⚡ v0.5.9-stable Released: All compliance auditing and interactive remediation features are now live. Read Release Documentation ➔
FIPS 140-2 Sunset: Sept 2026 | CNSA 2.0 Mandate: Jan 2027

Is your codebase ready for the Post-Quantum federal mandates?

CipherMap is a local, privacy-first CLI that audits your repository for quantum-vulnerable cryptography. Find out where you stand in 30 seconds.

One command. No signup. Click to copy.

ciphermap — scan session

Universal Multi-Language Scanning Engine

GoTypeScriptJavaScriptPythonRustC/C++JavaC#PHPSwiftRubyYAML/IaC

Built for the cryptographic migration

Everything you need to inventory, grade, and gate your post-quantum readiness — without handing your source code to a third party.

Detects quantum-vulnerable crypto

Flags RSA, ECDSA, DH, and broken hashes like MD5 across your entire dependency tree before adversaries harvest-now-decrypt-later.

CNSA 2.0 Target Enforcement

Enforces NSA Commercial National Security Algorithm Suite 2.0 targets. Rejects SHA-3 and SLH-DSA variants for general software applications.

CycloneDX 1.6 CBOM export

Serialize every cryptographic asset into a machine-readable Cryptographic Bill of Materials for compliance pipelines.

Crypto-Agility Analysis

Grades code coupling. Measures how easily algorithms can be swapped by checking wrapper interfaces vs hardcoded direct calls.

Stateful Signature checks

Audits LMS and XMSS state mutations in AST. Flags errors if multi-tree variants (XMSS^MT) are used.

Entropy & DRBG Verification

Validates random bit generation seeds (NIST SP 800-90A) and flags weak math-seeding routines.

Interactive CLI Fix Wizard

Run 'ciphermap fix' to step through vulnerabilities in an interactive shell. Standalone Auditor and DevSecOps Enterprise licenses unlock instant inline PQC code replacement templates matching your specific files.

Automated Git PR Engine

Under DevSecOps Enterprise, execute scans with '--git-pr' to automatically branch, commit structural compliance patches locally, and generate CLI instructions to open a PR on GitHub/GitLab.

Zero network footprint

Runs 100% on your machine. Your source code never leaves the directory — no uploads, no telemetry, no servers.

Grade your repository now

Don't wait for an audit to find your RSA-2048 keys. Scan locally, today.