Cryptographic discovery for the post-quantum era

Discover the cryptography hiding across your infrastructure.

Cipher Discovery identifies cryptographic assets, algorithms, certificates and dependencies so security teams can understand their exposure and prepare for post-quantum migration.

Deterministic evidence Explicit scan coverage No black-box score
Demo report
Public exposureapi.example.com
Scan complete
24Assets discovered
9Migration candidates
4Need review
RSA-2048Public key / exchange
ECDSA P-256Public key / exchange
ECDHEPublic key / exchange
AES-256Symmetric / hash
SHA-256Symmetric / hash
X.509 certificateHigh confidence

RSA-2048 public key

Evidence
Certificate public key
Source
TLS endpoint
PQC relevance
Review required
Evidence attached to every findingCoverage: public TLS only
The visibility gap

You can't migrate cryptography you can't see.

Modern systems depend on cryptography across source code, dependencies, TLS, certificates, APIs, cloud infrastructure, authentication, signing and key exchange.

Those dependencies are distributed across teams and technology layers. Cipher Discovery is designed to turn fragmented observations into a traceable inventory—not another opaque security score.

Cryptographic
inventory
Source code
Dependencies
TLS
Certificates
Cloud
APIs
Signing
Key exchange
From observation to action

A disciplined path from discovery to migration.

Each stage keeps the evidence and coverage needed to make defensible cryptographic decisions.

01

Discover

Collect deterministic observations from supported discovery sources.

02

Normalize

Turn source-specific observations into consistent cryptographic assets.

03

Assess

Apply versioned rules to identify security and PQC migration relevance.

04

Act

Prioritize evidence-backed findings and build a migration inventory.

Cryptographic asset coverage

What Cipher Discovery is built to discover.

The product starts with public TLS and expands through modular, evidence-producing discovery sources.

Algorithms

Identify cryptographic algorithms and the contexts in which they are used.

Public TLS available

Certificates

Parse public certificates, keys, signatures, validity and presented chains.

Public TLS available

Protocols

Observe TLS versions, negotiated suites, groups and cryptographic parameters.

Public TLS available

Libraries

Map cryptographic libraries and APIs when source discovery becomes available.

Expanding coverage

Dependencies

Connect transitive software dependencies to the cryptography they introduce.

Expanding coverage

Public-key cryptography

Surface RSA, elliptic-curve and other public-key assets for review.

Expanding coverage

TLS configuration

Document public TLS behavior with exact endpoint evidence and coverage.

Expanding coverage

PQC migration candidates

Prioritize observations that need a post-quantum migration path.

Expanding coverage
Evidence first

Every finding should explain itself.

A cryptographic finding is useful only when a reviewer can see why it exists. Cipher Discovery keeps the observation, method and uncertainty attached to the result.

  • Where

    The endpoint, file or asset where it was observed.

  • What

    The algorithm, certificate, protocol or dependency identified.

  • How

    The deterministic parser, negotiation or rule that produced it.

  • Confidence

    A level and reason grounded in the available evidence.

  • Migration relevance

    Why it matters and the next action to consider.

Finding evidenceHigh confidence
RSA
RSA-2048 public keyX.509 leaf certificate
Observed at
api.example.com:443
Source
TLS certificate
Detection
Deterministic X.509 parser
Evidence
SubjectPublicKeyInfo
Rule
pqc-public-key-review / v1
PQC migration relevanceReview required

Identify the owner and plan a standards-aligned migration path when supported by the dependent systems.

Post-quantum preparation

Start your post-quantum migration with discovery.

PQC migration begins with understanding where vulnerable public-key cryptography exists, which systems depend on it and what evidence supports each observation.

Cipher Discovery helps build the inventory needed to prioritize migration. It does not claim that an automated scan makes an organization quantum-safe.

Roadmap

One normalized inventory, more discovery sources over time.

These capabilities describe the direction of the product. They are not represented as available before they ship.

Early access

Repository Discovery

Find cryptographic APIs, configuration and dependencies in source repositories.

Planned

Cryptographic Inventory

Maintain normalized assets, evidence, ownership and relationships.

Planned

CycloneDX CBOM

Export standards-based cryptographic inventory for downstream workflows.

Planned

PQC Exposure

Map public-key dependencies to explainable migration relevance.

Planned

Migration Planning

Turn findings into owned, prioritized replacement work.

Planned

Continuous Monitoring

Detect cryptographic change and inventory drift over time.

Planned

Cloud Discovery

Collect cryptographic metadata from approved cloud integrations.

Start with what is publicly visible

See the cryptography exposed by your domain.

Run a conservative public TLS scan and inspect the evidence behind every reported property.

Scan a domain
Coverage matters.

Cipher Discovery provides automated cryptographic discovery and analysis. Results depend on scan coverage and available evidence and should not be interpreted as proof that all cryptography within an organization has been identified.