Broad source coverage
12 programming languages plus configuration and IaC
CipherMap inventories cryptographic API usage, risky public-key algorithms, weak primitives, dependency signals, and configuration evidence—on your machine, before you plan a post-quantum migration.
v0.6.0 release candidate
Public installation opens when the signed release is promoted. Until then, approved developers can request the history-free source preview and evaluate the Free workflow locally.
Request Preview accessBroad source coverage
12 programming languages plus configuration and IaC
Local by design
Scan without uploading repository source
Evidence you can use
Text, versioned JSON, and SARIF 2.1.0 output
CipherMap combines language-aware source rules with manifest and configuration checks. Every result is a lead for review—not a claim that an algorithm is reachable at runtime or that a system is certified.
Public-key migration
Surface selected source-level RSA, DSA, Diffie-Hellman, ECDSA, and ECDH evidence so reviewers can identify migration candidates and inspect the surrounding implementation.
Cryptographic hygiene
Flag patterns such as MD5, SHA-1, weak randomness, committed private keys, and selected stateful-signature misuse with file-level evidence.
Dependencies and configuration
Review supported manifests, lockfiles, TLS and SSH configuration, IaC, and Dockerfiles alongside language-specific source rules.
Developer workflow
Use versioned JSON or SARIF, diff-aware scanning, severity thresholds, and free CI failure gates without replacing your general SAST or secrets tools.
Tell us whether you need help interpreting findings, producing CBOM or audit evidence, scanning multiple repositories, or planning a migration. Do not send source code or sensitive findings.
No account or sales call is required to use the scanner.
Choose email guidance or request meeting times only if either would help your next decision.
Choose your next step
Tell us what you are trying to decide. We will send relevant guidance or offer a 20-minute technical-fit call.
The Free scanner is the entry point. Paid evidence and enterprise workflows remain separate decisions, with clear boundaries between what is verified, beta, contract-tested, and planned.
Evaluate an organizational inventory pathFree
Point CipherMap at a repository. Source stays in your environment, and --offline disables optional network activity.
Free
Triage rule IDs, file locations, severity, rationale, and supported remediation proposals before making a migration decision.
Tier A
Generate compliance-profile findings, CycloneDX 1.6 CBOM, SPDX, OpenVEX, and attested report artifacts.
Tier B · controlled
Discuss fleet visibility and contract-tested delivery integrations after the local workflow proves useful for your organization.
CipherMap does not prove runtime reachability, inspect live network negotiation, inventory certificates across your estate, or certify post-quantum readiness. Use its source evidence alongside runtime, certificate, infrastructure, ownership, and data-lifetime inventories.
Need to evaluate the boundary first?
Review how rules fire, what files are supported, and what a zero-finding result does—and does not—mean.
Read the methodologyStart with one representative repository. Confirm what CipherMap can see, inspect the evidence, and decide whether broader inventory work is justified.