Discover
See where cryptography appears in representative code
Test whether a reviewable source-layer map of cryptographic calls, configuration, dependencies, and key-material signals is useful across three deliberately different repositories.
Find where cryptography appears across representative repositories, review the evidence with your team, and decide how source discovery fits into a broader post-quantum migration programme.
Your team runs CipherMap locally. The request is not a purchase, certification, or request to send us repository source.
Choose your next step
Choose whether you want the outline by email or available times for a 20-minute technical-fit call.
Three representative repositories can be enough to test language coverage, evidence quality, workflow fit, and the review effort a larger cryptographic discovery programme may require.
Discover
Test whether a reviewable source-layer map of cryptographic calls, configuration, dependencies, and key-material signals is useful across three deliberately different repositories.
Prioritize
Review quantum-vulnerable public-key evidence independently from weak hashes, entropy issues, committed keys, and policy-profile findings.
Decide
Use the bounded evaluation to assess source coverage, reviewer effort, evidence quality, and the fit of repeatable scanning across more repositories.
The purpose is to reduce uncertainty—not manufacture a sales-qualified result. Each step produces a decision your technical and security stakeholders can challenge.
Your code remains in your environment.
Share only non-sensitive observations needed to discuss coverage, findings, and workflow fit.
Select a service, a shared library, and a repository with meaningfully different languages or configuration. The goal is representative variation, not a favorable demo.
Your team runs the documented offline workflow. Repository source remains in your environment; do not email code, credentials, or sensitive findings.
Inspect true positives, false-positive questions, unsupported boundaries, skipped files, and what each signal means for the migration decision.
Stop, continue with the Free scanner, add Tier A evidence, or discuss controlled Tier B fleet and integration fit. A bounded evaluation does not force a purchase.
A complete cryptographic inventory also needs information CipherMap does not derive from static source: deployed systems, active protocols, certificates and keys, HSMs, data lifetimes, business ownership, vendors, and remediation dependencies.
Treat source discovery as a high-leverage input to that programme—not a replacement for runtime, infrastructure, PKI, asset-management, or governance work.
Review methodology and limitsWe will use four qualification questions to decide whether a bounded source-inventory evaluation is a useful next step.