Automated scanners and analyzers to help you discover cryptographic assets and assess quantum readiness across your organization
Discover and inventory cryptographic assets in your codebase. CryptoScan scans source code, configurations, and dependencies to identify cryptographic implementations vulnerable to quantum attacks.
Analyze TLS/SSL configurations across your infrastructure for quantum readiness. Evaluates cipher suites, protocols, and certificates against CNSA 2.0 compliance timelines.
Identify quantum-vulnerable cryptographic algorithms hiding in your software dependencies. Analyzes Go, npm, Python, and Maven packages for cryptographic usage and quantum risk exposure.
An independent open-source project (Apache 2.0). CryptoServe is cryptography and key management as a service. Rather than each application picking algorithms and managing its own keys, the app declares what it is protecting and why; CryptoServe resolves the algorithm from policy, derives and rotates the keys beneath it, and keeps that choice post-quantum ready. It also scans codebases and scores post-quantum readiness, which covers the discovery work in QRAMM Dimension 1, Cryptographic Visibility & Inventory.
"What post-quantum crypto should I use?" Finally, there's a tool for that. Get natural language recommendations for NIST algorithms with sector-specific guidance and SNDL threat assessment.
Invisible provenance capture for quantum computing experiments. One import for complete reproducibility with zero code changes. Automatically captures environment, circuit, transpilation, hardware, and results.
Choose the right tool based on your assessment needs
| Feature | CryptoScan | TLS Analyzer | CryptoDeps | CryptoServe | PQC-Bench | QBOM |
|---|---|---|---|---|---|---|
| Primary Use | Source code and configuration scanning | Network endpoint and certificate analysis | Dependency and package scanning | Cryptography and key management for applications | PQC algorithm recommendations | Quantum experiment reproducibility |
| Scan Target | Codebases, repositories, config files | TLS endpoints, SSL certificates | Go, npm, Python, Maven dependencies | Application data via SDK, plus codebases in 6 languages | Natural language queries, use cases | Qiskit, Cirq, PennyLane experiments |
| Output Formats | SARIF, CycloneDX CBOM, JSON, CSV | HTML reports, CycloneDX CBOM, JSON | SARIF, CycloneDX CBOM, JSON | SARIF, CycloneDX and SPDX CBOM, JSON | CLI output, sector guides | JSON, CycloneDX, SPDX, YAML |
| CI/CD Integration | GitHub Actions, GitLab CI, Jenkins | Any CI/CD pipeline | GitHub Actions, any CI/CD pipeline | Python and JavaScript SDKs, REST API, SARIF CI gate | CLI tool, scriptable | Python import hook, CLI |
| Compliance Mapping | NIST PQC, CNSA 2.0 | CNSA 2.0 timelines | NIST PQC, quantum risk levels | NIST PQC (FIPS 203/204/205), FIPS 140-2/3 compliance mode | CNSA 2.0, FIPS 140-3, SNDL threat model | Reproducibility scoring, provenance capture |
Combine these automated tools with the QRAMM Assessment Toolkit for a comprehensive organizational evaluation.