For developers
Run the Free source preview locally
Build a reviewed, history-free source archive and evaluate Free discovery against a real repository without uploading source.
Review the PreviewCipherMap is a local CLI for source-layer cryptographic discovery, triage, and evidence. It helps teams understand one important layer of a broader post-quantum inventory.
Invitation-only Free source preview
Approved recipients receive a reviewed, history-free source archive and a checksum-bound build guide after accepting the Preview terms. Build locally—no unsigned native binary or repository history is distributed.
For developers
Build a reviewed, history-free source archive and evaluate Free discovery against a real repository without uploading source.
Review the PreviewFor evaluators
See illustrative output, artifact boundaries, methodology, and known limitations without submitting contact information.
Inspect sample evidenceFor organizations
Define the source-inventory question, representative repositories, success criteria, and decision path with the founder.
See the assessment pathBroad Multi-Language Scanning Engine
Discover risk and preview supported proposals free, produce readiness evidence with Tier A, and use Tier B integration and fleet workflows — without handing your source code to a third party.
Flags RSA, ECDSA, DH, and broken hashes like MD5 in source code. When network enrichment is enabled, it can also query OSV for known-vulnerable dependencies in supported lockfiles and manifests.
Tier A's --target cnsa-2.0 profile adds NSA Commercial National Security Algorithm Suite 2.0 policy findings — SHA-3/SHAKE, SLH-DSA, and XMSS^MT exclusions — on top of the free base ruleset.
Serialize detected cryptographic assets into a machine-readable Cryptographic Bill of Materials with real cryptoProperties. SPDX 2.3 and OpenVEX export too.
Run scan --agility to score how tightly primitives are coupled: hardcoded algorithm literals and direct calls versus decoupled wrappers, file by file.
Flags multi-tree XMSS (XMSS^MT) usage and LMS/XMSS signatures used without visible state tracking.
Flags non-cryptographic PRNGs and static or predictable seeds where keys, nonces, salts, and tokens are generated.
Preview supported Go, Python and Node ESM proposals with fix --dry-run. Production source publication is disabled until the isolated Gate 2 transaction and recovery evidence are promoted.
The --fail-on CI gate is free. Tier B adds PR comments and annotations for GitHub, GitLab, Azure DevOps and Bitbucket Cloud. Live-provider qualification remains pending.
Scanning runs on your machine and never uploads source code. The developer-preview workflow requires --offline and --no-telemetry; optional enrichment and integrations remain separate, explicit paths.
The CLI functionality below is implemented and test-backed. Commercial activation, signed downloads, native Windows qualification and live-provider evidence remain separate release gates.
Approved users receive a checksum-bound, history-free source archive and build guide while signed native downloads remain gated.