum Migration Path

·2026.09.29 22:00

Key point

Cloudflare developed CryptoLabe, an internal AI tool built on its Developer Platform, to scan codebases and chart a course for its 2029 post-quantum readiness deadline.

Details

Cloudflare is racing toward a 2029 target deadline for full post-quantum (PQ) readiness, adopting a maximalist "PQ everything" stance to future-proof customer traffic. To manage the scale of this migration across its centralized codebase, the company developed CryptoLabe, an internal AI tool that discovers cryptography usage, provides progress metrics, and surfaces prerequisites.

How CryptoLabe Works

CryptoLabe operates in two stages to overcome the limitations of simple pattern matching, which often overcounts unused code or misses indirect dependencies:

  • Discovery Stage: Maps repositories and searches source, configuration, and manifests for raw observations of cryptographic operations.
  • Analysis Stage: Re-checks observations against source code, investigates runtime usage, and assigns classifications such as Classical encryption, Classical signature, PQ-ready hybrid key exchange, or More evidence needed.

The tool generates reports for both product managers and engineers, detailing migration paths for specific protocols like TLS, JWTs, and IPsec.

Architecture and Scaling

Built on Cloudflare's Developer Platform, CryptoLabe uses Workers, Durable Objects, and Workflows to orchestrate scans. It isolates code analysis by downloading repository snapshots to R2 and running them in short-lived Cloudflare Sandboxes. To handle capacity limits, a global Durable Object paces model requests through AI Gateway, ensuring concurrent scans share available capacity rather than triggering rate limits.

Identifying Hard Cases

Beyond standard scans, CryptoLabe identifies "hard cases" where ecosystem support is lacking, such as custom protocols or size-constrained fields. For example, it flagged certificates carried in HTTP headers, where larger PQ signatures could break systems assuming fixed sizes. The tool also groups findings by shared prerequisites, such as the need for library support for post-quantum JWTs (RFC 9964).

Guidance for Other Organizations

Cloudflare advises that most organizations do not need an exhaustive cryptographic inventory immediately. Instead, they should prioritize systems handling sensitive data or exposed to the public internet. Cloudflare notes that its own platform already provides post-quantum encryption for traffic via Cloudflare One and its network, offering a compensating control while organizations plan their internal migrations.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.