Open source tools

Automated scanners and analyzers to help you discover cryptographic assets and assess quantum readiness across your organization

CryptoScan

Available Now

Discover and inventory cryptographic assets in your codebase. CryptoScan scans source code, configurations, and dependencies to identify cryptographic implementations vulnerable to quantum attacks.

Key features

  • Detects RSA, ECDSA, AES, MD5, SHA-1 and more
  • Classifies findings by quantum vulnerability level
  • SARIF output for GitHub Security integration
  • Generates CycloneDX Cryptographic BOM (CBOM)
  • CI/CD pipeline integration ready

TLS Analyzer

Available Now

Analyze TLS/SSL configurations across your infrastructure for quantum readiness. Evaluates cipher suites, protocols, and certificates against CNSA 2.0 compliance timelines.

Key features

  • Scans TLS configurations and certificates
  • CNSA 2.0 compliance timeline assessment
  • Generates detailed HTML security reports
  • CycloneDX CBOM output for compliance
  • Bulk endpoint scanning capability

CryptoDeps

Available Now

Identify quantum-vulnerable cryptographic algorithms hiding in your software dependencies. Analyzes Go, npm, Python, and Maven packages for cryptographic usage and quantum risk exposure.

Key features

  • Scans Go, npm, Python, and Maven dependencies
  • Quantum risk classification (VULNERABLE, PARTIAL, SAFE)
  • CycloneDX CBOM and SARIF output formats
  • Workspace & monorepo support (npm, pnpm, Go)
  • Direct GitHub repository scanning
  • CI/CD pipeline integration ready

CryptoServe

Available Now

An independent open-source project (Apache 2.0). CryptoServe is cryptography and key management as a service. Rather than each application picking algorithms and managing its own keys, the app declares what it is protecting and why; CryptoServe resolves the algorithm from policy, derives and rotates the keys beneath it, and keeps that choice post-quantum ready. It also scans codebases and scores post-quantum readiness, which covers the discovery work in QRAMM Dimension 1, Cryptographic Visibility & Inventory.

Key features

  • Context-driven algorithm selection: describe the data, not the cipher
  • Hierarchical key management with HKDF derivation, rotation, and versioning
  • NIST post-quantum algorithms: ML-KEM, ML-DSA, SLH-DSA, and hybrid key exchange
  • Zero-config Python and JavaScript SDKs, plus a REST API
  • Codebase scanning and CBOM export in CycloneDX or SPDX, with a SARIF CI gate
  • Optional self-hosted server adds policy enforcement, audit logging, and HSM/KMS backends

PQC-Bench

Available Now

"What post-quantum crypto should I use?" Finally, there's a tool for that. Get natural language recommendations for NIST algorithms with sector-specific guidance and SNDL threat assessment.

Key features

  • Natural language algorithm queries
  • 7 critical infrastructure sector guides
  • SNDL (Store Now, Decrypt Later) threat assessment
  • Library production-readiness checks
  • Protocol impact analysis (TLS, certificates)
  • Compliance guidance (CNSA 2.0, FIPS 140-3)

QBOM

Available Now

Invisible provenance capture for quantum computing experiments. One import for complete reproducibility with zero code changes. Automatically captures environment, circuit, transpilation, hardware, and results.

Key features

  • Zero code changes required
  • Qiskit, Cirq, PennyLane support
  • Reproducibility scoring (0-100)
  • Calibration & drift analysis
  • CycloneDX/SPDX SBOM export
  • Paper statement generation

Tool comparison

Choose the right tool based on your assessment needs

Feature CryptoScan TLS Analyzer CryptoDeps CryptoServe PQC-Bench QBOM
Primary Use Source code and configuration scanning Network endpoint and certificate analysis Dependency and package scanning Cryptography and key management for applications PQC algorithm recommendations Quantum experiment reproducibility
Scan Target Codebases, repositories, config files TLS endpoints, SSL certificates Go, npm, Python, Maven dependencies Application data via SDK, plus codebases in 6 languages Natural language queries, use cases Qiskit, Cirq, PennyLane experiments
Output Formats SARIF, CycloneDX CBOM, JSON, CSV HTML reports, CycloneDX CBOM, JSON SARIF, CycloneDX CBOM, JSON SARIF, CycloneDX and SPDX CBOM, JSON CLI output, sector guides JSON, CycloneDX, SPDX, YAML
CI/CD Integration GitHub Actions, GitLab CI, Jenkins Any CI/CD pipeline GitHub Actions, any CI/CD pipeline Python and JavaScript SDKs, REST API, SARIF CI gate CLI tool, scriptable Python import hook, CLI
Compliance Mapping NIST PQC, CNSA 2.0 CNSA 2.0 timelines NIST PQC, quantum risk levels NIST PQC (FIPS 203/204/205), FIPS 140-2/3 compliance mode CNSA 2.0, FIPS 140-3, SNDL threat model Reproducibility scoring, provenance capture

Ready to assess your quantum readiness?

Combine these automated tools with the QRAMM Assessment Toolkit for a comprehensive organizational evaluation.