1. Observe deterministically
Supported scanners use bounded protocol negotiation, certificate parsing, dependency analysis, configuration parsing or static rules. AI is not the source of an authoritative cryptographic asset.
2. Keep repository source local
The repository scanner reads supported files in the browser, excludes hidden, generated, dependency-vendor, binary and secret-like paths, and applies strict file, byte and finding limits. Only a reviewed manifest containing allowlisted rule metadata, relative location, file digest, coverage counters and digests of fully inspected paths may be imported; source content and snippets are not transmitted. Path digests can reveal predictable names.
3. Preserve evidence
Each finding keeps its source, location, timestamp, detection method, confidence reason and relevant metadata. Repository findings remain inferred because static source declarations do not prove build, deployment or runtime use.
4. Normalize assets
Source-specific observations map to one cryptographic asset model. Identical certificates are reconciled by fingerprint while separate endpoint and repository observations remain visible.
5. Compare versioned observations
Repeated scans are matched through deterministic semantic slots and canonical property digests. NEW, CHANGED, REGRESSION and RESOLVED events retain both sides of the comparison. A repository finding absent from a newer manifest is marked no longer reported only when its file was declared fully inspected; otherwise it is counted as not compared. Client-side coverage declarations cannot be independently verified by the server.
6. Prioritize operationally
The private migration queue combines retained review-required evidence, current manual ownership and lifecycle assertions, and current-revision verification results through a versioned precedence policy. Every state explains its inputs and next action; no readiness score is calculated.
7. Verify migration externally
Planned, configured and deployed are manual implementation stages—not proof of completion. For a public X.509 certificate, Cipher Discovery waits for a strictly newer scan and compares the expected profile with the observed certificate in the same hostname, port, presented role and chain position. Every predicate, both evidence sets, coverage and method version remain visible. Missing or ambiguous evidence is inconclusive, never verified.
8. Assess with versioned rules
Migration relevance uses reviewed standards data and rule versions. Results explain what was found, why it matters and the next action without an unexplained readiness score.
9. Report coverage honestly
Reports distinguish scanned, discovered, inferred, unknown and not-scanned scope. Public exposure or a selected source directory is never represented as a complete organizational inventory, and resolved means only that an asset was not observed in a newer comparable bounded source.