Cryptographic discovery for the post-quantum era

Evidence-based cryptographic discovery for crypto-agility.

Cipher Discovery inspects authorized public TLS services and supported repository patterns with deterministic evidence. Repository files stay in the browser; retained results contain bounded metadata, not source code.

Deterministic evidence Explicit scan coverage No black-box score
Demo report
Public exposureapi.example.com
Scan complete
24Assets discovered
9Migration candidates
4Need review
RSA-2048Public key / exchange
ECDSA P-256Public key / exchange
ECDHEPublic key / exchange
AES-256Symmetric / hash
SHA-256Symmetric / hash
X.509 certificateHigh confidence

RSA-2048 public key

Evidence
Certificate public key
Source
TLS endpoint
PQC relevance
Review required
Evidence attached to every findingCoverage: public TLS only
The visibility gap

You can't migrate cryptography you can't see.

Modern systems depend on cryptography across source code, dependencies, TLS, certificates, APIs, cloud infrastructure, authentication, signing and key exchange.

Those dependencies are distributed across teams and technology layers. Cipher Discovery is designed to turn fragmented observations into a traceable inventory—not another opaque security score.

Cryptographic
inventory
Source code
Dependencies
TLS
Certificates
Cloud
APIs
Signing
Key exchange
From observation to action

A disciplined path from discovery to migration.

Each stage keeps the evidence and coverage needed to make defensible cryptographic decisions.

01

Discover

Collect deterministic observations from supported discovery sources.

02

Normalize

Turn source-specific observations into consistent cryptographic assets.

03

Assess

Apply versioned rules to identify security and PQC migration relevance.

04

Act

Prioritize evidence-backed findings and build a migration inventory.

Cryptographic asset coverage

What Cipher Discovery is built to discover.

The product combines selected public TLS services, browser-local repository rules and explicit imported declarations while keeping each source and its limits visible.

Algorithms

Identify cryptographic algorithms and the contexts in which they are used.

Public and local sources available

Certificates

Parse public certificates, keys, signatures, validity and presented chains.

Public service TLS available

Protocols

Observe TLS versions, negotiated suites, groups and cryptographic parameters.

Public service TLS available

Libraries

Find supported cryptographic API and dependency declarations locally in an authorized repository.

Local repository rules available

Dependencies

Map declared package and CBOM relationships without inventing runtime evidence.

Local manifest and CBOM sources

Public-key cryptography

Surface RSA, elliptic-curve and other public-key assets for review.

Public and local sources available

TLS configuration

Document public TLS behavior and supported static configuration with exact evidence.

Public and local sources available

PQC migration candidates

Prioritize observations that need a post-quantum migration path.

Available for supported findings
Evidence first

Every finding should explain itself.

A cryptographic finding is useful only when a reviewer can see why it exists. Cipher Discovery keeps the observation, method and uncertainty attached to the result.

  • Where

    The endpoint, file or asset where it was observed.

  • What

    The algorithm, certificate, protocol or dependency identified.

  • How

    The deterministic parser, negotiation or rule that produced it.

  • Confidence

    A level and reason grounded in the available evidence.

  • Migration relevance

    Why it matters and the next action to consider.

Finding evidenceHigh confidence
RSA
RSA-2048 public keyX.509 leaf certificate
Observed at
api.example.com:443
Source
TLS certificate
Detection
Deterministic X.509 parser
Evidence
SubjectPublicKeyInfo
Rule
pqc-public-key-review / v1
PQC migration relevanceReview required

Identify the owner and plan a standards-aligned migration path when supported by the dependent systems.

Post-quantum preparation

Start your post-quantum migration with discovery.

PQC migration begins with understanding where vulnerable public-key cryptography exists, which systems depend on it and what evidence supports each observation.

Cipher Discovery helps build the inventory needed to prioritize migration. It does not claim that an automated scan makes an organization quantum-safe.

Evidence-backed field guides

Move from a public observation to an owned migration plan.

Use the guides to understand the evidence model, turn findings into migration records and exchange observed public cryptography in CycloneDX.

Roadmap

One normalized inventory, more discovery sources over time.

These capabilities describe the direction of the product. They are not represented as available before they ship.

Available

Public Service Discovery

Inspect HTTPS, SMTP STARTTLS, IMAPS, POP3S and LDAPS with fixed service profiles and exact evidence.

Browser-local rules available

Repository Discovery

Scan supported APIs, package declarations and configuration locally; retain metadata only after explicit import.

Available for retained sources

Cryptographic Inventory

Maintain normalized assets, evidence, ownership and source-separated dependency impact.

Import / export / diff available

Living CycloneDX CBOM

Export public observations, import existing CBOMs, preserve provenance and compare source versions.

Available for supported public TLS services

PQC Exposure

Map public-key dependencies to explainable migration relevance.

Available

Migration Planning

Turn retained observations and imported declarations into an explainable ownership-aware action queue and evidence pack.

Available for public X.509

Migration Verification

Compare an expected public certificate profile with a newer external observation.

Available

Continuous Monitoring

Detect cryptographic change and inventory drift over time.

Planned

Cloud Discovery

Collect cryptographic metadata from approved cloud integrations.

Start with what is publicly visible

See the cryptography exposed by your domain.

Run a conservative public TLS scan and inspect the evidence behind every reported property.

Scan a domain
Coverage matters.

Cipher Discovery provides automated cryptographic discovery and analysis. Results depend on scan coverage and available evidence and should not be interpreted as proof that all cryptography within an organization has been identified.