Cryptographic inventory

Know where cryptography lives, and who owns it.

Qestrel brings fragmented cryptographic metadata into one inventory, so your team can see algorithms, keys, certificates, dependencies, systems and owners before migration begins.

qestrel · inventory build · demo estate
qestrel connect --sources adcs,aws,azure-kv,ciphertrust
✓ 4 sources connected · read-only · metadata only
qestrel scan
› normalising findings .......... 67,800 records
› quantum-vulnerable ............ 53,872 flagged
› assigning ownership ........... vendor 9,871 · internal mapped
› oldest safe-until ............. 2004 [replace now]
✓ inventory ready · one estate view
Sample output

One row per finding, with an owner and a deadline.

Every algorithm, key and certificate becomes a record your team can act on: where it was found, which tool reported it, who owns the fix, and how long it can be relied on.

AlgorithmFound inSourceOwnerSafe untilStatus
RSA-2048Public TLS certificatesADCSInternal PKI team2030Quantum-vulnerable
ECC P-256API gateway keysAWSPlatform team2030Quantum-vulnerable
3DESPayments middlewareCipherTrustVendor2023Replace now
SHA-1Code-signing certificatesADCSVendor2017Replace now
MD5Legacy internal applicationAzure Key VaultApplication owner2004Replace now

Sample records from a demo estate. Column set shown is simplified.

A usable inventory

Discovery is only useful when it leads to action.

01

Normalised evidence

Consolidate cryptographic findings from existing security and cloud tooling into a consistent model: one schema, whatever the source.

02

Dependency context

Connect cryptography to the systems, applications, data and vendors that depend on it, so a finding is never just a string in a scan result.

03

Clear ownership

Separate supplier-controlled fixes from internal work and identify gaps in accountability before they become gaps in the migration.

What you can answer

Turn unknown exposure into measurable scope.

Q.01

Where are RSA, ECC and vulnerable legacy algorithms still in use?

Every finding is tied to the certificate, key or system where it was observed and the tool that reported it, so exposure is located, not estimated.

Q.02

Which systems protect long-lived or sensitive information?

Data sensitivity and shelf life sit alongside each finding, so the systems guarding decade-long secrets rise to the top of the queue.

Q.03

Which remediation actions depend on a vendor roadmap?

Ownership is recorded per finding, separating fixes that wait on a supplier's post-quantum timeline from work your own teams control.

Q.04

What evidence can be given to leadership, auditors and regulators?

The inventory exports as evidence: coverage, exposure and remediation progress in a form risk committees and assurance teams accept.

Get started

Start with the inventory.

The inventory is the foundation every later phase depends on. See how Qestrel builds yours from the tools you already run, with no agents and read-only access.