Find cryptography across the codebase.
Identify cryptographic calls, libraries, dependencies, configurations, and weak or quantum-vulnerable patterns.
Cryptographic posture management built for the migration era
Ciphertron scans the cryptography inside your repositories, traces how it is used, and turns the result into a prioritized CBOM—so migration decisions can start with evidence.
Discover assets
Trace usage
Prioritize change
Retain evidence
Start from a GitHub URL. Repository access and source handling are confirmed in the Ciphertron workspace.
Repository reviews remain bounded to the source and evidence needed for the decision.
Start with source context, not a generic dependency list. Ciphertron identifies cryptographic assets, traces how they are used, and structures the result for engineering and risk teams.
A quantum-vulnerable key-transport path is present in the authentication boundary.
auth/token.ts:84Illustrative interface. Connect your own repository after access is provisioned.
Every detected asset stays connected to its location, use, and suggested migration state.
auth/token.tsReview requiredvault/envelope.goReplacesigning/receipt.pyReplaceaudit/chain.rsTrace contextIllustrative product data.
Inventory alone cannot direct a migration. Ciphertron keeps discovery, context, priority, and evidence connected.
Identify cryptographic calls, libraries, dependencies, configurations, and weak or quantum-vulnerable patterns.
Connect assets to cross-file usage, data paths, dependencies, and the system boundaries that determine impact.
Carry the finding, migration state, supported verification result, and human review into one retained record.
Ciphertron is designed to limit source handling, isolate supported verification work, and preserve a reviewable record.
Hosted scans use a temporary workspace designed to be cleaned after processing.
Supported migration checks can run with network access removed and container capabilities restricted.
CycloneDX 1.6 CBOM data turns repository findings into a portable, reviewable inventory.
Evidence supports engineering judgment. Review remains part of the decision before code changes land.
Repository context is used to produce a structured posture record. Internal orchestration and proprietary evaluation logic remain outside the customer-facing surface.
Evidence supports judgment. It does not replace it.