Discover
Identify algorithms, keys, certificates, protocols, libraries, hardware modules and cloud services.
BUILT FOR THE POST-QUANTUM TRANSITION
Enterprise cryptographic discovery.
Post-quantum migration intelligence.
Inventory your cryptography across software and infrastructure. Evaluate quantum exposure, prioritise migration, and verify what changed.
Built for SIH 2026 • PS 26164 • NTRO
01 / THE VISIBILITY GAP
Cryptography rarely lives in one place. It is distributed across source code, libraries, binaries, containers, certificates, protocols and cloud infrastructure.
Post-quantum migration starts with a trustworthy inventory. CipherSetu connects scattered evidence to a defensible next step.
Identify algorithms, keys, certificates, protocols, libraries, hardware modules and cloud services.
Build an evidence-backed CBOM. Evaluate quantum and classical risk, business impact, HNDL and Mosca timelines.
Prioritise function-aware PQC or hybrid paths with ML-KEM, ML-DSA, SLH-DSA and architecture-specific guidance.
Rescan, compare inventories and establish where vulnerable cryptography has been removed or reduced.
02 / ACROSS YOUR STACK
Follow cryptography wherever it lives, from a source-level call to infrastructure metadata.
Find cryptography in the code that runs your business.
Expose the cryptography inherited through your stack.
Inspect compiled artefacts with transparent evidence quality.
Trace cryptographic dependencies through image layers.
Understand algorithms and metadata without retaining key material.
Connect protocol configuration to cryptographic exposure.
Discover hardware crypto references and supported metadata.
Extend visibility to authorised cloud cryptographic services.
Product capabilities, not a live environment status. Structured parsers and live connectors depend on installed libraries, supported targets and authorised access. Fallbacks and unavailable capabilities are reported explicitly.
03 / BUILT TO BE DEFENSIBLE
A migration decision needs more than an algorithm name. It needs evidence, purpose and context.
Provenance and confidence travel with the finding, from discovery to the migration decision.
RSA signing and RSA encryption need different migration paths. Cryptographic purpose matters.
Insufficient evidence produces an explicit abstention, so unresolved roles stay visible.
Criticality informs consequence without manufacturing quantum vulnerability.
Rescan and compare before versus after. Make progress visible in the evidence.
Designed for local operation without external SaaS. Provision dependencies before disconnected deployment.
04 / RISK INTELLIGENCE
Business importance and quantum vulnerability answer different questions. CipherSetu keeps them distinct.
Critical data does not make every primitive an urgent PQC migration target.
Long-lived confidential data changes the urgency of a quantum-vulnerable use.
Examples explain the model; they are not scan results. Actual priority depends on the primitive, resolved function, exposure window, evidence and policy.
THE TIME DIMENSION
Mosca-style analysis asks whether the lifetime of sensitive data plus migration time exceeds a selected quantum horizon.
Encrypted data captured today may remain sensitive long enough to become decryptable in the future. Applicability depends on the cryptographic role.
Scenario analysis — not a prediction of quantum-computer arrival.
RECOGNISED STANDARDS. TRACEABLE GUIDANCE.
References describe formats and methodology. They do not imply certification, endorsement or affiliation.
05 / YOUR ENVIRONMENT. YOUR CONTROL.
A local-first platform with explicit processing boundaries and visible capability limits.
Static analysis inspects application artefacts without running the scanned application.
Temporary extraction workspaces and archive limits. Deploy in an operator-managed sandbox for additional isolation.
Path traversal, symlink, member-count and expanded-size checks protect extraction boundaries.
Secret-handling safeguards and metadata-focused inventories keep key material out of findings and exports.
Available parsers, degraded fallbacks and unavailable connectors are visible to operators.
Provision packages and dependencies locally; live external connectors remain explicit operator actions.
Track the knowledge base, engine and policy behind a scan’s decisions.
06 / FROM INTELLIGENCE TO ACTION
Move between findings, risk, asset relationships and remediation in one operational workspace.
THE NEXT STEP IS VISIBILITY
Start with evidence. Build a migration plan you can defend.