CipherFlag EE 4.10.9

Every key, certificate, and cipher in your sights

CipherFlag EE discovers cryptography across every endpoint, cloud, repo, and network segment, scores it against 49 rules, ranks migration by data lifetime and exposure, and proves compliance — built for the post-quantum transition.

Built to evidence NIST 800-131A PCI DSS 4.0 FIPS 140-3 CNSA 2.0 EU NIS2 FIPS 203 · 204 · 205
The CipherFlag EE Lifecycle
Discover. Score. Comply. Remediate.

One program for cryptographic preparedness — from finding every asset to proving you are ready for the post-quantum transition.

01

Discover

A single, unified inventory of every cryptographic asset across endpoint, cloud, source, container, network, directory, CNAPP, and data-sensitivity sources — with host identity resolution and application tagging, so each asset is mapped to the host and application that owns it.

Endpoint
osquery / FleetDM Available Velociraptor Available Microsoft Defender Available CrowdStrike Falcon Available CrowdStrike Falcon for IT Available SentinelOne Available Tanium Available Absolute Available Forescout Available Rapid7 Available
Cloud / KMS
AWS Available Azure Available Microsoft Entra Available Azure Key Vault Available
Source, CI & container
Git Available OCI registry + binary crypto Available
Network
Zeek passive TLS Available Forescout eyeSight Available Splunk (Palo Alto TLS) Available Active TLS scanning Available Certificate Transparency Available
Directory / PKI / DDI
Netwrix (AD CS) Available Defender for Identity Available Infoblox Available BlueCat Available Saviynt Available
CNAPP / data sensitivity
Prisma Cloud Available Wiz Available Microsoft Purview Available
operator
key
02

Score

Every asset is graded A+ to F against 49 rules across five asset types plus CNAPP enrichment — expiration, key strength, signature algorithms, chain trust, protocol versions, library CVEs, SSH hygiene, crypto-agility, and linked Prisma Cloud or Wiz exposure and IaC findings. Each finding carries severity, category, point deduction, and remediation guidance. Scoring is deterministic; CNAPP deductions fire only when a CNAPP signal is linked. Every rule is listed in the Detection Rules register, where admins can tune severity, scope, or deduction with a recorded justification — and any report or CBOM scored under a modified ruleset says so.

A+ 95–100 A 85–94 B 70–84 C 50–69 D 20–49 F <20
Certificates · 24 rules SSH · 8 rules Libraries · 5 rules Protocols · 6 rules Configs · 4 rules CNAPP · 2 rules
03

Comply

Map findings to the controls auditors ask about — including the NIST post-quantum standards — export a complete cryptographic bill of materials, and forward a hash-chained authorization log to the SIEM you already run.

NIST 800-131A PCI DSS 4.0 FIPS 140-3 CNSA 2.0 EU NIS2 FIPS 203 FIPS 204 FIPS 205

Standards timeline — every asset shows its CNSA 2.0 use-case class and milestone clock, and where it sits on the NIST IR 8547 deprecation timeline (a draft, and labelled as one).

CBOM export — generate a CycloneDX v1.6 cryptographic bill of materials for any scope, with per-component rule-engine provenance and an optional Ed25519 signature from a standard OpenSSL, HSM, or KMS key, ready to hand to auditors or feed downstream tooling.

Evidence pack — a deterministic ZIP of inventory, findings, per-framework compliance, the standards timeline, and the waiver register, with a signed SHA-256 manifest; plus OMB M-23-02 inventory exports for federal agencies.

Hash-chained audit + SIEM — every authorization decision, admin action, login, MFA event and governance write is a durable, queryable, hash-chained row. Forward it to Splunk HEC, syslog (CEF or RFC5424), or generic HTTP from an in-app wizard; worklist findings push to owner Slack channels.

04

Remediate

Turn findings into action. CipherFlag EE ranks what to migrate first by data lifetime (Microsoft Purview HNDL) and internet exposure (Prisma Cloud or Wiz), not just by certificate expiry, then sequences the work through blast radius, Chain Posture, and post-quantum readiness as CNSA 2.0 deadlines approach. Policies open Jira or ServiceNow tickets for the owning team and sync their status back, and every waiver lands in a governance register with a reason and an expiry.

PQC readiness scoring Purview data-lifetime ranking CNAPP exposed-PQC assets Jira / ServiceNow two-way sync Blast-radius prioritization Chain Posture Crypto-agility tracking
Now in CipherFlag EE 4.10
Graded against the standards. Tuned on the record. Closed in the ticket.

Six capabilities shipped since this page last changed: the NIST post-quantum standards as compliance frameworks, an auditable rules register, policy-driven ticketing, Wiz alongside Prisma Cloud, MCP over HTTP, and a governance register built for the board.

01

Standards-mapped compliance

FIPS 203, 204, and 205 — ML-KEM, ML-DSA, and SLH-DSA — are now compliance frameworks in their own right, for eight in total. Every asset shows its CNSA 2.0 use-case class and milestone clock and its place on the NIST IR 8547 deprecation timeline (labelled draft), in the app, in a standards-timeline report, and in the evidence pack. CNSA 2.0 now passes only level-5 parameter sets or LMS/XMSS.

02

Detection Rules register

Every scoring and detection rule is visible. Admins can disable a rule, override its severity, scope it by path, or change its deduction — each change needs a justification and lands in append-only history and the audit log. Reports and CBOMs record the ruleset that scored them and say so when it was modified.

03

Closed-loop ticketing

Policies open Jira and ServiceNow tickets from the worklist by severity, deadline, team, or asset type, with a preview and run-now before anything is sent. Status flows back through verified webhooks, and each asset-and-rule pair maps to one ticket, never a duplicate.

04

Wiz joins Prisma Cloud

CNAPP enrichment now covers Wiz as well as Prisma Cloud: internet exposure, effective permissions, secrets on disk, attack paths, and IaC findings, linked to the crypto assets they touch. Absence of a CNAPP signal is never treated as evidence of safety.

MCP over HTTP

Connect Claude Code, Cursor, or any MCP client straight to your deployment's /api/v1/mcp/rpc endpoint with a scoped bearer token — no binary to install. All 55 tools, the same preview-and-confirm gates on every write, and the same network limits.

06

Governance register

One board-visible list of every waiver, accepted risk, and exception, each with a mandatory reason and expiry and the framework status underneath it. Download it as CSV, and find it inside every evidence pack.

See It In Action
Inside the platform
CipherFlag EE PKI Constellation
CipherFlag EE crypto posture dashboard
CipherFlag EE compliance report
CipherFlag EE applications view
Your crypto estate, addressable by AI agents

CipherFlag EE ships a native Model Context Protocol server — cipherflag-mcp — exposing 55 tools over your live inventory. Point Claude, or any MCP-capable agent, at your own deployment — through the local binary or directly over HTTP — and ask questions in plain language. The agent queries your data directly; nothing is uploaded anywhere to make that work.

Inventory & Search

Certificates, SSH keys, protocol endpoints, and crypto libraries — filtered by algorithm, issuer, owner, environment, posture, grade, or expiry, with faceted drill-down.

PQC Program

Readiness rollups per framework, ranked remediation tasks, dispositions and expiring waivers, and the ordered migration-wave plan with cross-wave consequences.

Risk & Blast Radius

Downstream impact if an asset is compromised, shared-asset host pairs, shadow and rogue CAs, and orphaned assets with no owner sighting.

Compliance

Per-framework pass/partial/fail rollups and per-asset violations across NIST 800-131A, PCI DSS 4.0, FIPS 140-3, CNSA 2.0, NIS2, and FIPS 203/204/205 — computed live, with the effective detection rules one call away.

Coverage & Drift

Which asset classes your sources can structurally see, which connectors are stale or failing, dev-vs-prod config drift, and whether a renewal actually propagated.

Ownership & Action

Resolve the ownership chain for any asset, stamp owners and environments, and open or list remediation tickets in ServiceNow or Jira.

Reports & Mosca gap

Every registered report — HNDL exposure with Mosca-gap ranking, expiry, burndown, inventory, domain, CA, compliance overview — with the same filters the web view uses.

Sensitivity & exposure

Per-signal Purview coverage (how many assets carry each label, how many are host-linked, which are mapped to a horizon) and CNAPP-labelled internet-exposed PQC assets from Prisma Cloud or Wiz.

“What's left for CNSA 2.0, who owns it, and what breaks if we rotate the top item first?”

→ pqc_worklist · owner_resolve · blast_radius · report_view · exposed_pqc_assets · create_tickets

46 read-only tools 9 write tools, all gated Preview + confirm token on compliance-affecting writes Entra device-code OAuth or scoped agent token HTTP transport is bearer-only, with network limits intact External side effects require a provisioned human user
AI, on your terms
Deterministic by default. Local by choice.

Cryptographic inventory is the most sensitive asset list a security team holds — it is a literal map of what breaks if compromised. So CipherFlag treats AI as an option you switch on, not an architecture you inherit.

Every grade, finding, compliance verdict, and CBOM is produced deterministically. The 49-rule scoring engine, the compliance evaluator, and CBOM export are rule-based and reproducible. No model is involved in any of them, and most deployments run with AI switched off entirely.

Off by default

AI enrichment ships disabled. Turning it on is a deliberate, licensed configuration change — never a default, never implicit.

Run it entirely on your own network

Point enrichment at a local open-weight model — Ollama, vLLM, llama.cpp, LM Studio, or any OpenAI-compatible endpoint — and no cryptographic data ever leaves your infrastructure. Or use a commercial API under your own key. Cyber Flag operates no inference service and never proxies your data.

Narrow scope

Enrichment applies only to source-repository and container-image finding triage. It never produces a grade, a compliance verdict, or CBOM contents.

Redacted before it is sent

A byte-range redactor sits on the only code path between detection and prompt assembly. Key material is replaced with [REDACTED-<TYPE>-<hash>] markers before any bytes reach a model — enforced by test, not by convention.

Validated before it counts

Every response passes exploit-content scanning, a no-leak check that original key material has not been echoed back, and strict-JSON schema validation before it can become a finding.

Capped and ledgered

Per-scan, per-day, and per-month spend ceilings, with a full token and cost ledger for every call. No surprise bills, and a complete audit trail of what was asked.

Runs where the network is closed. Answers when the auditor asks.

What a regulated or air-gapped deployment needs to install, recover, sign in, and prove what happened.

Air-gapped install

cipherflag bundle packs the binary, a checksummed manifest, and every container image into one file. Setup detects it and verifies each SHA-256 before anything runs. Deploy on Docker or natively on Linux with systemd.

Recovery you can prove

Create, verify, and restore backups, with optional encryption. A restore drill writes an Ed25519-signed, tamper-evident record with the measured recovery time, and backup freshness shows on the health endpoint.

Sign-in that holds up

OIDC single sign-on that verifies the identity provider's MFA, native TOTP and WebAuthn/FIDO2 security keys, an SSO-only mode with governed break-glass accounts, and server-side sessions you can revoke.

Secrets stay references

Connector credentials point to environment variables, files, HashiCorp Vault, Kubernetes, AWS Secrets Manager, or GCP Secret Manager. They are never stored in the database or written back to config in plaintext.

An audit log that proves itself

Every authorization decision, admin action, login, and MFA event is a hash-chained row, sealed in segments; admins verify the whole chain with one call. A separate security audit log is mandatory and cannot be switched off.

Hardened by default

TLS to PostgreSQL in every shipped configuration, non-root containers, account lockout that never reveals whether an account exists, and CSV exports protected against formula injection.

Editions
Community vs Enterprise

Start free with the open-source Community Edition, a post-quantum inventory and signed CBOM toolkit. Step up to Enterprise for full-fleet discovery, risk prioritization, post-quantum program management, and the full compliance set.

CapabilityCE — Free (Apache 2.0)EE — Enterprise
Asset typesCertificates · SSH keys · libraries · configs+ protocol endpoints
Health scoring40 rules across 4 asset types49 rules across 5 asset types + CNAPP
Detection Rules register—Tunable with justification · disclosed on every report
Host & endpoint discoveryosquery, Defender, SentinelOne, Tanium, Absolute · trust-store scan+ FleetDM, Velociraptor, CrowdStrike Falcon, Falcon for IT, Forescout, Rapid7
Cloud / KMS—AWS, Azure, Entra, Azure Key Vault
Source / Git discovery—✓
Container image scanning—OCI registry + binary crypto, JCEKS, DER, PGP, secrets-in-config
NetworkCertificate Transparency+ Zeek passive TLS, Forescout eyeSight, Splunk (PAN TLS), active TLS scan
Directory / PKI / DDINetwrix AD CS+ Defender for Identity, Infoblox, BlueCat, Saviynt
CNAPP / data sensitivity—Prisma Cloud, Wiz, Microsoft Purview
Host mapping✓+ ownership and environment attribution
PKI explorer3D PKI Constellation+ host-dependency blast radius, Chain Posture
Risk prioritization—Blast radius · exposure-aware ranking
Compliance frameworksNIST 800-131A · FIPS 140-3 · CNSA 2.0 · NIS2+ PCI DSS 4.0 · FIPS 203 · FIPS 204 · FIPS 205
Post-quantum readinessPer-asset classification+ dispositions, waivers, migration waves, Purview HNDL ranking, governance register
CBOM export (CycloneDX v1.6)Signed · whole estate or a filtered scope+ application and repository scopes, evidence pack, OMB M-23-02 export
CBOM deliveryFile · HTTP · S3 · Splunk HEC · Syslog✓
Venafi exportTPP + Cloud pushTPP + Cloud push
MCP server (AI agent interface)—55 tools · 46 read, 9 gated writes · binary or HTTP
Optional AI enrichment—Off by default · local or BYO-key model
Audit / SIEM—Hash-chained log · Splunk / syslog / HTTP · Slack
Ticketing (ServiceNow, Jira)—Policy-driven · two-way status sync
AuthLocal accounts · admin/viewer roles+ OIDC SSO, TOTP and WebAuthn MFA, SSO-only mode
DeploymentDocker ComposeDocker, native Linux (systemd), air-gap bundle
SupportCommunityCommercial SLA
PriceFreeContact for pricing
Open Source · Apache 2.0
Start free with the Community Edition

CipherFlag CE is the open-source core: a post-quantum migration inventory and signed CycloneDX 1.6 CBOM toolkit. It finds certificates, SSH keys, crypto libraries, and configs through osquery, endpoint connectors, and Certificate Transparency, grades them against 40 rules, evaluates four compliance frameworks, and runs from a single docker compose up.

$ git clone https://github.com/net4n6-dev/cipherflag.git && cd cipherflag && docker compose up -d

See CipherFlag EE against your environment

Bring your toughest crypto-visibility question. We'll show you what we find.

Request a Demo See it live