CipherFlag EE discovers cryptography across every endpoint, cloud, repo, and network segment, scores it against 49 rules, ranks migration by data lifetime and exposure, and proves compliance — built for the post-quantum transition.
One program for cryptographic preparedness — from finding every asset to proving you are ready for the post-quantum transition.
A single, unified inventory of every cryptographic asset across endpoint, cloud, source, container, network, directory, CNAPP, and data-sensitivity sources — with host identity resolution and application tagging, so each asset is mapped to the host and application that owns it.
Every asset is graded A+ to F against 49 rules across five asset types plus CNAPP enrichment — expiration, key strength, signature algorithms, chain trust, protocol versions, library CVEs, SSH hygiene, crypto-agility, and linked Prisma Cloud exposure and IaC findings. Each finding carries severity, category, point deduction, and remediation guidance. Scoring is deterministic; CNAPP deductions fire only when a CNAPP signal is linked.
Map findings to the controls auditors ask about, export a complete cryptographic bill of materials, and forward a hash-chained authorization log to the SIEM you already run.
CBOM export — generate a CycloneDX v1.6 cryptographic bill of materials for any scope, with per-component rule-engine provenance, ready to hand to auditors or feed downstream tooling.
Hash-chained audit + SIEM — every authorization decision, admin action, login, MFA event and governance write is a durable, queryable, hash-chained row. Forward it to Splunk HEC, syslog (CEF or RFC5424), or generic HTTP from an in-app wizard; worklist findings push to owner Slack channels.
Turn findings into action. CipherFlag EE ranks what to migrate first by data lifetime (Microsoft Purview HNDL) and internet exposure (Prisma Cloud CNAPP), not just by certificate expiry, then sequences the work through blast radius, Chain Posture, and post-quantum readiness as CNSA 2.0 deadlines approach.
Six capabilities that landed since the last public page: sensitivity-ranked migration, CNAPP exposure, Chain Posture, broader at-rest detection, a hash-chained SIEM audit log, and MCP access to the Mosca-gap report.
Rank post-quantum migration by how long the data stays sensitive, not by which certificate expires next. Microsoft Purview classifications and labels map to retention horizons; the HNDL lens flags no-signal coverage gaps and label-vs-classification mismatches. Suggestions never auto-apply.
Enrich crypto posture with CSPM exposure, CIEM effective permissions, secrets on disk, attack-path hosts, and IaC findings. Internet-exposed PQC assets surface as their own cadence card. Absence of a CNAPP signal is never treated as evidence of safety.
A scale-invariant conserved flow over trust origin, chain depth, and leaf grade — rooted, partial, self-signed, or unlinked. Replaces the old chain-flow sankey so an estate of thousands of CAs still reads as one picture, with every count clicking through to the list that proves it.
Container and source scans now catch JCEKS keystores, bare-DER private keys, standalone PGP armor, hardcoded vendor credentials and JWTs, and weak algorithms sitting in plain config files — fingerprinting matches, never storing the secret.
Authorization decisions, admin actions, logins, MFA events and governance writes land as a durable, hash-chained log. Forward it to Splunk HEC, syslog, or HTTP from an in-app wizard; push worklist findings to owner Slack channels. Queryable, admin-gated, never a rotating file you cannot prove.
Agents can now read the same narrative a human opens: report_catalog and report_view expose the HNDL Mosca-gap ranking — data lifetime vs migration time vs CRQC runway, worst-first — plus sensitivity_coverage so an empty result is never mistaken for safety.
CipherFlag EE ships a native Model Context Protocol server — cipherflag-mcp — exposing 52 tools over your live inventory. Point Claude, or any MCP-capable agent, at your own deployment and ask questions in plain language. The agent queries your data directly; nothing is uploaded anywhere to make that work.
Certificates, SSH keys, protocol endpoints, and crypto libraries — filtered by algorithm, issuer, owner, environment, posture, grade, or expiry, with faceted drill-down.
Readiness rollups per framework, ranked remediation tasks, dispositions and expiring waivers, and the ordered migration-wave plan with cross-wave consequences.
Downstream impact if an asset is compromised, shared-asset host pairs, shadow and rogue CAs, and orphaned assets with no owner sighting.
Per-framework pass/partial/fail rollups and per-asset violations across NIST 800-131A, PCI DSS 4.0, FIPS 140-3, CNSA 2.0, and NIS2 — computed live.
Which asset classes your sources can structurally see, which connectors are stale or failing, dev-vs-prod config drift, and whether a renewal actually propagated.
Resolve the ownership chain for any asset, stamp owners and environments, and open remediation tickets in ServiceNow or Jira.
Every registered report — HNDL exposure with Mosca-gap ranking, expiry, burndown, inventory, domain, CA, compliance overview — with the same filters the web view uses.
Per-signal Purview coverage (how many assets carry each label, how many are host-linked, which are mapped to a horizon) and Prisma-labelled internet-exposed PQC assets.
“What's left for CNSA 2.0, who owns it, and what breaks if we rotate the top item first?”
→ pqc_worklist · owner_resolve · blast_radius · report_view · exposed_pqc_assets · create_tickets
Cryptographic inventory is the most sensitive asset list a security team holds — it is a literal map of what breaks if compromised. So CipherFlag treats AI as an option you switch on, not an architecture you inherit.
Every grade, finding, compliance verdict, and CBOM is produced deterministically. The 49-rule scoring engine, the compliance evaluator, and CBOM export are rule-based and reproducible. No model is involved in any of them, and most deployments run with AI switched off entirely.
AI enrichment ships disabled. Turning it on is a deliberate, licensed configuration change — never a default, never implicit.
Point enrichment at a local open-weight model — Ollama, vLLM, llama.cpp, LM Studio, or any OpenAI-compatible endpoint — and no cryptographic data ever leaves your infrastructure. Or use a commercial API under your own key. Cyber Flag operates no inference service and never proxies your data.
Enrichment applies only to source-repository and container-image finding triage. It never produces a grade, a compliance verdict, or CBOM contents.
A byte-range redactor sits on the only code path between detection and prompt assembly. Key material is replaced with [REDACTED-<TYPE>-<hash>] markers before any bytes reach a model — enforced by test, not by convention.
Every response passes exploit-content scanning, a no-leak check that original key material has not been echoed back, and strict-JSON schema validation before it can become a finding.
Per-scan, per-day, and per-month spend ceilings, with a full token and cost ledger for every call. No surprise bills, and a complete audit trail of what was asked.
Start free with the open-source Community Edition. Step up to Enterprise for full-fleet discovery, multi-asset scoring, and compliance.
| Capability | CE — Free (Apache 2.0) | EE — Enterprise |
|---|---|---|
| Passive TLS discovery (Zeek) | ✓ | ✓ |
| Asset types | Certificates | Certs · keys · SSH · libraries · protocols · configs |
| Health scoring | 24 certificate rules | 49 rules across 5 asset types + CNAPP |
| PKI Explorer | Force-directed graph | + 3D constellation, blast-radius, Chain Posture |
| Endpoint discovery | — | osquery/FleetDM, Velociraptor, Defender, CrowdStrike Falcon, Falcon for IT, SentinelOne, Tanium, Absolute, Forescout, Rapid7 |
| Cloud / KMS | — | AWS, Azure, Entra, Azure Key Vault |
| Source / Git discovery | — | ✓ |
| Container image scanning | — | OCI registry + binary crypto, JCEKS, DER, PGP, secrets-in-config |
| Network | Zeek passive TLS | Zeek, Forescout eyeSight, Splunk (PAN TLS), active TLS scan, Certificate Transparency |
| Directory / PKI / DDI | — | Netwrix AD CS, Defender for Identity, Infoblox, BlueCat, Saviynt |
| CNAPP / data sensitivity | — | Prisma Cloud, Microsoft Purview |
| Host mapping | — | ✓ |
| Application tagging | — | ✓ |
| Venafi export | TPP + Cloud push | + TPP policy-folder management, Thales CipherTrust |
| Compliance frameworks | — | NIST 800-131A · PCI DSS 4.0 · FIPS 140-3 · CNSA 2.0 · NIS2 |
| CBOM export (CycloneDX v1.6) | — | ✓ |
| PQC program management | — | Dispositions, waivers, migration waves, Purview HNDL ranking |
| MCP server (AI agent interface) | — | 52 tools · 43 read, 9 gated writes |
| Optional AI enrichment | — | Off by default · local or BYO-key model |
| Audit / SIEM | — | Hash-chained log · Splunk / syslog / HTTP · Slack |
| Ticketing (ServiceNow, Jira) | — | ✓ |
| Auth | JWT + RBAC | + SSO / SAML, OIDC, PIV/CAC |
| Support | Community | Commercial SLA |
| Price | Free | Contact for pricing |
CipherFlag CE is the open-source core: passive TLS discovery via Zeek, 24-rule certificate health scoring, the interactive PKI Explorer, and Venafi export — all from a single docker-compose up.
$ curl -fsSL https://raw.githubusercontent.com/net4n6-dev/cipherflag/main/scripts/install.sh | sh
Bring your toughest crypto-visibility question. We'll show you what we find.