Product

Scanner. Classifier. Report engine.

A local command-line scanner that detects cryptographic and key-management signals in source code, grades them, and writes reports a reviewer or an auditor can act on.

Quantum Core field modelt = live
3329
repo → inventorywallet.sign() → classifyvalidator_key → priorityreport.md
Scansource
Classifydomain
Reportaction
Scan

Repository analysis

Walks source trees, skips vendored and generated code, and detects crypto and key-management patterns.

Classify

Crypto-native domains

Wallets, validators, exchanges, custody, governance, bridges, TLS and secrets.

Report

Actionable output

Markdown, JSON, SARIF 2.1.0 and CycloneDX 1.6 CBOM. Findings appear as GitHub code scanning alerts.

Two scores, not one.

Weakness score

Cryptography that is broken today: MD5, ECB, weak randomness, disabled TLS verification, hardcoded keys. Severity-weighted from 0 to 100. This is what gates CI.

Migration exposure

The asymmetric surface that must move before 2035, reported as sites, files and a percentage of the codebase. It never fails a build, because none of it is a defect.

Why separate

One number saturates on any real cryptography repository. A correct secp256k1 wallet scores zero weakness and passes, while still recording its migration work.

Cryptographic Bill of Materials.

What it is

A CycloneDX 1.6 CBOM, published as ECMA-424: the inventory format auditors and crypto-agility tooling consume, and the basis of NIST IR 8547 migration planning.

Inventory, not findings

One component per algorithm. MD5 found in forty files is a single entry with forty occurrences, each carrying its file and line.

Quantum grading

Every asset carries its NIST PQC security category. RSA, ECDSA, Ed25519 and ECDH all report category zero, meaning they meet none of them.

Deterministic

The same input produces the same document, so two runs can be compared directly.