End-to-end service
From the first scan to the last algorithm migrated
With our own knowledge and tools we connect the whole cycle: we map every algorithm in your code, your network and your key stores, we find the cryptography missing where it should be, and we build the roadmap to the most efficient and effective transition, solid in advance against any standard.
One transition, no loose ends
Five chained phases: what one uncovers, the next one resolves.
FIG. B · THE TRANSITION PIPELINE · END TO END
The five phases, in detail
PHASE 01 · FULL SCAN
Map everything that exists
We scan domains, network ranges, key stores, repositories and CI/CD pipelines to discover every certificate, key, protocol and algorithm in use. No questionnaires or self-declarations: direct technical evidence, taken from the code and the network.
- Domains and IP:port ranges
- Static repository analysis
- Key stores and CI/CD pipelines
PHASE 02 · CBOM
An inventory that is yours
Everything is consolidated into a CBOM (Cryptography Bill of Materials) exportable in CycloneDX v1.6: the organization's complete cryptographic map, classified by risk and ready for SIEM, GRC and audit.
- CycloneDX v1.6 (ECMA-424)
- Classification by risk
- Integrates with your tools
PHASE 03 · GAPS
The weak and the missing
We point out what is already weak, what falls to a quantum computer and something almost nobody reviews: where cryptography should exist and does not. Sensitive data in the clear is a cryptographic gap too.
- Obsolete and vulnerable algorithms
- Missing cryptography
- Prioritization by real exposure
PHASE 04 · ROADMAP
The most efficient transition
With our own methodology we turn the assessment into a plan in waves: what to migrate now, what can wait and what can be solved in hybrid mode without touching the application. Realistic, traceable goals that never stop operations.
- Waves by risk and impact
- Target hybrid architecture
- Operational continuity
PHASE 05 · COMPLIANCE
Solid against any standard
The transition is aligned in advance with current deadlines and frameworks: RSA and ECC obsolescence in 2030 and prohibition in 2035 according to NIST, plus the requirements of the EU, ANSSI, BSI and financial regulators.
- NIST FIPS 203 · 204 · 205
- NIST IR 8547
- EU · ANSSI · BSI · G7
THE DIFFERENCE
The gap almost nobody scans
Everyone looks for weak cryptography. We also look for the cryptography that is not there: the unencrypted sensitive field, the internal channel in plain text, the file that travels unprotected. The CBOM does not just say what to change: it says what is missing.
Request an initial scan and receive your organization's first CBOM.
Request an initial scan