Skip to main content
source-code cryptographic inventory

Build the source-code layer of your cryptographic inventory.

Find where cryptography appears across representative repositories, review the evidence with your team, and decide how source discovery fits into a broader post-quantum migration programme.

Your team runs CipherMap locally. The request is not a purchase, certification, or request to send us repository source.

Local scan · no source uploadReviewable JSON and SARIF20-minute call optional

Choose your next step

Get the three-repository evaluation outline

Choose whether you want the outline by email or available times for a 20-minute technical-fit call.

On-site delivery activates with the signed release. For now, submitting opens a prepared email to our team.
What would help next?
Required
Required
Required

Do not include source code, credentials, or sensitive findings. We use these details only to respond to this request—not to subscribe you to marketing. See our privacy notice. If email does not open, write to sales@ciphermap.io.

A bounded first assessment

Answer the first useful questions before scaling the programme.

Three representative repositories can be enough to test language coverage, evidence quality, workflow fit, and the review effort a larger cryptographic discovery programme may require.

Discover

See where cryptography appears in representative code

Test whether a reviewable source-layer map of cryptographic calls, configuration, dependencies, and key-material signals is useful across three deliberately different repositories.

Prioritize

Separate migration candidates from general hygiene findings

Review quantum-vulnerable public-key evidence independently from weak hashes, entropy issues, committed keys, and policy-profile findings.

Decide

Determine whether broader inventory work is justified

Use the bounded evaluation to assess source coverage, reviewer effort, evidence quality, and the fit of repeatable scanning across more repositories.

Three-repository path

A technical evaluation with a defined stopping point.

The purpose is to reduce uncertainty—not manufacture a sales-qualified result. Each step produces a decision your technical and security stakeholders can challenge.

Your code remains in your environment.

Share only non-sensitive observations needed to discuss coverage, findings, and workflow fit.

  1. 01

    Choose three repositories

    Select a service, a shared library, and a repository with meaningfully different languages or configuration. The goal is representative variation, not a favorable demo.

  2. 02

    Run CipherMap locally

    Your team runs the documented offline workflow. Repository source remains in your environment; do not email code, credentials, or sensitive findings.

  3. 03

    Review evidence together

    Inspect true positives, false-positive questions, unsupported boundaries, skipped files, and what each signal means for the migration decision.

  4. 04

    Make a bounded decision

    Stop, continue with the Free scanner, add Tier A evidence, or discuss controlled Tier B fleet and integration fit. A bounded evaluation does not force a purchase.

The source-code inventory layer

  • Free local discovery, versioned JSON, SARIF, diff scans, and CI failure gates.
  • Tier A compliance profiles, CycloneDX 1.6 CBOM, SPDX, OpenVEX, and attested reports.
  • Controlled Tier B evaluation for beta fleet capabilities and contract-tested delivery integrations.
Compare product tiers

The broader programme layer

A complete cryptographic inventory also needs information CipherMap does not derive from static source: deployed systems, active protocols, certificates and keys, HSMs, data lifetimes, business ownership, vendors, and remediation dependencies.

Treat source discovery as a high-leverage input to that programme—not a replacement for runtime, infrastructure, PKI, asset-management, or governance work.

Review methodology and limits

Bring a real inventory question—not a generic demo request.

We will use four qualification questions to decide whether a bounded source-inventory evaluation is a useful next step.

  • How many repositories are in scope?
  • Do you need recurring CI or fleet-level scanning?
  • What policy, customer, or migration deadline matters?
  • What deployment, privacy, or air-gap boundary must be preserved?
Get the evaluation outline