Find cryptography onceKeep it from drifting

Build a versioned cryptographic inventory. Add evidence, ownership, migration dependencies, policy gates, and pull-request drift control—without uploading source code.

Works across the stack you already run

  • Java
  • Python
  • Go
  • JavaScript
  • TypeScript
  • Terraform
  • Kubernetes
  • Nginx
  • Envoy
  • OpenSSL
  • GitHub
  • GitLab

One workspace for evidence, ownership, migration, and regression control.

Northstar Checkout

Inventory

Inventory

12 assets

Migration

7 active

CI drift

1 new

Evidence

24 exports
AssetConfidenceOwnerRisk
RSA-2048 / RS256confirmed@identity-platform92
ECDSA P-256probable@payments81
TLS 1.0confirmed@edge-runtime97
AES-256-GCMconfirmed@data-platform24

Local-first scanner

Look at code without sending code.

The scanner normalizes fingerprints, redacted evidence, and open-standard output on your machine. Upload only the records you choose.

Source and configuration Secrets excluded CycloneDX and SARIF Offline-capable CLI
$ cipherdrift scan . --output cbom.json

 indexed 18,402 files
 parsed source & configuration
 resolved dependency evidence
 inspected authorized TLS targets

12 cryptographic assets
  5 quantum-vulnerable
  2 deprecated
  1 unknown

 wrote CycloneDX 1.6 → cbom.json
 wrote SARIF 2.1.0 → results.sarif

Evidence stays portable

Open formats in. Open formats out.

Cryptographic inventory should remain inspectable and usable outside the platform. Export the evidence, replay a policy locally, or retain a signed scan ledger.

Read the security model
CycloneDX 1.6

Versioned CBOM

SARIF 2.1.0

Code scanning results

JSON / CSV

Portable analysis

Signed ledger

Attributable history

Find cryptographic debt, keep it from returning