CipherFlag EE 4.9.5

Every key, certificate, and cipher — in your sights

CipherFlag EE discovers cryptography across every endpoint, cloud, repo, and network segment, scores it against 49 rules, ranks migration by data lifetime and exposure, and proves compliance — built for the post-quantum transition.

Built to evidence NIST 800-131A PCI DSS 4.0 FIPS 140-3 CNSA 2.0 EU NIS2
The CipherFlag EE Lifecycle
Discover. Score. Comply. Remediate.

One program for cryptographic preparedness — from finding every asset to proving you are ready for the post-quantum transition.

01

Discover

A single, unified inventory of every cryptographic asset across endpoint, cloud, source, container, network, directory, CNAPP, and data-sensitivity sources — with host identity resolution and application tagging, so each asset is mapped to the host and application that owns it.

Endpoint
osquery / FleetDM Available Velociraptor Available Microsoft Defender Available CrowdStrike Falcon Available CrowdStrike Falcon for IT Available SentinelOne Available Tanium Available Absolute Available Forescout Available Rapid7 Available
Cloud / KMS
AWS Available Azure Available Microsoft Entra Available Azure Key Vault Available
Source, CI & container
Git Available OCI registry + binary crypto Available
Network
Zeek passive TLS Available Forescout eyeSight Available Splunk (Palo Alto TLS) Available Active TLS scanning Available Certificate Transparency Available
Directory / PKI / DDI
Netwrix (AD CS) Available Defender for Identity Available Infoblox Available BlueCat Available Saviynt Available
CNAPP / data sensitivity
Prisma Cloud Available Microsoft Purview Available
operator
key
02

Score

Every asset is graded A+ to F against 49 rules across five asset types plus CNAPP enrichment — expiration, key strength, signature algorithms, chain trust, protocol versions, library CVEs, SSH hygiene, crypto-agility, and linked Prisma Cloud exposure and IaC findings. Each finding carries severity, category, point deduction, and remediation guidance. Scoring is deterministic; CNAPP deductions fire only when a CNAPP signal is linked.

A+ 95–100 A 90–94 B 80–89 C 70–79 D 60–69 F <60
Certificates · 24 rules SSH · 8 rules Libraries · 5 rules Protocols · 6 rules Configs · 4 rules CNAPP · 2 rules
03

Comply

Map findings to the controls auditors ask about, export a complete cryptographic bill of materials, and forward a hash-chained authorization log to the SIEM you already run.

NIST 800-131A PCI DSS 4.0 FIPS 140-3 CNSA 2.0 EU NIS2

CBOM export — generate a CycloneDX v1.6 cryptographic bill of materials for any scope, with per-component rule-engine provenance, ready to hand to auditors or feed downstream tooling.

Hash-chained audit + SIEM — every authorization decision, admin action, login, MFA event and governance write is a durable, queryable, hash-chained row. Forward it to Splunk HEC, syslog (CEF or RFC5424), or generic HTTP from an in-app wizard; worklist findings push to owner Slack channels.

04

Remediate

Turn findings into action. CipherFlag EE ranks what to migrate first by data lifetime (Microsoft Purview HNDL) and internet exposure (Prisma Cloud CNAPP), not just by certificate expiry, then sequences the work through blast radius, Chain Posture, and post-quantum readiness as CNSA 2.0 deadlines approach.

PQC readiness scoring Purview data-lifetime ranking Prisma exposed-PQC assets Blast-radius prioritization Chain Posture Crypto-agility tracking
Now in CipherFlag EE 4.9.5
Ranked by data. Proven by the chain. Addressable by agents.

Six capabilities that landed since the last public page: sensitivity-ranked migration, CNAPP exposure, Chain Posture, broader at-rest detection, a hash-chained SIEM audit log, and MCP access to the Mosca-gap report.

01

Purview → HNDL

Rank post-quantum migration by how long the data stays sensitive, not by which certificate expires next. Microsoft Purview classifications and labels map to retention horizons; the HNDL lens flags no-signal coverage gaps and label-vs-classification mismatches. Suggestions never auto-apply.

02

Prisma Cloud CNAPP

Enrich crypto posture with CSPM exposure, CIEM effective permissions, secrets on disk, attack-path hosts, and IaC findings. Internet-exposed PQC assets surface as their own cadence card. Absence of a CNAPP signal is never treated as evidence of safety.

03

Chain Posture

A scale-invariant conserved flow over trust origin, chain depth, and leaf grade — rooted, partial, self-signed, or unlinked. Replaces the old chain-flow sankey so an estate of thousands of CAs still reads as one picture, with every count clicking through to the list that proves it.

At-rest scanner breadth

Container and source scans now catch JCEKS keystores, bare-DER private keys, standalone PGP armor, hardcoded vendor credentials and JWTs, and weak algorithms sitting in plain config files — fingerprinting matches, never storing the secret.

05

Hash-chained audit + SIEM

Authorization decisions, admin actions, logins, MFA events and governance writes land as a durable, hash-chained log. Forward it to Splunk HEC, syslog, or HTTP from an in-app wizard; push worklist findings to owner Slack channels. Queryable, admin-gated, never a rotating file you cannot prove.

06

MCP reports and Mosca gap

Agents can now read the same narrative a human opens: report_catalog and report_view expose the HNDL Mosca-gap ranking — data lifetime vs migration time vs CRQC runway, worst-first — plus sensitivity_coverage so an empty result is never mistaken for safety.

See It In Action
Inside the platform
CipherFlag EE PKI Constellation
CipherFlag EE crypto posture dashboard
CipherFlag EE compliance report
CipherFlag EE applications view
Your crypto estate, addressable by AI agents

CipherFlag EE ships a native Model Context Protocol servercipherflag-mcp — exposing 52 tools over your live inventory. Point Claude, or any MCP-capable agent, at your own deployment and ask questions in plain language. The agent queries your data directly; nothing is uploaded anywhere to make that work.

Inventory & Search

Certificates, SSH keys, protocol endpoints, and crypto libraries — filtered by algorithm, issuer, owner, environment, posture, grade, or expiry, with faceted drill-down.

PQC Program

Readiness rollups per framework, ranked remediation tasks, dispositions and expiring waivers, and the ordered migration-wave plan with cross-wave consequences.

Risk & Blast Radius

Downstream impact if an asset is compromised, shared-asset host pairs, shadow and rogue CAs, and orphaned assets with no owner sighting.

Compliance

Per-framework pass/partial/fail rollups and per-asset violations across NIST 800-131A, PCI DSS 4.0, FIPS 140-3, CNSA 2.0, and NIS2 — computed live.

Coverage & Drift

Which asset classes your sources can structurally see, which connectors are stale or failing, dev-vs-prod config drift, and whether a renewal actually propagated.

Ownership & Action

Resolve the ownership chain for any asset, stamp owners and environments, and open remediation tickets in ServiceNow or Jira.

Reports & Mosca gap

Every registered report — HNDL exposure with Mosca-gap ranking, expiry, burndown, inventory, domain, CA, compliance overview — with the same filters the web view uses.

Sensitivity & exposure

Per-signal Purview coverage (how many assets carry each label, how many are host-linked, which are mapped to a horizon) and Prisma-labelled internet-exposed PQC assets.

“What's left for CNSA 2.0, who owns it, and what breaks if we rotate the top item first?”

→ pqc_worklist · owner_resolve · blast_radius · report_view · exposed_pqc_assets · create_tickets

43 read-only tools 9 write tools, all gated Preview + confirm token on compliance-affecting writes Entra device-code OAuth or scoped agent token External side effects require a provisioned human user
AI, on your terms
Deterministic by default. Local by choice.

Cryptographic inventory is the most sensitive asset list a security team holds — it is a literal map of what breaks if compromised. So CipherFlag treats AI as an option you switch on, not an architecture you inherit.

Every grade, finding, compliance verdict, and CBOM is produced deterministically. The 49-rule scoring engine, the compliance evaluator, and CBOM export are rule-based and reproducible. No model is involved in any of them, and most deployments run with AI switched off entirely.

Off by default

AI enrichment ships disabled. Turning it on is a deliberate, licensed configuration change — never a default, never implicit.

Run it entirely on your own network

Point enrichment at a local open-weight model — Ollama, vLLM, llama.cpp, LM Studio, or any OpenAI-compatible endpoint — and no cryptographic data ever leaves your infrastructure. Or use a commercial API under your own key. Cyber Flag operates no inference service and never proxies your data.

Narrow scope

Enrichment applies only to source-repository and container-image finding triage. It never produces a grade, a compliance verdict, or CBOM contents.

Redacted before it is sent

A byte-range redactor sits on the only code path between detection and prompt assembly. Key material is replaced with [REDACTED-<TYPE>-<hash>] markers before any bytes reach a model — enforced by test, not by convention.

Validated before it counts

Every response passes exploit-content scanning, a no-leak check that original key material has not been echoed back, and strict-JSON schema validation before it can become a finding.

Capped and ledgered

Per-scan, per-day, and per-month spend ceilings, with a full token and cost ledger for every call. No surprise bills, and a complete audit trail of what was asked.

Editions
Community vs Enterprise

Start free with the open-source Community Edition. Step up to Enterprise for full-fleet discovery, multi-asset scoring, and compliance.

CapabilityCE — Free (Apache 2.0)EE — Enterprise
Passive TLS discovery (Zeek)
Asset typesCertificatesCerts · keys · SSH · libraries · protocols · configs
Health scoring24 certificate rules49 rules across 5 asset types + CNAPP
PKI ExplorerForce-directed graph+ 3D constellation, blast-radius, Chain Posture
Endpoint discoveryosquery/FleetDM, Velociraptor, Defender, CrowdStrike Falcon, Falcon for IT, SentinelOne, Tanium, Absolute, Forescout, Rapid7
Cloud / KMSAWS, Azure, Entra, Azure Key Vault
Source / Git discovery
Container image scanningOCI registry + binary crypto, JCEKS, DER, PGP, secrets-in-config
NetworkZeek passive TLSZeek, Forescout eyeSight, Splunk (PAN TLS), active TLS scan, Certificate Transparency
Directory / PKI / DDINetwrix AD CS, Defender for Identity, Infoblox, BlueCat, Saviynt
CNAPP / data sensitivityPrisma Cloud, Microsoft Purview
Host mapping
Application tagging
Venafi exportTPP + Cloud push+ TPP policy-folder management, Thales CipherTrust
Compliance frameworksNIST 800-131A · PCI DSS 4.0 · FIPS 140-3 · CNSA 2.0 · NIS2
CBOM export (CycloneDX v1.6)
PQC program managementDispositions, waivers, migration waves, Purview HNDL ranking
MCP server (AI agent interface)52 tools · 43 read, 9 gated writes
Optional AI enrichmentOff by default · local or BYO-key model
Audit / SIEMHash-chained log · Splunk / syslog / HTTP · Slack
Ticketing (ServiceNow, Jira)
AuthJWT + RBAC+ SSO / SAML, OIDC, PIV/CAC
SupportCommunityCommercial SLA
PriceFreeContact for pricing
Open Source · Apache 2.0
Start free with the Community Edition

CipherFlag CE is the open-source core: passive TLS discovery via Zeek, 24-rule certificate health scoring, the interactive PKI Explorer, and Venafi export — all from a single docker-compose up.

$ curl -fsSL https://raw.githubusercontent.com/net4n6-dev/cipherflag/main/scripts/install.sh | sh

See CipherFlag EE against your environment

Bring your toughest crypto-visibility question. We'll show you what we find.

Request a Demo See it live