Repository analysis
Walks source trees, skips vendored and generated code, and detects crypto and key-management patterns.
Product
A local command-line scanner that detects cryptographic and key-management signals in source code, grades them, and writes reports a reviewer or an auditor can act on.
Walks source trees, skips vendored and generated code, and detects crypto and key-management patterns.
Wallets, validators, exchanges, custody, governance, bridges, TLS and secrets.
Markdown, JSON, SARIF 2.1.0 and CycloneDX 1.6 CBOM. Findings appear as GitHub code scanning alerts.
Cryptography that is broken today: MD5, ECB, weak randomness, disabled TLS verification, hardcoded keys. Severity-weighted from 0 to 100. This is what gates CI.
The asymmetric surface that must move before 2035, reported as sites, files and a percentage of the codebase. It never fails a build, because none of it is a defect.
One number saturates on any real cryptography repository. A correct secp256k1 wallet scores zero weakness and passes, while still recording its migration work.
A CycloneDX 1.6 CBOM, published as ECMA-424: the inventory format auditors and crypto-agility tooling consume, and the basis of NIST IR 8547 migration planning.
One component per algorithm. MD5 found in forty files is a single entry with forty occurrences, each carrying its file and line.
Every asset carries its NIST PQC security category. RSA, ECDSA, Ed25519 and ECDH all report category zero, meaning they meet none of them.
The same input produces the same document, so two runs can be compared directly.