Skip to main content
Free local source-code scan

Find the cryptography hiding in your codebase.

CipherMap inventories cryptographic API usage, risky public-key algorithms, weak primitives, dependency signals, and configuration evidence—on your machine, before you plan a post-quantum migration.

v0.6.0 release candidate

Public installation opens when the signed release is promoted. Until then, approved developers can request the history-free source preview and evaluate the Free workflow locally.

Request Preview access
ciphermap — scan session

Broad source coverage

12 programming languages plus configuration and IaC

Local by design

Scan without uploading repository source

Evidence you can use

Text, versioned JSON, and SARIF 2.1.0 output

Source-layer discovery

Start with evidence your engineering team can verify.

CipherMap combines language-aware source rules with manifest and configuration checks. Every result is a lead for review—not a claim that an algorithm is reachable at runtime or that a system is certified.

Public-key migration

Locate classical cryptography that needs investigation

Surface selected source-level RSA, DSA, Diffie-Hellman, ECDSA, and ECDH evidence so reviewers can identify migration candidates and inspect the surrounding implementation.

Cryptographic hygiene

Find weak primitives and unsafe implementation signals

Flag patterns such as MD5, SHA-1, weak randomness, committed private keys, and selected stateful-signature misuse with file-level evidence.

Dependencies and configuration

Inspect more than direct function calls

Review supported manifests, lockfiles, TLS and SSH configuration, IaC, and Dockerfiles alongside language-specific source rules.

Developer workflow

Turn findings into an enforceable review step

Use versioned JSON or SARIF, diff-aware scanning, severity thresholds, and free CI failure gates without replacing your general SAST or secrets tools.

Optional human help

The Free scanner stays ungated. Ask for help after you see the evidence.

Tell us whether you need help interpreting findings, producing CBOM or audit evidence, scanning multiple repositories, or planning a migration. Do not send source code or sensitive findings.

No account or sales call is required to use the scanner.

Choose email guidance or request meeting times only if either would help your next decision.

Choose your next step

Get setup help and sample results

Tell us what you are trying to decide. We will send relevant guidance or offer a 20-minute technical-fit call.

On-site delivery activates with the signed release. For now, submitting opens a prepared email to our team.
What would help next?
Required
Required
Optional

Do not include source code, credentials, or sensitive findings. We use these details only to respond to this request—not to subscribe you to marketing. See our privacy notice. If email does not open, write to sales@ciphermap.io.

One useful path forward

Discover first. Add governance only when the evidence earns it.

The Free scanner is the entry point. Paid evidence and enterprise workflows remain separate decisions, with clear boundaries between what is verified, beta, contract-tested, and planned.

Evaluate an organizational inventory path
  1. 01

    Free

    Scan locally

    Point CipherMap at a repository. Source stays in your environment, and --offline disables optional network activity.

  2. 02

    Free

    Review evidence

    Triage rule IDs, file locations, severity, rationale, and supported remediation proposals before making a migration decision.

  3. 03

    Tier A

    Package audit evidence

    Generate compliance-profile findings, CycloneDX 1.6 CBOM, SPDX, OpenVEX, and attested report artifacts.

  4. 04

    Tier B · controlled

    Evaluate repeatable governance

    Discuss fleet visibility and contract-tested delivery integrations after the local workflow proves useful for your organization.

Honest scope boundary

A code scan is one layer of readiness—not the verdict.

CipherMap does not prove runtime reachability, inspect live network negotiation, inventory certificates across your estate, or certify post-quantum readiness. Use its source evidence alongside runtime, certificate, infrastructure, ownership, and data-lifetime inventories.

Need to evaluate the boundary first?

Review how rules fire, what files are supported, and what a zero-finding result does—and does not—mean.

Read the methodology

Make your first migration question concrete.

Start with one representative repository. Confirm what CipherMap can see, inspect the evidence, and decide whether broader inventory work is justified.