Skip to main content
discovery → evidence → governance

Find cryptographic risk locally. Build the case for what changes next.

CipherMap starts with inspectable repository findings, then adds separately controlled evidence and workflow layers as teams move from discovery toward a governed migration program.

  1. Stage 01

    Discover

    Free

    Scan the repository where it already lives

    Run the CLI against a local path. CipherMap identifies supported cryptographic usage and emits findings without requiring a hosted source upload.

    Terminal findings
    Versioned JSON
    SARIF 2.1.0
    CI exit-code gates
  2. Stage 02

    Evidence

    Tier A · future commercial path

    Turn findings into reviewable readiness evidence

    Tier A would add detection profiles and audit-oriented artifacts after release promotion. It is not enabled for paid evaluation in the current Preview, and it does not turn a scan into a certification.

    CNSA 2.0 and other detection profiles
    CBOM, SPDX and OpenVEX
    Executive and technical reports
    Auditor bundles
  3. Stage 03

    Govern

    Tier B · future controlled beta

    Connect approved evidence to team workflows

    Tier B includes Tier A and adds provider delivery and fleet operations. These paths require a commercial build, configuration, and provider-specific qualification.

    PR review workflows
    Jira, Slack and OTLP delivery
    Dependency-Track delivery
    Local fleet operations

Maturity boundary

One product direction, three different access states

The tiers describe capability boundaries. They do not imply that every capability is generally available or production-qualified today.

Free developer source preview

Available by invitation

Approved users build a reviewed, history-free archive locally. The normal build enables local discovery, CI gates, read-only TUI/LSP inspection, and supported remediation proposal previews.

Standalone Auditor · Tier A

Implemented behind a commercial-build gate

Adds readiness profiles and evidence artifacts. Paid licences are intentionally disabled in the normal Free source build and are unavailable in the current Preview.

DevSecOps Enterprise · Tier B

Future controlled beta

Adds integrations and fleet workflows. Live-provider qualification, production source publication, and native Windows lifecycle evidence remain pending.

Evaluate the workflow against a real need

Developers can request the Free Preview. Teams considering evidence or integration workflows can start with a technical-fit conversation—without pretending that a pricing-card click replaces evaluation.