Find cryptography onceKeep it from drifting
Build a versioned cryptographic inventory. Add evidence, ownership, migration dependencies, policy gates, and pull-request drift control—without uploading source code.
Cryptographic discovery
Scan source, dependencies, containers, configuration, and authorized TLS endpoints without uploading source code.
- Deterministic asset IDs
- Redacted evidence
- Offline rule bundle
CBOM & evidence
Generate CycloneDX 1.6 inventory with confidence and exact locations.
Migration work
Connect every asset to an owner, dependency, deadline, and test plan.
PR drift control
Diff every pull request and block only newly introduced violations.
Policy as code
Version policy gates, severity, exceptions, and baseline behavior.
Ownership routing
Map repositories and findings to teams with attributable decisions.
Open exports
Keep evidence portable with CBOM, SARIF, JSON, and CSV.
One workspace for evidence, ownership, migration, and regression control.
Northstar Checkout
Inventory
Inventory
12 assetsMigration
7 activeCI drift
1 newEvidence
24 exportsLocal-first scanner
Look at code without sending code.
The scanner normalizes fingerprints, redacted evidence, and open-standard output on your machine. Upload only the records you choose.
$ cipherdrift scan . --output cbom.json
✓ indexed 18,402 files
✓ parsed source & configuration
✓ resolved dependency evidence
✓ inspected authorized TLS targets
12 cryptographic assets
5 quantum-vulnerable
2 deprecated
1 unknown
✓ wrote CycloneDX 1.6 → cbom.json
✓ wrote SARIF 2.1.0 → results.sarifEvidence stays portable
Open formats in. Open formats out.
Cryptographic inventory should remain inspectable and usable outside the platform. Export the evidence, replay a policy locally, or retain a signed scan ledger.
Read the security modelVersioned CBOM
Code scanning results
Portable analysis
Attributable history
Works across the stack you already run