Skip to main content
Inspect the boundary before the claim

Evidence you can inspect, without invented proof

CipherMap turns supported source detections into reviewable findings and, where the applicable commercial build enables them, audit-oriented artifacts. The examples on this page are synthetic illustrations. They are not CLI captures, customer results, validator-tested downloads, or readiness certifications.

Illustrative output shapes

What a reviewer needs to see

These compact excerpts explain the role of each output without posing as complete, downloadable evidence.

Source finding
A source-layer signal links a rule identity to an observed location. A reviewer still has to confirm purpose, context, and migration priority.
Free scan output
SYNTHETIC ILLUSTRATION — NOT SCAN EVIDENCE
rule       PQC-GO-AST-002
location   example/auth/keys.go:7
signal     crypto/rsa import
review     confirm purpose and migration boundary
CI result
Structured findings can enter a code-scanning workflow while the local fail gate remains a separate policy decision.
Free SARIF 2.1.0 output
SYNTHETIC ILLUSTRATION — NOT A SARIF FILE
format     SARIF 2.1.0
ruleId     PQC-GO-AST-002
uri        example/auth/keys.go
verdict    finding emitted; CI policy evaluates severity
Cryptographic inventory shape
A commercial build can serialize supported detections into the current CycloneDX 1.6-shaped CBOM boundary. Unknown fields are omitted rather than inferred.
Tier A controlled build
SYNTHETIC ILLUSTRATION — NOT A CBOM FILE
format       CycloneDX
specVersion  1.6
asset type   cryptographic-asset
algorithm    RSA
unknowns     omitted, not fabricated

Controlled evaluation

Customer-specific evidence starts with an agreed scope

In a controlled evaluation, the customer runs CipherMap locally against agreed representative repositories. The evaluation can preserve the command, product version, rule identity, input boundary, findings, and reviewer dispositions needed for a technical readout. Commercial evidence formats depend on the authorized build and entitlement; the normal Free source-preview build does not generate Tier A CBOMs, reports, or auditor bundles.

  1. 01

    Agree repositories, languages, exclusions, and success criteria.

  2. 02

    Run locally with the required offline and no-telemetry boundary.

  3. 03

    Review findings with source owners; record confirmed signals and open questions.

  4. 04

    Produce a scoped technical readout with limitations and recommended next steps.

What the evaluation does not establish

  • • It is not a compliance certification, legal opinion, or guarantee of post-quantum readiness.
  • • A zero-finding result does not prove that a repository or deployed system contains no cryptography.
  • • Source findings do not prove runtime reachability, exploitability, or deployed configuration.
  • • It does not replace network, certificate, dependency, binary, key-store, HSM, or asset inventory.

Explore the browser-local demonstrations

Each surface states whether it is showing fictional data, an imported findings report, or an imported inventory. Nothing on these pages upgrades an illustration into customer evidence.

Have an evidence or methodology question?

Tell us which artifact, environment, or standard you need to evaluate. We will separate what CipherMap can demonstrate from what still requires another inventory or an independent authority.

Ask an evidence question