Skip to content

BUILT FOR THE POST-QUANTUM TRANSITION

Discover. Assess.
Migrate. Verify.

Enterprise cryptographic discovery.
Post-quantum migration intelligence.

Inventory your cryptography across software and infrastructure. Evaluate quantum exposure, prioritise migration, and verify what changed.

Built for SIH 2026 • PS 26164 • NTRO

THE CRYPTOGRAPHIC INTELLIGENCE LAYERCONCEPTUAL ARCHITECTURE
01Source code
02Dependencies
03Binaries
04Containers
05Certificates
06Protocols
07HSM / TPM
08Cloud KMS
CipherSetuDISCOVERY → INTELLIGENCEProvenance · Confidence · Context
01
CBOMCryptographic inventory
02
RiskPrioritised exposure
03
Mosca / HNDLTime & confidentiality
04
PQC migrationFunction-aware paths
05
VerificationRescan & compare
SOFTWARE + INFRASTRUCTUREONE TRACEABLE EVIDENCE CHAIN
DISCOVER → ASSESS → PRIORITISE → MIGRATE → VERIFYExplore the platform ↓

01 / THE VISIBILITY GAP

You can’t migrate cryptography you can’t see.

Cryptography rarely lives in one place. It is distributed across source code, libraries, binaries, containers, certificates, protocols and cloud infrastructure.

Post-quantum migration starts with a trustworthy inventory. CipherSetu connects scattered evidence to a defensible next step.

01

Discover

Identify algorithms, keys, certificates, protocols, libraries, hardware modules and cloud services.

02

Assess

Build an evidence-backed CBOM. Evaluate quantum and classical risk, business impact, HNDL and Mosca timelines.

03

Migrate

Prioritise function-aware PQC or hybrid paths with ML-KEM, ML-DSA, SLH-DSA and architecture-specific guidance.

04

Verify

Rescan, compare inventories and establish where vulnerable cryptography has been removed or reduced.

02 / ACROSS YOUR STACK

Eight evidence layers.
One cryptographic picture.

Follow cryptography wherever it lives, from a source-level call to infrastructure metadata.

Source code

Find cryptography in the code that runs your business.

Python AST · Tree-sitter C / C++ / Java

Dependencies

Expose the cryptography inherited through your stack.

Libraries · Package manifests

Binaries

Inspect compiled artefacts with transparent evidence quality.

LIEF · Dynamic symbols · Fallback evidence

Containers

Trace cryptographic dependencies through image layers.

Docker-save · OCI · Layer provenance

Certificates & keys

Understand algorithms and metadata without retaining key material.

X.509 · PKCS8 · PKCS12

Protocols

Connect protocol configuration to cryptographic exposure.

TLS · SSH · IPsec / IKE · WPA evidence

Hardware

Discover hardware crypto references and supported metadata.

PKCS#11 · HSM · TPM-style references

Cloud crypto

Extend visibility to authorised cloud cryptographic services.

AWS KMS / CloudHSM · Azure Key Vault / Managed HSM · GCP KMS

Product capabilities, not a live environment status. Structured parsers and live connectors depend on installed libraries, supported targets and authorised access. Fallbacks and unavailable capabilities are reported explicitly.

03 / BUILT TO BE DEFENSIBLE

Every recommendation
has to earn your trust.

A migration decision needs more than an algorithm name. It needs evidence, purpose and context.

01

Evidence, not guesswork

Provenance and confidence travel with the finding, from discovery to the migration decision.

02

Function-aware migration

RSA signing and RSA encryption need different migration paths. Cryptographic purpose matters.

03

No forced answers

Insufficient evidence produces an explicit abstention, so unresolved roles stay visible.

04

Business + crypto context

Criticality informs consequence without manufacturing quantum vulnerability.

05

Remediation proof

Rescan and compare before versus after. Make progress visible in the evidence.

06

Air-gapped ready

Designed for local operation without external SaaS. Provision dependencies before disconnected deployment.

04 / RISK INTELLIGENCE

Separate the dimensions.
Sharpen the decision.

Business importance and quantum vulnerability answer different questions. CipherSetu keeps them distinct.

01Quantum vulnerability02Business impact03Classical security04Evidence confidence05HNDL exposure06Mosca timing
ILLUSTRATIVE EXAMPLE

AES-GCM

Critical data does not make every primitive an urgent PQC migration target.

Business impact
Critical
Quantum migration priority
Low
ILLUSTRATIVE EXAMPLE

RSA encryption

Long-lived confidential data changes the urgency of a quantum-vulnerable use.

Business impact
Critical
Quantum migration priority
Immediate
HNDL exposure
Applicable

Examples explain the model; they are not scan results. Actual priority depends on the primitive, resolved function, exposure window, evidence and policy.

THE TIME DIMENSION

Migration has a lead time.
So does your data.

Mosca-style analysis asks whether the lifetime of sensitive data plus migration time exceeds a selected quantum horizon.

Harvest now. Decrypt later.

Encrypted data captured today may remain sensitive long enough to become decryptable in the future. Applicability depends on the cryptographic role.

ILLUSTRATIVE SCENARIO / 8 + 3 = 11 YEARS
8yData lifetime
+
3yMigration time
>
?Quantum horizon
5 yearsAT RISK
10 yearsAT RISK
15 yearsNOT YET
20 yearsNOT YET

Scenario analysis — not a prediction of quantum-computer arrival.

RECOGNISED STANDARDS. TRACEABLE GUIDANCE.

Built around recognised standards
and migration guidance.

CycloneDX 1.6Cryptographic inventory
NIST FIPS 203ML-KEM
NIST FIPS 204ML-DSA
NIST FIPS 205SLH-DSA
MoscaExposure-window analysis

References describe formats and methodology. They do not imply certification, endorsement or affiliation.

05 / YOUR ENVIRONMENT. YOUR CONTROL.

Designed for
security-conscious teams.

A local-first platform with explicit processing boundaries and visible capability limits.

Local by designNo external SaaS dependency for core analysis.

No scanned code execution

Static analysis inspects application artefacts without running the scanned application.

Bounded processing

Temporary extraction workspaces and archive limits. Deploy in an operator-managed sandbox for additional isolation.

Archive protections

Path traversal, symlink, member-count and expanded-size checks protect extraction boundaries.

Secret redaction

Secret-handling safeguards and metadata-focused inventories keep key material out of findings and exports.

Capability transparency

Available parsers, degraded fallbacks and unavailable connectors are visible to operators.

Local / air-gapped deployment

Provision packages and dependencies locally; live external connectors remain explicit operator actions.

Versioned knowledge and risk policy

Track the knowledge base, engine and policy behind a scan’s decisions.

06 / FROM INTELLIGENCE TO ACTION

The evidence is only the beginning.
Work through the decision.

Move between findings, risk, asset relationships and remediation in one operational workspace.

CipherSetu / Scan intelligencePRODUCT UI PREVIEW · NO SCAN DATA
Findings explorerRisk dimensionsAsset graphCBOM validationRemediation diff

Follow a finding to its source.

WORKSPACE ANATOMY
Evidence explorer
Location
File · line · symbol
Cryptographic use
Primitive · function · library
Provenance
Parser · confidence · evidence
Findings appear after a scan.

A traceable decision path

Raw evidence → Correlated asset
Risk context → Migration path
Rescan → Remediation diff
Evidence · Risk · Graph · CBOM · Policy · ExportEnter the real workspace

THE NEXT STEP IS VISIBILITY

Know your cryptography
before quantum migration
becomes urgent.

Start with evidence. Build a migration plan you can defend.