Cryptographic inventoryand post-quantum readiness

Find every algorithm, certificate and library you depend on, export a versioned CBOM, and measure how far you are from ML-KEM and ML-DSA. Evidence, ownership, policy gates and pull-request drift control, without uploading source code.

Works across the stack you already run

  • Java
  • Python
  • Go
  • JavaScript
  • TypeScript
  • Terraform
  • Kubernetes
  • Nginx
  • Envoy
  • OpenSSL
  • GitHub
  • GitLab

A design preview of one workspace for evidence, ownership, migration, and regression control.

Northstar Checkout

Inventory

Inventory

12 assets

Migration

7 active

CI drift

1 new

Evidence

24 exports
AssetConfidenceOwnerRisk
RSA-2048 / RS256confirmed@identity-platform92
ECDSA P-256probable@payments81
TLS 1.0confirmed@edge-runtime97
AES-256-GCMconfirmed@data-platform24

Local-first scanner

Look at code without sending code.

The scanner normalizes fingerprints, redacted evidence, and open-standard output on your machine. Upload only the records you choose.

Source and configuration Secrets excluded CycloneDX and SARIF Offline-capable CLI
$ cipherdrift scan . --output cbom.json

 indexed 18,402 files
 parsed source & configuration
 resolved dependency evidence
 inspected authorized TLS targets

12 cryptographic assets
  5 quantum-vulnerable
  2 deprecated
  1 unknown

 wrote CycloneDX 1.6 → cbom.json
 wrote SARIF 2.1.0 → results.sarif

Evidence stays portable

Open formats in. Open formats out.

Cryptographic inventory should remain inspectable and usable outside the platform. Export the evidence, replay a policy locally, or retain a signed scan ledger.

Read the security model
CycloneDX 1.6

Versioned CBOM

SARIF 2.1.0

Code scanning results

JSON / CSV

Portable analysis

Signed ledger

Attributable history

Find cryptographic debt, keep it from returning

Qubrisk is in development. There is no signup yet, so tell us what your estate looks like and we will show you what the inventory records.