You cannot migrate what you cannot see.
CADP finds every use of cryptography across your estate, on the wire, on disk, in source and in container images, scores it for post-quantum risk, and hands you a CycloneDX inventory your auditor can read.
Deploys on one Linux server in an afternoon. Nothing you discover ever leaves your environment.
Two quantum clocks are already running.
The question every regulator now asks first, and most organisations cannot answer from anything better than a spreadsheet: where is your cryptography, and what does it protect?
Harvest now, decrypt later
Traffic recorded today is decrypted the day a cryptographically relevant quantum computer exists. Anything whose confidentiality must outlive that day is already exposed, whatever the date turns out to be.
Harvest now, forge later
Signatures and trust roots break on that same day. Software updates, certificates and identities can then be forged. Nothing needs to be captured in advance; every classical signature still in service is exposed at once.
Data lifetime + migration time > time until the machine exists, and you are already late.
Migration time is dominated by discovery. The inventory is the first deliverable, not a by-product.
Two sensors, one platform, one living inventory.
No sensor computes a verdict, so a change of policy re-scores the whole estate without re-collecting anything.
Observe
Sensors report raw facts: what was negotiated, what was found on disk, what a repository or image contains. They never judge.
Judge
CADP de-duplicates millions of sightings into one system-centric inventory and scores each asset against an editable, audited policy.
Prove
Per-system CycloneDX 1.7 documents, a where-used view, and policy-as-code compliance runs your auditor can consume.
Four surfaces, one inventory.
Build time and run time are kept apart: repositories and images are where you fix cryptography; endpoints and hosts are where it is exposed. Both are modelled, neither is conflated.
Network traffic, in motion
Network Sensor, on the CADP server
Passive capture from a promiscuous interface fed by a SPAN port. Protocols and versions, cipher suites offered and selected, post-quantum and hybrid key-exchange groups, certificate chains, SSH host keys, IPsec transforms. Nothing is installed on the systems being inventoried.
Host filesystems, at rest
Host Sensor, optional
Private and public keys, certificate files, PKCS#12, Java keystores, PKCS#11 and HSM providers, service key references, the Windows certificate store. Only the algorithm, path and encrypted-at-rest flag leave the host, never the key bytes.
Container images and running containers
Host Sensor or agentless image scan
Cryptographic material inside image layers and running container filesystems, including mounted volumes.
Source code repositories
Agentless git scan, server-side
Cryptographic API use and algorithms in source with file-and-line evidence, plus dependency package URLs for the dependency maps regulators ask for.
Coverage follows sensor placement. The product reports its own gaps rather than implying completeness.
What you see on day one.
A populated estate, not an empty table. Host sensors fill the inventory quickly and independently of traffic volume, so the first week looks real.
Dashboard
PQC Cockpit
Topology graph
Proof, not opinion.
Four things you will see in your own estate inside the first two weeks. Try them here.
Every red row is a server that was offered post-quantum key exchange and chose classical. The session looks fine; it is simply not protected against harvest-now-decrypt-later.
| Server | Protocol | Client offered | Server selected | Posture |
|---|---|---|---|---|
| web-portal-03 | TLS 1.3 | X25519MLKEM768, X25519 | X25519 | Offered, then declined |
| pg-primary-05 | TLS 1.3 | X25519MLKEM768, X25519 | X25519 | Offered, then declined |
| api-gw-02 | TLS 1.3 | X25519MLKEM768, X25519 | X25519MLKEM768 | Post-quantum |
| auth-svc-04 | TLS 1.2 | ECDHE P-256 | ECDHE P-256 | Classical only |
One timeline, five jurisdictions.
Inventory obligations sit between now and 2028. High-risk migration clusters around 2030. Choose a jurisdiction to see what it asks for.
European Union
DORA binding; roadmap dated; NIS2 amendment proposedThe Coordinated Implementation Roadmap asks for cryptographic inventories with dependency maps by end-2026 and names the CBOM as the recommended format. DORA already requires a register of certificates and certificate-storing devices for financial entities. A proposed NIS2 amendment would write post-quantum transition into every national strategy.
What CADP contributes: the technical inventory every regime mandates, bound to the system that uses it, in the CycloneDX format the EU roadmap names. Business classifications such as criticality and impact level remain yours to add.
Positions as of September 2026. Verify before relying on them.
Deploys in an afternoon. Nothing leaves.
One Linux server with Docker and two network interfaces. The Network Sensor is installed with CADP and captures from a promiscuous interface fed by your SPAN port. Host sensors are one command each.
- 1Install CADP and the Network Sensor with a single command
- 2Log in, set the admin password, activate the licence
- 3Mint an enrolment token and install host sensors with the one-liner
- 4Watch assets appear as traffic and first at-rest scans arrive
What sensors collect
- Connection metadata: addresses, ports, transport, detected protocol
- Handshake metadata: versions, suites and groups offered and selected, SNI
- X.509 fields and SSH host public keys, public by construction
- At rest: algorithm, type, size and path of key material; keystore and HSM presence
What is never collected
- Packet payloads or application data
- Decrypted content: no interception, no key escrow, no session keys
- Credentials, message bodies, file contents, full packet captures
- Private key bytes or passphrases
What leaves your environment: nothing.
Inventory, observations and CBOMs stay in your deployment. There is no telemetry channel. Licence activation and updates are the only outbound connections, and both can be replaced by an offline entitlement file and bundle updates for air-gapped sites.
What it is not, yet.
Technical buyers trust a vendor that states where the product stops. Several of these limits are surfaced inside the product itself.
Linux-only platform host
Windows, FreeBSD and Solaris are sensor hosts. Run a Linux VM to host the platform.
Single node in version 1.0
High availability is prepared architecturally but not yet shipped.
Local users, roles and tokens
Single sign-on and multi-factor authentication for the console are on the roadmap.
Coverage follows sensor placement
Passive capture sees what crosses the monitored link. The product reports gaps rather than implying completeness.
Unobserved means unobserved
Where a negotiation was not seen, the product says so rather than guessing a posture.
Business context is yours
Criticality, impact level and data sensitivity are your classifications, not something the product infers.
Sixty days. Your estate. At least one finding you did not already know.
A demo shows our lab. A proof of value shows your estate, with the full feature set, agreed exit criteria, and a written read-out at the end.
How we agree success before we start
- Both sensor types reporting inside day one
- Target systems inventoried by week two, gaps stated
- A per-system CBOM accepted by your compliance function
- One classification rule tuned to your standard
- At least one finding you did not already know
