Know where cryptography lives, and who owns it.
Qestrel brings fragmented cryptographic metadata into one inventory, so your team can see algorithms, keys, certificates, dependencies, systems and owners before migration begins.
One row per finding, with an owner and a deadline.
Every algorithm, key and certificate becomes a record your team can act on: where it was found, which tool reported it, who owns the fix, and how long it can be relied on.
| Algorithm | Found in | Source | Owner | Safe until | Status |
|---|---|---|---|---|---|
| RSA-2048 | Public TLS certificates | ADCS | Internal PKI team | 2030 | Quantum-vulnerable |
| ECC P-256 | API gateway keys | AWS | Platform team | 2030 | Quantum-vulnerable |
| 3DES | Payments middleware | CipherTrust | Vendor | 2023 | Replace now |
| SHA-1 | Code-signing certificates | ADCS | Vendor | 2017 | Replace now |
| MD5 | Legacy internal application | Azure Key Vault | Application owner | 2004 | Replace now |
Sample records from a demo estate. Column set shown is simplified.
Discovery is only useful when it leads to action.
Normalised evidence
Consolidate cryptographic findings from existing security and cloud tooling into a consistent model: one schema, whatever the source.
Dependency context
Connect cryptography to the systems, applications, data and vendors that depend on it, so a finding is never just a string in a scan result.
Clear ownership
Separate supplier-controlled fixes from internal work and identify gaps in accountability before they become gaps in the migration.
Turn unknown exposure into measurable scope.
Where are RSA, ECC and vulnerable legacy algorithms still in use?
Every finding is tied to the certificate, key or system where it was observed and the tool that reported it, so exposure is located, not estimated.
Which systems protect long-lived or sensitive information?
Data sensitivity and shelf life sit alongside each finding, so the systems guarding decade-long secrets rise to the top of the queue.
Which remediation actions depend on a vendor roadmap?
Ownership is recorded per finding, separating fixes that wait on a supplier's post-quantum timeline from work your own teams control.
What evidence can be given to leadership, auditors and regulators?
The inventory exports as evidence: coverage, exposure and remediation progress in a form risk committees and assurance teams accept.
Start with the inventory.
The inventory is the foundation every later phase depends on. See how Qestrel builds yours from the tools you already run, with no agents and read-only access.
