Back to News
RSS feedblog.cloudflare.com

Cloudflare Uses AI to Map Its Post-Quantum Cryptography Migration

Summary

Cloudflare is working toward full post-quantum readiness by 2029 and is using AI to understand how cryptography is deployed across its products and codebase. Its internal tool, CryptoLabe, maps repositories and searches source code, configuration, manifests, scripts, tests, documentation, and dependencies for cryptographic operations. A second analysis stage rechecks each observation, follows runtime and cross-repository evidence, identifies the system’s role and dependencies, and classifies findings as classical encryption, classical signatures, classical tokens, post-quantum-ready use, or cases requiring more evidence. CryptoLabe then produces reports for product managers and engineers, while metrics track classical and post-quantum usage. The system runs on Cloudflare’s developer platform: Workers handle scanning and inventory, D1 stores results, Durable Objects coordinate repository scans, Workflows provide persistence and retries, R2 stores exact repository snapshots, and Sandboxes give models read-only access to isolated code. AI Gateway routes requests to cost-effective open-weight models on Workers AI, while a global Durable Object paces requests and coordinates backoff after rate limits. Cloudflare also runs a separate broad scan for hard cases, such as custom protocols, size-constrained certificate fields, hardware-bound cryptography, and dependencies without post-quantum support. The company says its prompts are still being refined, lacks a ground-truth dataset for reproducible comparison, and does not claim complete coverage. CryptoLabe is an internal tool and will not be released to customers. Cloudflare recommends that other organizations begin with critical systems, validate findings with owning engineers, and prioritize blockers and high-impact migrations instead of attempting an exhaustive inventory immediately.