Evidence you can inspect, without invented proof
CipherMap turns supported source detections into reviewable findings and, where the applicable commercial build enables them, audit-oriented artifacts. The examples on this page are synthetic illustrations. They are not CLI captures, customer results, validator-tested downloads, or readiness certifications.
Illustrative output shapes
What a reviewer needs to see
These compact excerpts explain the role of each output without posing as complete, downloadable evidence.
Controlled evaluation
Customer-specific evidence starts with an agreed scope
In a controlled evaluation, the customer runs CipherMap locally against agreed representative repositories. The evaluation can preserve the command, product version, rule identity, input boundary, findings, and reviewer dispositions needed for a technical readout. Commercial evidence formats depend on the authorized build and entitlement; the normal Free source-preview build does not generate Tier A CBOMs, reports, or auditor bundles.
- 01
Agree repositories, languages, exclusions, and success criteria.
- 02
Run locally with the required offline and no-telemetry boundary.
- 03
Review findings with source owners; record confirmed signals and open questions.
- 04
Produce a scoped technical readout with limitations and recommended next steps.
What the evaluation does not establish
- • It is not a compliance certification, legal opinion, or guarantee of post-quantum readiness.
- • A zero-finding result does not prove that a repository or deployed system contains no cryptography.
- • Source findings do not prove runtime reachability, exploitability, or deployed configuration.
- • It does not replace network, certificate, dependency, binary, key-store, HSM, or asset inventory.
Explore the browser-local demonstrations
Each surface states whether it is showing fictional data, an imported findings report, or an imported inventory. Nothing on these pages upgrades an illustration into customer evidence.
Pattern Playground
Try a deliberately small educational rule set in the browser. It is not a repository scan or readiness assessment.
Evidence Visualizer
Inspect a supported CipherMap findings report or an existing CycloneDX 1.6 CBOM locally in your browser.
Evidence Dashboard Demo
Explore explicitly fictional repositories and see how findings-only and inventory views remain distinct.
CLI Reference
Review the documented scan commands, output boundaries, access tiers, and source-preview build workflow.
Have an evidence or methodology question?
Tell us which artifact, environment, or standard you need to evaluate. We will separate what CipherMap can demonstrate from what still requires another inventory or an independent authority.
Ask an evidence question