Cloudflare is building an internal AI tool called CryptoLabe to find and classify every use of cryptography across its codebase, part of a push to reach full post-quantum readiness by 2029. The company says the tool is needed because cryptography is buried in shared libraries, configuration files and protocol defaults, making a simple search insufficient for planning a migration of its scale.
Cloudflare has set a 2029 target deadline for full post-quantum readiness. Many of its products already use post-quantum encryption over TLS 1.3, but the company says it still needs to cover the long tail of TLS connections and upgrade other uses of public-key encryption. Post-quantum authentication is at an earlier stage. Cloudflare describes its stance as maximalist, aiming to future-proof customer traffic against quantum adversaries.
The migration faces three challenges, according to Cloudflare. Code is spread across many repositories; cryptography hides in shared libraries, protocol defaults and configuration files stored in separate repositories; and discovery requires more than pattern matching. Grepping for algorithm names such as RSA or X25519 overcounts by finding unused code and undercounts by missing defaults and indirect uses in dependencies. It also cannot show how cryptography is used, Cloudflare says, noting that a classical ECDSA signature could appear in a JWT, IPsec, TLS or SSH, each with a different migration path.
CryptoLabe scans in two stages. A discovery stage maps the repository and searches source, configuration, manifests, lockfiles, scripts, tests and documentation for key agreement, signatures, asymmetric encryption, PKI, tokens, credentials and hardware security module integrations. Each raw observation then feeds an analysis stage that re-checks the finding against source code, investigates runtime use and dependencies, and can inspect related code in other repositories. The model assigns a classification or, when evidence is insufficient, labels the finding More evidence needed, External dependency or Unknown rather than guessing.
Current classifications include Classical encryption, Classical signature, Classical token, PQ-ready hybrid key exchange and PQ-ready. Cloudflare says the most prevalent post-quantum use in its codebase is X25519MLKEM768 hybrid key exchange in TLS 1.3. It created a special category for RS256 and ES256 JWT tokens, noting that RFC 9964 defines a post-quantum replacement using ML-DSA. The tool generates reports for product managers and engineers.
CryptoLabe is built on Cloudflare’s Developer Platform and runs across two Cloudflare Workers, including a scanner Worker. The company says the tool is highly specialized to its internal repositories, ticketing systems and documentation processes, and is not available to customers. It is still evolving.
Cloudflare acknowledges it does not yet have a ground-truth dataset for reproducibly comparing different versions of the prompts used in CryptoLabe, though it has been iteratively reviewing findings against source code and with engineers. The company says it is sharing its learnings so other organizations can build on its efforts.
