You cannot migrate what you cannot see.

CADP finds every use of cryptography across your estate, on the wire, on disk, in source and in container images, scores it for post-quantum risk, and hands you a CycloneDX inventory your auditor can read.

Deploys on one Linux server in an afternoon. Nothing you discover ever leaves your environment.

edge-lb-01api-gw-02web-portal-03auth-svc-04pg-primary-05hsm-proxy-06bastion-07partner-sftp
Post-quantum negotiatedOffered, then declinedClassical only

The inventory these regimes now expectPCI DSS 12.3.3DORANIS2EU PQC roadmapUK NCSC timelinesUS EO 14412UAE National Encryption PolicyKSA NCA ECC

Two quantum clocks are already running.

The question every regulator now asks first, and most organisations cannot answer from anything better than a spreadsheet: where is your cryptography, and what does it protect?

Harvest now, decrypt later

Traffic recorded today is decrypted the day a cryptographically relevant quantum computer exists. Anything whose confidentiality must outlive that day is already exposed, whatever the date turns out to be.

Harvest now, forge later

Signatures and trust roots break on that same day. Software updates, certificates and identities can then be forged. Nothing needs to be captured in advance; every classical signature still in service is exposed at once.

Data lifetime + migration time > time until the machine exists, and you are already late.

Migration time is dominated by discovery. The inventory is the first deliverable, not a by-product.

Two sensors, one platform, one living inventory.

No sensor computes a verdict, so a change of policy re-scores the whole estate without re-collecting anything.

Observe

Sensors report raw facts: what was negotiated, what was found on disk, what a repository or image contains. They never judge.

Judge

CADP de-duplicates millions of sightings into one system-centric inventory and scores each asset against an editable, audited policy.

Prove

Per-system CycloneDX 1.7 documents, a where-used view, and policy-as-code compliance runs your auditor can consume.

Four surfaces, one inventory.

Build time and run time are kept apart: repositories and images are where you fix cryptography; endpoints and hosts are where it is exposed. Both are modelled, neither is conflated.

Network traffic, in motion

Network Sensor, on the CADP server

Passive capture from a promiscuous interface fed by a SPAN port. Protocols and versions, cipher suites offered and selected, post-quantum and hybrid key-exchange groups, certificate chains, SSH host keys, IPsec transforms. Nothing is installed on the systems being inventoried.

Host filesystems, at rest

Host Sensor, optional

Private and public keys, certificate files, PKCS#12, Java keystores, PKCS#11 and HSM providers, service key references, the Windows certificate store. Only the algorithm, path and encrypted-at-rest flag leave the host, never the key bytes.

Container images and running containers

Host Sensor or agentless image scan

Cryptographic material inside image layers and running container filesystems, including mounted volumes.

Source code repositories

Agentless git scan, server-side

Cryptographic API use and algorithms in source with file-and-line evidence, plus dependency package URLs for the dependency maps regulators ask for.

Coverage follows sensor placement. The product reports its own gaps rather than implying completeness.

What you see on day one.

A populated estate, not an empty table. Host sensors fill the inventory quickly and independently of traffic volume, so the first week looks real.

Dashboard

DashboardScreenshot placeholder · shot 1
System-centric headline numbers and the coverage-gap card, on load.

PQC Cockpit

PQC CockpitScreenshot placeholder · shot 4
Key-exchange and signature readiness on two axes, with migration over time.

Topology graph

Topology graphScreenshot placeholder · shot 3
Nodes coloured by worst posture, downgrade edges in red, inspector on click.

Proof, not opinion.

Four things you will see in your own estate inside the first two weeks. Try them here.

Every red row is a server that was offered post-quantum key exchange and chose classical. The session looks fine; it is simply not protected against harvest-now-decrypt-later.

ServerProtocolClient offeredServer selectedPosture
web-portal-03TLS 1.3X25519MLKEM768, X25519X25519Offered, then declined
pg-primary-05TLS 1.3X25519MLKEM768, X25519X25519Offered, then declined
api-gw-02TLS 1.3X25519MLKEM768, X25519X25519MLKEM768Post-quantum
auth-svc-04TLS 1.2ECDHE P-256ECDHE P-256Classical only
Downgraded-only filterScreenshot placeholder · shot 2
The graph filtered to silent downgrades, with one link inspector open.

One timeline, five jurisdictions.

Inventory obligations sit between now and 2028. High-risk migration clusters around 2030. Choose a jurisdiction to see what it asks for.

202520272029203120332035DORA in forceNational strategies and inventoriesHigh-risk migratedAll migrated

European Union

DORA binding; roadmap dated; NIS2 amendment proposed

The Coordinated Implementation Roadmap asks for cryptographic inventories with dependency maps by end-2026 and names the CBOM as the recommended format. DORA already requires a register of certificates and certificate-storing devices for financial entities. A proposed NIS2 amendment would write post-quantum transition into every national strategy.

What CADP contributes: the technical inventory every regime mandates, bound to the system that uses it, in the CycloneDX format the EU roadmap names. Business classifications such as criticality and impact level remain yours to add.

Positions as of September 2026. Verify before relying on them.

Deploys in an afternoon. Nothing leaves.

One Linux server with Docker and two network interfaces. The Network Sensor is installed with CADP and captures from a promiscuous interface fed by your SPAN port. Host sensors are one command each.

  1. 1Install CADP and the Network Sensor with a single command
  2. 2Log in, set the admin password, activate the licence
  3. 3Mint an enrolment token and install host sensors with the one-liner
  4. 4Watch assets appear as traffic and first at-rest scans arrive
All-in-one installerScreenshot placeholder · shot 16
Install completing with the admin URL printed.

What sensors collect

  • Connection metadata: addresses, ports, transport, detected protocol
  • Handshake metadata: versions, suites and groups offered and selected, SNI
  • X.509 fields and SSH host public keys, public by construction
  • At rest: algorithm, type, size and path of key material; keystore and HSM presence

What is never collected

  • Packet payloads or application data
  • Decrypted content: no interception, no key escrow, no session keys
  • Credentials, message bodies, file contents, full packet captures
  • Private key bytes or passphrases

What leaves your environment: nothing.

Inventory, observations and CBOMs stay in your deployment. There is no telemetry channel. Licence activation and updates are the only outbound connections, and both can be replaced by an offline entitlement file and bundle updates for air-gapped sites.

What it is not, yet.

Technical buyers trust a vendor that states where the product stops. Several of these limits are surfaced inside the product itself.

Linux-only platform host

Windows, FreeBSD and Solaris are sensor hosts. Run a Linux VM to host the platform.

Single node in version 1.0

High availability is prepared architecturally but not yet shipped.

Local users, roles and tokens

Single sign-on and multi-factor authentication for the console are on the roadmap.

Coverage follows sensor placement

Passive capture sees what crosses the monitored link. The product reports gaps rather than implying completeness.

Unobserved means unobserved

Where a negotiation was not seen, the product says so rather than guessing a posture.

Business context is yours

Criticality, impact level and data sensitivity are your classifications, not something the product infers.

Sixty days. Your estate. At least one finding you did not already know.

A demo shows our lab. A proof of value shows your estate, with the full feature set, agreed exit criteria, and a written read-out at the end.

60
days, full feature set
1
site, one CADP server
25
host sensors, plus 3 network
250
systems inventoried

How we agree success before we start

  • Both sensor types reporting inside day one
  • Target systems inventoried by week two, gaps stated
  • A per-system CBOM accepted by your compliance function
  • One classification rule tuned to your standard
  • At least one finding you did not already know

No pricing on this page by design. We discuss commercials once the scope is agreed.