Cryptographic Preparedness

Every key, certificate, and cipher — in your sights

CipherFlag EE discovers cryptography across every endpoint, cloud, repo, and network segment, scores it against 47 rules, and proves compliance — built for the post-quantum transition.

Built to evidence NIST 800-131A PCI DSS 4.0 FIPS 140-3 CNSA 2.0 EU NIS2
The CipherFlag EE Lifecycle
Discover. Score. Comply. Remediate.

One program for cryptographic preparedness — from finding every asset to proving you are ready for the post-quantum transition.

01

Discover

A single, unified inventory of every cryptographic asset across endpoint, cloud, source, network, and directory — with host identity resolution and application tagging, so each asset is mapped to the host and application that owns it.

Endpoint
osquery / FleetDM Available Velociraptor Available Microsoft Defender Available SentinelOne Available Tanium Available Absolute Available Forescout Available
Cloud
AWS Available Azure Available
Source & CI
Git Available
Network
Zeek passive TLS Available Forescout eyeSight Available
Directory / PKI
Netwrix (AD CS) Available Defender for AD Available
operator
key
02

Score

Every asset is graded A+ to F against 47 rules across five asset types — expiration, key strength, signature algorithms, chain trust, protocol versions, library CVEs, SSH hygiene, and crypto-agility. Each finding carries severity, category, point deduction, and remediation guidance.

A+ 95–100 A 90–94 B 80–89 C 70–79 D 60–69 F <60
Certificates · 24 rules SSH · 8 rules Libraries · 5 rules Protocols · 6 rules Configs · 4 rules
03

Comply

Map findings to the controls auditors ask about, and export a complete cryptographic bill of materials.

NIST 800-131A PCI DSS 4.0 FIPS 140-3 CNSA 2.0 EU NIS2

CBOM export — generate a CycloneDX v1.6 cryptographic bill of materials for any scope, with per-component rule-engine provenance, ready to hand to auditors or feed downstream tooling.

04

Remediate

Turn findings into action. CipherFlag EE prioritizes by blast radius and exposure, tracks crypto-agility across your estate, and surfaces a post-quantum readiness view so you know exactly what to migrate first as CNSA 2.0 deadlines approach.

PQC readiness scoring Blast-radius prioritization Crypto-agility tracking Remediation guidance
See It In Action
Inside the platform
CipherFlag EE PKI Constellation
CipherFlag EE crypto posture dashboard
CipherFlag EE compliance report
CipherFlag EE applications view
Your crypto estate, addressable by AI agents

CipherFlag EE ships a native Model Context Protocol servercipherflag-mcp — exposing 45 tools over your live inventory. Point Claude, or any MCP-capable agent, at your own deployment and ask questions in plain language. The agent queries your data directly; nothing is uploaded anywhere to make that work.

Inventory & Search

Certificates, SSH keys, protocol endpoints, and crypto libraries — filtered by algorithm, issuer, owner, environment, posture, grade, or expiry, with faceted drill-down.

PQC Program

Readiness rollups per framework, ranked remediation tasks, dispositions and expiring waivers, and the ordered migration-wave plan with cross-wave consequences.

Risk & Blast Radius

Downstream impact if an asset is compromised, shared-asset host pairs, shadow and rogue CAs, and orphaned assets with no owner sighting.

Compliance

Per-framework pass/partial/fail rollups and per-asset violations across NIST 800-131A, PCI DSS 4.0, FIPS 140-3, CNSA 2.0, and NIS2 — computed live.

Coverage & Drift

Which asset classes your sources can structurally see, which connectors are stale or failing, dev-vs-prod config drift, and whether a renewal actually propagated.

Ownership & Action

Resolve the ownership chain for any asset, stamp owners and environments, and open remediation tickets in ServiceNow or Jira.

“What's left for CNSA 2.0, who owns it, and what breaks if we rotate the top item first?”

→ pqc_worklist · owner_resolve · blast_radius · create_tickets

36 read-only tools 9 write tools, all gated Preview + confirm token on compliance-affecting writes Entra device-code OAuth or scoped agent token External side effects require a provisioned human user
AI, on your terms
Deterministic by default. Local by choice.

Cryptographic inventory is the most sensitive asset list a security team holds — it is a literal map of what breaks if compromised. So CipherFlag treats AI as an option you switch on, not an architecture you inherit.

Every grade, finding, compliance verdict, and CBOM is produced deterministically. The 47-rule scoring engine, the compliance evaluator, and CBOM export are rule-based and reproducible. No model is involved in any of them, and most deployments run with AI switched off entirely.

Off by default

AI enrichment ships disabled. Turning it on is a deliberate, licensed configuration change — never a default, never implicit.

Run it entirely on your own network

Point enrichment at a local open-weight model — Ollama, vLLM, llama.cpp, LM Studio, or any OpenAI-compatible endpoint — and no cryptographic data ever leaves your infrastructure. Or use a commercial API under your own key. Cyber Flag operates no inference service and never proxies your data.

Narrow scope

Enrichment applies only to source-repository and container-image finding triage. It never produces a grade, a compliance verdict, or CBOM contents.

Redacted before it is sent

A byte-range redactor sits on the only code path between detection and prompt assembly. Key material is replaced with [REDACTED-<TYPE>-<hash>] markers before any bytes reach a model — enforced by test, not by convention.

Validated before it counts

Every response passes exploit-content scanning, a no-leak check that original key material has not been echoed back, and strict-JSON schema validation before it can become a finding.

Capped and ledgered

Per-scan, per-day, and per-month spend ceilings, with a full token and cost ledger for every call. No surprise bills, and a complete audit trail of what was asked.

Editions
Community vs Enterprise

Start free with the open-source Community Edition. Step up to Enterprise for full-fleet discovery, multi-asset scoring, and compliance.

CapabilityCE — Free (Apache 2.0)EE — Enterprise
Passive TLS discovery (Zeek)
Asset typesCertificatesCerts · keys · SSH · libraries · protocols · configs
Health scoring24 certificate rules47 rules across 5 asset types
PKI ExplorerForce-directed graph+ 3D constellation, blast-radius
Endpoint discoveryosquery/FleetDM, Velociraptor, Defender, CrowdStrike, SentinelOne, Tanium, Absolute, Forescout
Cloud discovery (AWS, Azure, Entra)
Source / Git discovery
Container image scanningOCI registry + binary crypto detection
Active TLS network scanningScheduled, with blackout windows
Directory (Netwrix AD CS)
Host mapping
Application tagging
Venafi exportTPP + Cloud push+ TPP policy-folder management, Thales CipherTrust
Compliance frameworksNIST 800-131A · PCI DSS 4.0 · FIPS 140-3 · CNSA 2.0 · NIS2
CBOM export (CycloneDX v1.6)
PQC program managementDispositions, waivers, migration waves
MCP server (AI agent interface)45 tools · 36 read, 9 gated writes
Optional AI enrichmentOff by default · local or BYO-key model
Ticketing (ServiceNow, Jira)
AuthJWT + RBAC+ SSO / SAML, OIDC, PIV/CAC
SupportCommunityCommercial SLA
PriceFreeContact for pricing
Open Source · Apache 2.0
Start free with the Community Edition

CipherFlag CE is the open-source core: passive TLS discovery via Zeek, 24-rule certificate health scoring, the interactive PKI Explorer, and Venafi export — all from a single docker-compose up.

$ curl -fsSL https://raw.githubusercontent.com/net4n6-dev/cipherflag/main/scripts/install.sh | sh

See CipherFlag EE against your environment

Bring your toughest crypto-visibility question. We'll show you what we find.

Request a Demo See it live