Cryptographic Supply Chain Intelligence

Map Your Crypto. Prepare for Quantum.

An enterprise Cryptographic & Quantum Bill of Materials engine - discovers cryptography across source code, dependencies, container images, binaries, PKI, key vaults, and live network endpoints, then scores your post-quantum exposure.

Node.js ≥ 18
AST-level detection
Pure-JS, offline
SARIF · CI-ready
Complete cryptographic visibility across your entire software estate

7

Discovery surfaces

15

Languages (AST)

120

Algorithm signatures

0/0

Prod. critical / high advisories

100%

Schema-valid output

Two Bills of Materials

A CBOM you can act on, A QBOM you can plan with

A complete cryptographic inventory today, with the intelligence to plan your post-quantum migration tomorrow.

CBOM

CRYPTOGRAPHIC BILL OF MATERIALS · CYCLONEDX 1.6

  • cryptographic-asset components with full crypto properties
  • Classical & NIST quantum security levels per algorithm
  • Evidence occurrences - file + line for every finding
  • CWE/CVE vulnerabilities, overall risk score & grade
  • Validated against the official CycloneDX 1.6 schema

QBOM

QUANTUM BILL OF MATERIALS · EMITTED ALONGSIDE EVERY CBOM

  • Per-asset threat:shor/grover/none
  • Harvest-now-decrypt-later exposure flag
  • Concrete migration target + FIPS 203/204/205 standard
  • Quantum-readiness score, grade & migration roadmap
  • CNSA 2.0 (2035) deadline mapping
Why now

The post-quantum migration clock is running

NIST's PQC standards are final and the deadlines are set. A QBOM turns that timeline into a per-asset plan.

2024NIST finalizes FIPS 203/204/205
2025Inventory now - baseline your CBOM / QBOM
2030NSA: quantum-resistant preferred; begin deprecation
2033PQC exclusive for new systems
2035CNSA 2.0 - classical public-key disallowed
Coverage

Five Pillars of Cryptographic Discovery

Every cryptographic asset falls into one of five discovery domains, providing complete visibility across software, firmware, infrastructure, and runtime environments.

Source Code - AST level

Real syntax trees resolve import aliases, aliased objects, and propagated constants that regex-only tools miss.

Container · Binary · Deps

Dependency manifests + CVE DB, Dockerfiles, OCI image layers, and ELF/PE/JAR crypto-library detection.

Certificate & PKI

X.509, JKS keystores, CA-bundle & trust-chain analysis, LDAP / Active Directory discovery.

Network / Protocol

Live TLS version + cipher + cert-chain enumeration, SSH KEXINIT algorithms, LDAP, IPsec reachability.

Keys & Secrets

PKCS#11 HSMs, AWS/Azure/GCP KMS, HashiCorp Vault, CyberArk, private-key files, entropy detection.

How a scan flows

Discover → Understand → Score → Emit

One pass over your codebase, resolved to a signed, schema-valid inventory.

Step 01

Discover

Walk source, deps, images, keystores & endpoints.

Step 02

Parse

AST + regex extract every crypto API, key & cert.

Step 03

Classify & score

Rank SAFE → CRITICAL against a bundled rule set.

Step 04

Quantum analysis

Flag Shor/Grover exposure & migration targets.

Step 05

Emit

CBOM · QBOM · SARIF · HTML · Markdown.

Detection Engines

Ten specialised scanners, one ranked inventory

Every engine feeds a single deduplicated, risk-scored bill of materials.

Algorithm

Regex + AST

102 signatures across symmetric, asymmetric, hash, MAC, PQC and protocol families.

  • AES modes, DES/3DES/RC4
  • RSA/DSA/ECC + key sizes
  • ML-KEM · ML-DSA · SLH-DSA

Certificate & PKI

X.509
  • PEM / DER / PKCS#12 / JKS
  • Expiry, self-signed, weak sig
  • Trust-chain validation

Network

Active

Pure-Node probing, no external binaries.

  • TLS 1.0–1.3 + cipher + chain
  • SSH KEXINIT enumeration

Dependencies

CVE DB

11 manifest formats vs 25 CVE-tracked crypto libraries with EOL & safe-version data.

Container

OCI
  • Dockerfile crypto packages
  • Keys/certs baked into layers
  • docker-save tarball walking

Binary

ELF/PE/JAR

13 crypto libraries by soname & banner (OpenSSL, BoringSSL, mbedTLS...) with versions.

Key Management

18 rules

PKCS#11 HSMs, cloud KMS, Vault, CyberArk, Luna / nShield / YubiHSM.

Secrets

29 rules

Provider tokens + entropy — docs skipped, tuned thresholds to cut noise.

Post-Quantum

FIPS 203/4/5

Shor-breakable vs Grover-weakened, migration priority, CNSA 2.0 timeline.

WHY PRECOGS

Traditional SCA vs. Precogs CBOM/QBOM

Existing tools scan dependencies. Precogs scans the cryptographic algorithms inside your code.

CapabilitySnyk / Checkmarx / SonarQubeIBM CBOMkitPrecogs AI
Cryptographic algorithm inventory
Quantum-vulnerable classification (QBOM)Partial
Post-Quantum Readiness Score
NIST FIPS 203/204/205 migration mapping
SCA + SBOM + CBOM unified platformPartialCBOM only
Deterministic (no AI/ML in detection)
CycloneDX CBOM output (ECMA-424)
Auto-fix / remediation PR generation
Autonomous penetration testing
INDUSTRY APPLICATIONS

Built for Security-Critical Industries

Where cryptographic failures mean lives, money, or national security.

Automotive

ISO 21434 • UNECE R155

Protect vehicle software supply chains, ECUs, and OTA update signatures against Harvest Now, Decrypt Later (HNDL) attacks.

ECU firmwareOTA signingV2X

Financial Services

PCI DSS • SOX

Inventory cryptographic assets across payment rails, HSMs, and trading systems. Prove quantum readiness to auditors and regulators.

HSMPaymentsTrading

Healthcare

HIPAA • HITECH

Discover legacy TLS and weak key exchanges across EHR systems, medical devices, and laboratory environments with zero disruption.

EHRMedical IoTClinical Labs

Defence & Government

CNSA 2.0

Prepare for CNSA 2.0 migration timelines. Map, prioritize, and migrate national security systems to NIST PQC standards.

Air-gappedPQCClassified

Cloud & SaaS

EU CRA

Continuously assess multi-cloud cryptography, KMS usage, and third-party components across every service.

AWSAzureGCPKMS

Critical Infrastructure

CISA • SCADA

Harden OT and ICS environments with crypto discovery designed for air-gapped and hybrid deployments.

OTICS
Outputs

Formats for humans, machines, and pipelines

Human-readable reports and machine-readable formats for every security workflow.

FormatFilePurpose
CycloneDX 1.6 CBOM*.jsonMachine-readable inventory, schema-valid
CycloneDX 1.6 QBOM*.qbom.jsonQuantum readiness & migration
SARIF 2.1.0*.sarifGitHub code-scanning / CI
Markdown*.mdHuman-readable report
Interactive HTML*.htmlSelf-contained dashboard
Compliance Ready

Security Standards Alignmen

Continuously validate software artifacts against recognized industry benchmarks.

Compliance Precogs AI
Get started with Precogs for free

Inventory your cryptography today.

One command gives you a schema-valid CBOM, a quantum-readiness QBOM, and a SARIF report for your pipeline.