Lifestyle

Cloudflare Describes CryptoLabe, the Internal AI Tool It Uses to Find Cryptography in Its Code Ahead of a 2029 Post-Quantum Deadline

In a September 29, 2026 blog post, Cloudflare described CryptoLabe, an internal tool that uses AI to find where its code relies on encryption and digital signatures. Cloudflare wants these protections to hold up against future quantum computers by 2029. The post covers how the tool works, what it cannot yet do, and some prompts other organizations can use. All content comes solely from Cloudflare's own account.

About 8 min read

Cloudflare Describes CryptoLabe, the Internal AI Tool It Uses to Find Cryptography in Its Code Ahead of a 2029 Post-Quantum Deadline
Image: Mokaair (Original editorial artwork)

What happened

On September 29, 2026, Cloudflare published a post on its official blog, written by Sharon Goldberg and Tiago Silva. Cloudflare said its goal is to be fully post-quantum ready by 2029. "Post-quantum" cryptography means encryption and digital signatures designed to stay secure even against a quantum computer powerful enough to break today's methods. The company said it has already moved many products to post-quantum encryption, but its use of post-quantum authentication, which proves who or what is on the other end of a connection, is still at an early stage.

To that end, Cloudflare set out three goals. The first is to help product and engineering teams understand how cryptography is used and how it should be upgraded. The second is to provide metrics on migration progress. The third is to spot early the prerequisites that need outside cooperation. The company is developing an internal tool called CryptoLabe to meet these goals. It is named after the mariner's astrolabe, a navigation instrument refined by Portuguese navigators. Cloudflare said the tool is highly specific to its internal systems and will not be offered to customers.

Cloudflare Describes CryptoLabe, the Internal AI Tool It Uses to Find Cryptography in Its Code Ahead of a 2029 Post-Quantum Deadline
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

Why keyword search alone isn't enough

According to Cloudflare, cryptography rarely appears plainly in code. It hides in shared libraries, in protocol defaults, in configuration files far from where it is used, and in code paths that are dead, test-only or on a path to being deprecated. The company noted that simply searching for algorithm names such as "RSA" overcounts, because it finds unused code. It also undercounts, because it misses defaults and indirect use. And it cannot explain what the cryptography is for. For example, the same ECDSA signature may be used in a JWT (a kind of digital access token), IPsec, TLS (the protocol behind secure web connections) or SSH, and each has a different migration path.

Cloudflare said CryptoLabe's "discovery" phase maps a repository, meaning a project's store of code, and produces raw observations. The "analysis" phase then re-checks each observation against the source code. It investigates how the code behaves when it runs and which internal or external parties it depends on. It also looks for conflicting evidence such as configuration overrides and test-only code. When evidence is insufficient, the model labels a finding "More evidence needed", "External dependency" or "Unknown".

Categories currently used by CryptoLabe (source: Cloudflare Blog)
Category (per Cloudflare)Examples coveredStatus notes
Classical encryptionECDHE (e.g. X25519, P-256), RSA key agreement, HPKECloudflare says a quantum computer running Shor's algorithm (a quantum method that breaks these schemes) will break it. It is also exposed to "harvest now, decrypt later" attacks, in which data recorded today is decrypted once such a computer exists.
Classical signatureRSA and ECDSA signatures in certificates or handshakesCloudflare says Shor's algorithm will break it
Classical tokenJWTs using RS256 or ES256RFC 9964 defines a post-quantum alternative using ML-DSA
PQ-ready hybrid key exchangeX25519MLKEM768 in TLS 1.3Cloudflare calls this the most common post-quantum encryption usage in its code
PQ-readyOther post-quantum usage, such as ML-DSAAlready post-quantum

How the tool works and its known limitations

Cloudflare said CryptoLabe is built on its own developer platform. It consists of two Workers, one for scanning and one for the inventory, and stores data in D1. It uses the Agents SDK, Durable Objects and Cloudflare Workflows to run four stages in order: discovery, deep analysis, merging and publishing. To avoid damaging code, each scan saves a snapshot of the repository at one exact version (a specific commit) into R2. It then restores that snapshot into an isolated container, Cloudflare Sandbox, where the model can only read it through read-only tools.

Cloudflare said model requests go through AI Gateway to open-weight models, whose underlying model files are publicly available, hosted on Workers AI. Many scans running at once triggered HTTP 429 rate-limit responses. The company fixed this with a single global Durable Object that paces all requests and retries. The company also acknowledged that it has no ground-truth dataset for repeatably comparing how well different prompts perform. It is also not certain it has found every use of cryptography in its code.

Prerequisites and hard cases

Cloudflare uses "prerequisites" to flag problems a single team cannot solve on its own. For example, RFC 9964 already defines post-quantum JWTs. Even so, teams cannot be asked to upgrade across the board if libraries do not yet support verifying them or token issuers do not yet issue them. The post says CryptoLabe found six findings with post-quantum SAML as a prerequisite; SAML is a protocol for single sign-on. Cloudflare also noted that when it deployed X25519MLKEM768 in 2022, the scheme was still an IETF draft. It was not finalized as RFC 10024 until 2026.

Cloudflare also wrote a separate prompt dedicated to finding "hard cases". One example is a certificate carried in an HTTP header. Post-quantum certificates and signatures are larger, so if a system assumes a certificate has a certain size, switching algorithms could break it. Cloudflare's conclusion is that no single scan can find everything. Every finding still needs to be checked by engineers familiar with the system.

What it means for general readers and organizations

For ordinary users, the post shows that major internet infrastructure providers are already preparing for quantum computers that could break today's public-key cryptography. It also shows AI being used for this kind of massive inventory work. Cloudflare published a selection of its prompts but stressed that they are only a starting point. It said the quality of the results depends on the model, tools, context and engineering review.

For organizations, Cloudflare believes most do not need to, and should not, start by cataloguing all cryptography in every repository right now. It suggests the following way to begin:

  1. Pick the repository of one important system, such as one that handles sensitive or long-lived data, authenticates users or software, or is exposed to the public internet.
  2. Run cryptography discovery on that repository.
  3. Have the team that owns the system validate the results. They should confirm whether each use is needed long-term and whether another safeguard (a compensating control) is already in place.
  4. Separate the items that can be upgraded now from those that are blocked. Record shared prerequisites that need help from libraries, vendors or standards bodies, and deal with the highest-impact items first.

Frequently asked questions

What is CryptoLabe?

According to Cloudflare, CryptoLabe is a tool it built for its own use. It uses AI to find cryptography in code, understand what it is used for and plan how to move it to post-quantum methods.

Can individuals or businesses use CryptoLabe?

No. Cloudflare said CryptoLabe is highly tailored to its internal repositories, ticketing system and documentation workflows, so it will not be offered to customers. However, the company published some of its prompts and explained that they are only a starting point, not a standalone version of CryptoLabe.

Why worry about current encryption?

Cloudflare notes that a quantum computer running Shor's algorithm will break classical public-key encryption such as ECDHE and RSA, and also RSA and ECDSA signatures. Classical encryption also faces "harvest now, decrypt later" attacks, in which data captured today is decrypted later.

Does my organization need to catalogue all its code immediately?

Cloudflare believes most organizations do not. It recommends starting with the most important systems. Run cryptography discovery on them, have the team that owns each system validate the results, then deal with items in order of priority. Record any prerequisites that need outside help along the way.

Can AI scan results be trusted as-is?

Cloudflare itself says it has no ground-truth dataset to measure accuracy and is not sure it has found every use of cryptography. It stresses that no single scan can find every problem. Every finding needs to be checked by engineers familiar with the system.

Have these claims been independently verified?

No. All information in this article comes from Cloudflare's official blog and represents the company's own account.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle