Cloudflare said on Monday it is developing an internal AI-powered tool called CryptoLabe to discover and map cryptography across its codebase as it works toward a 2029 target for full post-quantum readiness.
The company said it has already transitioned many products to post-quantum encryption over TLS 1.3 but still needs to cover remaining TLS connections, other uses of public-key encryption, and post-quantum authentication, where it said deployment is at an early stage.
Cloudflare named the tool after the mariner’s astrolabe, saying it helps the company discover cryptography in its code, understand how it is used and chart a path to migration. The tool is specialized to Cloudflare’s internal systems and will not be made available to customers, though the company said it is sharing its learnings so other organizations can build on them.
Cloudflare set out three goals for the migration: helping product and engineering teams understand how cryptography is used and how it should be upgraded, providing progress metrics such as per-repository counts of classical and post-quantum cryptography, and surfacing prerequisites early, such as protocols, standards or software libraries that do not yet have post-quantum support.
Most Cloudflare products live in a single centralized source control platform, but the company said cryptography is hard to find because it is hidden in shared libraries, protocol defaults such as a TLS 1.3 listener negotiating classical X25519 key exchange instead of post-quantum X25519MLKEM768, configuration files stored away from the code, and dead or test-only code paths.
Simply searching for algorithm names overcounts, because it finds cryptography in unused code, and undercounts, because it misses defaults and indirect uses, the company said. It also cannot show how the cryptography is used, which determines the migration path.
CryptoLabe scans repositories in two stages, the company said. A discovery stage maps the repository and searches source, configuration, manifests, lockfiles, scripts, tests and documentation for uses of cryptography, producing raw observations. An analysis stage then re-checks each observation against the source code, investigates how it is used at runtime, can inspect related code in other repositories, and reviews its own conclusions for missing or conflicting evidence.
The model then assigns a classification to each finding, and where evidence is insufficient it assigns “More evidence needed”, “External dependency” or “Unknown” rather than guessing, Cloudflare said. It generates reports for two audiences: product managers and engineers who need detail to carry out the migration.
Cloudflare said it has been reviewing findings against source code and with engineers but does not yet have a ground-truth dataset for reproducibly comparing different versions of the tool’s prompts.
The company built CryptoLabe on its own Developer Platform, running it across two Cloudflare Workers - one scanner and one inventory service backed by a D1 database - with a persistent coordinator per repository built on Agents SDK Durable Objects and Cloudflare Workflows handling retries and recovery. The company said the tool is still evolving as development continues toward the 2029 deadline.

