Cryptoramic

Terminology

What is cryptographic discovery?

The first step is finding cryptography. The useful step is understanding where it belongs.

The discovery chain from a scanned source to a cryptographic asset A host runs a scan; inside a container image, inside a layer, inside a package, a keystore holds a certificate and a private key. Each step is recorded, so the asset can be traced back to its origin and its owner. Discovery chain, kept with every finding Hostbuild-runner-02 Imageapp:2.4 · sha256:9f3c… Layer 3application and runtime Packageapp-server-2.4.jar Keystoreconf/keys.p12 Certificate + private key RSA-2048 · expires 2027-03 · key kept as metadata only What the chain makes possible owner via the image's build pipeline · fix in the right layer · rescan the digest Found in a package is not the same as used at runtime. The inventory keeps the distinction; configuration, traffic or runtime evidence confirms use.
  1. Source

    Identify the host, file, repository or image that was examined.

  2. Discovery path

    Follow containers, archives or packages to the cryptographic object.

  3. Finding

    Retain that path so the owner can investigate and verify a change.

The discovery chain: host, image, layer, package, keystore, asset.

Cryptographic discovery is the process of identifying cryptographic assets and evidence of cryptographic use in an environment. Findings can include certificates, keys, algorithms, protocols, and the software or services associated with them.

The Cryptoramic asset inventory: certificates, keys and protocol observations with their algorithms, issues and last-seen time, plus distributions by type and algorithm.
Assets · Illustrative assessment data

How is it different from a certificate inventory?

A certificate inventory focuses on certificates and properties such as issuer, validity, and key algorithm. A broader cryptographic inventory also considers other material and usage context. A certificate inventory can be an important part of that picture without representing all of it. The broader practice is often called cryptographic asset discovery and inventory; see what CADI means and how it differs from certificate lifecycle management.

What makes a finding useful?

An asset record becomes more actionable when it includes evidence of where it was observed and relationships that help explain its use. Technical teams can then investigate the finding, establish who owns the affected system, and determine whether action is needed.

Discovery also has limits. Access restrictions, scan scope, encrypted content, and systems outside the assessment can create gaps. A useful report explains what was observed and preserves the distinction between observations and conclusions.

How does discovery support post-quantum planning?

An inventory gives teams a baseline for investigating cryptographic dependencies. They can combine that evidence with data sensitivity, system ownership, and supplier roadmaps to plan migration work. The inventory is an input to that work, not proof that a system is ready for a cryptographic change.

Back to perspectives

See your own environment more clearly.

Explore the platform

Product screenshot

Illustrative assessment data