Skip to main content
v0.6.0 developer source preview: request-only, locally built, and Free-capability only. Review availability ➔
Local-first source-code cryptographic inventory

Find the cryptography hidden in your source code—without uploading it

CipherMap is a local CLI for source-layer cryptographic discovery, triage, and evidence. It helps teams understand one important layer of a broader post-quantum inventory.

Invitation-only Free source preview

Approved recipients receive a reviewed, history-free source archive and a checksum-bound build guide after accepting the Preview terms. Build locally—no unsigned native binary or repository history is distributed.

ciphermap — scan session

For developers

Run the Free source preview locally

Build a reviewed, history-free source archive and evaluate Free discovery against a real repository without uploading source.

Review the Preview

For evaluators

Inspect the evidence before a call

See illustrative output, artifact boundaries, methodology, and known limitations without submitting contact information.

Inspect sample evidence

For organizations

Plan a bounded technical assessment

Define the source-inventory question, representative repositories, success criteria, and decision path with the founder.

See the assessment path

Broad Multi-Language Scanning Engine

GoTypeScriptJavaScriptPythonRustC/C++JavaKotlinC#PHPSwiftRubyYAML/IaC

Built for the cryptographic migration

Discover risk and preview supported proposals free, produce readiness evidence with Tier A, and use Tier B integration and fleet workflows — without handing your source code to a third party.

Free Discovery

Detects quantum-vulnerable crypto

Flags RSA, ECDSA, DH, and broken hashes like MD5 in source code. When network enrichment is enabled, it can also query OSV for known-vulnerable dependencies in supported lockfiles and manifests.

Tier A · Evidence

CNSA 2.0 detection profile

Tier A's --target cnsa-2.0 profile adds NSA Commercial National Security Algorithm Suite 2.0 policy findings — SHA-3/SHAKE, SLH-DSA, and XMSS^MT exclusions — on top of the free base ruleset.

Tier A · Evidence

CycloneDX 1.6 CBOM export

Serialize detected cryptographic assets into a machine-readable Cryptographic Bill of Materials with real cryptoProperties. SPDX 2.3 and OpenVEX export too.

Free Discovery

Crypto-agility scorecard

Run scan --agility to score how tightly primitives are coupled: hardcoded algorithm literals and direct calls versus decoupled wrappers, file by file.

Free Discovery

Stateful signature checks

Flags multi-tree XMSS (XMSS^MT) usage and LMS/XMSS signatures used without visible state tracking.

Free Discovery

Weak randomness detection

Flags non-cryptographic PRNGs and static or predictable seeds where keys, nonces, salts, and tokens are generated.

Free preview

Remediation proposal preview (ciphermap fix)

Preview supported Go, Python and Node ESM proposals with fix --dry-run. Production source publication is disabled until the isolated Gate 2 transaction and recovery evidence are promoted.

Tier B · Enforce

CI pull-request review

The --fail-on CI gate is free. Tier B adds PR comments and annotations for GitHub, GitLab, Azure DevOps and Bitbucket Cloud. Live-provider qualification remains pending.

All tiers

Your code stays local

Scanning runs on your machine and never uploads source code. The developer-preview workflow requires --offline and --no-telemetry; optional enrichment and integrations remain separate, explicit paths.

Commercial pilot capability map

What works now—and what remains gated

The CLI functionality below is implemented and test-backed. Commercial activation, signed downloads, native Windows qualification and live-provider evidence remain separate release gates.

FreeImplemented locally

Local discovery

  • Static scanning across all supported languages
  • Text, versioned JSON and SARIF 2.1.0 output
  • CI failure gates, local hooks and CI template preview
  • Read-only TUI/LSP inspection and remediation dry-run
Tier AImplemented · commercial build gate

Audit evidence

  • CNSA 2.0, FIPS 140-3 and NIST SP 800-56B detection profiles
  • CycloneDX 1.6-shaped CBOM, SPDX 2.3 and OpenVEX
  • Executive and technical reports with report-byte attestation
  • Auditor bundles and encrypted air-gap export/import
Tier BControlled beta · commercial build and live qualification pending

Enterprise workflows

  • Contract-tested PR review and Jira/Slack/OTLP delivery
  • Dependency-Track delivery with verified-version boundaries
  • Local single-tenant fleet server and aggregate fleet sync
  • Go, Python and Node ESM proposal engines without source publication
Unavailable in the MVP release: automatic source publication, TUI/LSP source-changing actions, a production multi-tenant fleet control plane, native binary installers, automatic updates, and production Windows support before native lifecycle and accessibility qualification.

Request the v0.6.0 developer preview

Approved users receive a checksum-bound, history-free source archive and build guide while signed native downloads remain gated.