CipherFlag EE discovers cryptography across every endpoint, cloud, repo, and network segment, scores it against 47 rules, and proves compliance — built for the post-quantum transition.
One program for cryptographic preparedness — from finding every asset to proving you are ready for the post-quantum transition.
A single, unified inventory of every cryptographic asset across endpoint, cloud, source, network, and directory — with host identity resolution and application tagging, so each asset is mapped to the host and application that owns it.
Every asset is graded A+ to F against 47 rules across five asset types — expiration, key strength, signature algorithms, chain trust, protocol versions, library CVEs, SSH hygiene, and crypto-agility. Each finding carries severity, category, point deduction, and remediation guidance.
Map findings to the controls auditors ask about, and export a complete cryptographic bill of materials.
CBOM export — generate a CycloneDX v1.6 cryptographic bill of materials for any scope, with per-component rule-engine provenance, ready to hand to auditors or feed downstream tooling.
Turn findings into action. CipherFlag EE prioritizes by blast radius and exposure, tracks crypto-agility across your estate, and surfaces a post-quantum readiness view so you know exactly what to migrate first as CNSA 2.0 deadlines approach.
CipherFlag EE ships a native Model Context Protocol server — cipherflag-mcp — exposing 45 tools over your live inventory. Point Claude, or any MCP-capable agent, at your own deployment and ask questions in plain language. The agent queries your data directly; nothing is uploaded anywhere to make that work.
Certificates, SSH keys, protocol endpoints, and crypto libraries — filtered by algorithm, issuer, owner, environment, posture, grade, or expiry, with faceted drill-down.
Readiness rollups per framework, ranked remediation tasks, dispositions and expiring waivers, and the ordered migration-wave plan with cross-wave consequences.
Downstream impact if an asset is compromised, shared-asset host pairs, shadow and rogue CAs, and orphaned assets with no owner sighting.
Per-framework pass/partial/fail rollups and per-asset violations across NIST 800-131A, PCI DSS 4.0, FIPS 140-3, CNSA 2.0, and NIS2 — computed live.
Which asset classes your sources can structurally see, which connectors are stale or failing, dev-vs-prod config drift, and whether a renewal actually propagated.
Resolve the ownership chain for any asset, stamp owners and environments, and open remediation tickets in ServiceNow or Jira.
“What's left for CNSA 2.0, who owns it, and what breaks if we rotate the top item first?”
→ pqc_worklist · owner_resolve · blast_radius · create_tickets
Cryptographic inventory is the most sensitive asset list a security team holds — it is a literal map of what breaks if compromised. So CipherFlag treats AI as an option you switch on, not an architecture you inherit.
Every grade, finding, compliance verdict, and CBOM is produced deterministically. The 47-rule scoring engine, the compliance evaluator, and CBOM export are rule-based and reproducible. No model is involved in any of them, and most deployments run with AI switched off entirely.
AI enrichment ships disabled. Turning it on is a deliberate, licensed configuration change — never a default, never implicit.
Point enrichment at a local open-weight model — Ollama, vLLM, llama.cpp, LM Studio, or any OpenAI-compatible endpoint — and no cryptographic data ever leaves your infrastructure. Or use a commercial API under your own key. Cyber Flag operates no inference service and never proxies your data.
Enrichment applies only to source-repository and container-image finding triage. It never produces a grade, a compliance verdict, or CBOM contents.
A byte-range redactor sits on the only code path between detection and prompt assembly. Key material is replaced with [REDACTED-<TYPE>-<hash>] markers before any bytes reach a model — enforced by test, not by convention.
Every response passes exploit-content scanning, a no-leak check that original key material has not been echoed back, and strict-JSON schema validation before it can become a finding.
Per-scan, per-day, and per-month spend ceilings, with a full token and cost ledger for every call. No surprise bills, and a complete audit trail of what was asked.
Start free with the open-source Community Edition. Step up to Enterprise for full-fleet discovery, multi-asset scoring, and compliance.
| Capability | CE — Free (Apache 2.0) | EE — Enterprise |
|---|---|---|
| Passive TLS discovery (Zeek) | ✓ | ✓ |
| Asset types | Certificates | Certs · keys · SSH · libraries · protocols · configs |
| Health scoring | 24 certificate rules | 47 rules across 5 asset types |
| PKI Explorer | Force-directed graph | + 3D constellation, blast-radius |
| Endpoint discovery | — | osquery/FleetDM, Velociraptor, Defender, CrowdStrike, SentinelOne, Tanium, Absolute, Forescout |
| Cloud discovery (AWS, Azure, Entra) | — | ✓ |
| Source / Git discovery | — | ✓ |
| Container image scanning | — | OCI registry + binary crypto detection |
| Active TLS network scanning | — | Scheduled, with blackout windows |
| Directory (Netwrix AD CS) | — | ✓ |
| Host mapping | — | ✓ |
| Application tagging | — | ✓ |
| Venafi export | TPP + Cloud push | + TPP policy-folder management, Thales CipherTrust |
| Compliance frameworks | — | NIST 800-131A · PCI DSS 4.0 · FIPS 140-3 · CNSA 2.0 · NIS2 |
| CBOM export (CycloneDX v1.6) | — | ✓ |
| PQC program management | — | Dispositions, waivers, migration waves |
| MCP server (AI agent interface) | — | 45 tools · 36 read, 9 gated writes |
| Optional AI enrichment | — | Off by default · local or BYO-key model |
| Ticketing (ServiceNow, Jira) | — | ✓ |
| Auth | JWT + RBAC | + SSO / SAML, OIDC, PIV/CAC |
| Support | Community | Commercial SLA |
| Price | Free | Contact for pricing |
CipherFlag CE is the open-source core: passive TLS discovery via Zeek, 24-rule certificate health scoring, the interactive PKI Explorer, and Venafi export — all from a single docker-compose up.
$ curl -fsSL https://raw.githubusercontent.com/net4n6-dev/cipherflag/main/scripts/install.sh | sh
Bring your toughest crypto-visibility question. We'll show you what we find.