CipherFlag EE discovers cryptography across every endpoint, cloud, repo, and network segment, scores it against 49 rules, ranks migration by data lifetime and exposure, and proves compliance — built for the post-quantum transition.
One program for cryptographic preparedness — from finding every asset to proving you are ready for the post-quantum transition.
A single, unified inventory of every cryptographic asset across endpoint, cloud, source, container, network, directory, CNAPP, and data-sensitivity sources — with host identity resolution and application tagging, so each asset is mapped to the host and application that owns it.
Every asset is graded A+ to F against 49 rules across five asset types plus CNAPP enrichment — expiration, key strength, signature algorithms, chain trust, protocol versions, library CVEs, SSH hygiene, crypto-agility, and linked Prisma Cloud or Wiz exposure and IaC findings. Each finding carries severity, category, point deduction, and remediation guidance. Scoring is deterministic; CNAPP deductions fire only when a CNAPP signal is linked. Every rule is listed in the Detection Rules register, where admins can tune severity, scope, or deduction with a recorded justification — and any report or CBOM scored under a modified ruleset says so.
Map findings to the controls auditors ask about — including the NIST post-quantum standards — export a complete cryptographic bill of materials, and forward a hash-chained authorization log to the SIEM you already run.
Standards timeline — every asset shows its CNSA 2.0 use-case class and milestone clock, and where it sits on the NIST IR 8547 deprecation timeline (a draft, and labelled as one).
CBOM export — generate a CycloneDX v1.6 cryptographic bill of materials for any scope, with per-component rule-engine provenance and an optional Ed25519 signature from a standard OpenSSL, HSM, or KMS key, ready to hand to auditors or feed downstream tooling.
Evidence pack — a deterministic ZIP of inventory, findings, per-framework compliance, the standards timeline, and the waiver register, with a signed SHA-256 manifest; plus OMB M-23-02 inventory exports for federal agencies.
Hash-chained audit + SIEM — every authorization decision, admin action, login, MFA event and governance write is a durable, queryable, hash-chained row. Forward it to Splunk HEC, syslog (CEF or RFC5424), or generic HTTP from an in-app wizard; worklist findings push to owner Slack channels.
Turn findings into action. CipherFlag EE ranks what to migrate first by data lifetime (Microsoft Purview HNDL) and internet exposure (Prisma Cloud or Wiz), not just by certificate expiry, then sequences the work through blast radius, Chain Posture, and post-quantum readiness as CNSA 2.0 deadlines approach. Policies open Jira or ServiceNow tickets for the owning team and sync their status back, and every waiver lands in a governance register with a reason and an expiry.
Six capabilities shipped since this page last changed: the NIST post-quantum standards as compliance frameworks, an auditable rules register, policy-driven ticketing, Wiz alongside Prisma Cloud, MCP over HTTP, and a governance register built for the board.
FIPS 203, 204, and 205 — ML-KEM, ML-DSA, and SLH-DSA — are now compliance frameworks in their own right, for eight in total. Every asset shows its CNSA 2.0 use-case class and milestone clock and its place on the NIST IR 8547 deprecation timeline (labelled draft), in the app, in a standards-timeline report, and in the evidence pack. CNSA 2.0 now passes only level-5 parameter sets or LMS/XMSS.
Every scoring and detection rule is visible. Admins can disable a rule, override its severity, scope it by path, or change its deduction — each change needs a justification and lands in append-only history and the audit log. Reports and CBOMs record the ruleset that scored them and say so when it was modified.
Policies open Jira and ServiceNow tickets from the worklist by severity, deadline, team, or asset type, with a preview and run-now before anything is sent. Status flows back through verified webhooks, and each asset-and-rule pair maps to one ticket, never a duplicate.
CNAPP enrichment now covers Wiz as well as Prisma Cloud: internet exposure, effective permissions, secrets on disk, attack paths, and IaC findings, linked to the crypto assets they touch. Absence of a CNAPP signal is never treated as evidence of safety.
Connect Claude Code, Cursor, or any MCP client straight to your deployment's /api/v1/mcp/rpc endpoint with a scoped bearer token — no binary to install. All 55 tools, the same preview-and-confirm gates on every write, and the same network limits.
One board-visible list of every waiver, accepted risk, and exception, each with a mandatory reason and expiry and the framework status underneath it. Download it as CSV, and find it inside every evidence pack.
CipherFlag EE ships a native Model Context Protocol server — cipherflag-mcp — exposing 55 tools over your live inventory. Point Claude, or any MCP-capable agent, at your own deployment — through the local binary or directly over HTTP — and ask questions in plain language. The agent queries your data directly; nothing is uploaded anywhere to make that work.
Certificates, SSH keys, protocol endpoints, and crypto libraries — filtered by algorithm, issuer, owner, environment, posture, grade, or expiry, with faceted drill-down.
Readiness rollups per framework, ranked remediation tasks, dispositions and expiring waivers, and the ordered migration-wave plan with cross-wave consequences.
Downstream impact if an asset is compromised, shared-asset host pairs, shadow and rogue CAs, and orphaned assets with no owner sighting.
Per-framework pass/partial/fail rollups and per-asset violations across NIST 800-131A, PCI DSS 4.0, FIPS 140-3, CNSA 2.0, NIS2, and FIPS 203/204/205 — computed live, with the effective detection rules one call away.
Which asset classes your sources can structurally see, which connectors are stale or failing, dev-vs-prod config drift, and whether a renewal actually propagated.
Resolve the ownership chain for any asset, stamp owners and environments, and open or list remediation tickets in ServiceNow or Jira.
Every registered report — HNDL exposure with Mosca-gap ranking, expiry, burndown, inventory, domain, CA, compliance overview — with the same filters the web view uses.
Per-signal Purview coverage (how many assets carry each label, how many are host-linked, which are mapped to a horizon) and CNAPP-labelled internet-exposed PQC assets from Prisma Cloud or Wiz.
“What's left for CNSA 2.0, who owns it, and what breaks if we rotate the top item first?”
→ pqc_worklist · owner_resolve · blast_radius · report_view · exposed_pqc_assets · create_tickets
Cryptographic inventory is the most sensitive asset list a security team holds — it is a literal map of what breaks if compromised. So CipherFlag treats AI as an option you switch on, not an architecture you inherit.
Every grade, finding, compliance verdict, and CBOM is produced deterministically. The 49-rule scoring engine, the compliance evaluator, and CBOM export are rule-based and reproducible. No model is involved in any of them, and most deployments run with AI switched off entirely.
AI enrichment ships disabled. Turning it on is a deliberate, licensed configuration change — never a default, never implicit.
Point enrichment at a local open-weight model — Ollama, vLLM, llama.cpp, LM Studio, or any OpenAI-compatible endpoint — and no cryptographic data ever leaves your infrastructure. Or use a commercial API under your own key. Cyber Flag operates no inference service and never proxies your data.
Enrichment applies only to source-repository and container-image finding triage. It never produces a grade, a compliance verdict, or CBOM contents.
A byte-range redactor sits on the only code path between detection and prompt assembly. Key material is replaced with [REDACTED-<TYPE>-<hash>] markers before any bytes reach a model — enforced by test, not by convention.
Every response passes exploit-content scanning, a no-leak check that original key material has not been echoed back, and strict-JSON schema validation before it can become a finding.
Per-scan, per-day, and per-month spend ceilings, with a full token and cost ledger for every call. No surprise bills, and a complete audit trail of what was asked.
What a regulated or air-gapped deployment needs to install, recover, sign in, and prove what happened.
cipherflag bundle packs the binary, a checksummed manifest, and every container image into one file. Setup detects it and verifies each SHA-256 before anything runs. Deploy on Docker or natively on Linux with systemd.
Create, verify, and restore backups, with optional encryption. A restore drill writes an Ed25519-signed, tamper-evident record with the measured recovery time, and backup freshness shows on the health endpoint.
OIDC single sign-on that verifies the identity provider's MFA, native TOTP and WebAuthn/FIDO2 security keys, an SSO-only mode with governed break-glass accounts, and server-side sessions you can revoke.
Connector credentials point to environment variables, files, HashiCorp Vault, Kubernetes, AWS Secrets Manager, or GCP Secret Manager. They are never stored in the database or written back to config in plaintext.
Every authorization decision, admin action, login, and MFA event is a hash-chained row, sealed in segments; admins verify the whole chain with one call. A separate security audit log is mandatory and cannot be switched off.
TLS to PostgreSQL in every shipped configuration, non-root containers, account lockout that never reveals whether an account exists, and CSV exports protected against formula injection.
Start free with the open-source Community Edition, a post-quantum inventory and signed CBOM toolkit. Step up to Enterprise for full-fleet discovery, risk prioritization, post-quantum program management, and the full compliance set.
| Capability | CE — Free (Apache 2.0) | EE — Enterprise |
|---|---|---|
| Asset types | Certificates · SSH keys · libraries · configs | + protocol endpoints |
| Health scoring | 40 rules across 4 asset types | 49 rules across 5 asset types + CNAPP |
| Detection Rules register | — | Tunable with justification · disclosed on every report |
| Host & endpoint discovery | osquery, Defender, SentinelOne, Tanium, Absolute · trust-store scan | + FleetDM, Velociraptor, CrowdStrike Falcon, Falcon for IT, Forescout, Rapid7 |
| Cloud / KMS | — | AWS, Azure, Entra, Azure Key Vault |
| Source / Git discovery | — | ✓ |
| Container image scanning | — | OCI registry + binary crypto, JCEKS, DER, PGP, secrets-in-config |
| Network | Certificate Transparency | + Zeek passive TLS, Forescout eyeSight, Splunk (PAN TLS), active TLS scan |
| Directory / PKI / DDI | Netwrix AD CS | + Defender for Identity, Infoblox, BlueCat, Saviynt |
| CNAPP / data sensitivity | — | Prisma Cloud, Wiz, Microsoft Purview |
| Host mapping | ✓ | + ownership and environment attribution |
| PKI explorer | 3D PKI Constellation | + host-dependency blast radius, Chain Posture |
| Risk prioritization | — | Blast radius · exposure-aware ranking |
| Compliance frameworks | NIST 800-131A · FIPS 140-3 · CNSA 2.0 · NIS2 | + PCI DSS 4.0 · FIPS 203 · FIPS 204 · FIPS 205 |
| Post-quantum readiness | Per-asset classification | + dispositions, waivers, migration waves, Purview HNDL ranking, governance register |
| CBOM export (CycloneDX v1.6) | Signed · whole estate or a filtered scope | + application and repository scopes, evidence pack, OMB M-23-02 export |
| CBOM delivery | File · HTTP · S3 · Splunk HEC · Syslog | ✓ |
| Venafi export | TPP + Cloud push | TPP + Cloud push |
| MCP server (AI agent interface) | — | 55 tools · 46 read, 9 gated writes · binary or HTTP |
| Optional AI enrichment | — | Off by default · local or BYO-key model |
| Audit / SIEM | — | Hash-chained log · Splunk / syslog / HTTP · Slack |
| Ticketing (ServiceNow, Jira) | — | Policy-driven · two-way status sync |
| Auth | Local accounts · admin/viewer roles | + OIDC SSO, TOTP and WebAuthn MFA, SSO-only mode |
| Deployment | Docker Compose | Docker, native Linux (systemd), air-gap bundle |
| Support | Community | Commercial SLA |
| Price | Free | Contact for pricing |
CipherFlag CE is the open-source core: a post-quantum migration inventory and signed CycloneDX 1.6 CBOM toolkit. It finds certificates, SSH keys, crypto libraries, and configs through osquery, endpoint connectors, and Certificate Transparency, grades them against 40 rules, evaluates four compliance frameworks, and runs from a single docker compose up.
$ git clone https://github.com/net4n6-dev/cipherflag.git && cd cipherflag && docker compose up -d
Bring your toughest crypto-visibility question. We'll show you what we find.