CipherWyze Discovery

Find the cryptography you use—and the estate you have never examined.

Discovery collects cryptographic evidence across networks, PKI, code, cloud, endpoints and hardware, then hands normalised evidence to Navigator for governance.

Estate signalsGoverned evidence
01Network
02PKI and identity
03Code and artefacts
04Keys and infrastructure
KeysCertificatesAlgorithmsLibrariesProtocolsHardware
Evidence coverage

No single scanner can describe a cryptographic estate.

Discovery combines nineteen evidence-producing collection methods across four domains. CMDB and IAM context form a twentieth input, adding ownership and the denominator needed to measure coverage.

KeysCertificatesAlgorithmsLibrariesProtocolsHardware
01

Network

Active and passive network evidence, runtime observation, configuration, telemetry and protocol-specific probes.

02

PKI and identity

Certificate estates, trust chains, signing material and third-party attestations.

03

Code and artefacts

Source, dependencies, binaries, firmware and container images examined before and during runtime.

04

Keys and infrastructure

Endpoints, cloud control planes, vaults, HSMs, databases, mainframes and legacy platforms.

Discovery to governance

The engine produces evidence. Navigator governs the inventory.

Discovery collects and normalises observations. Navigator correlates repeated sightings, adds ownership, maintains the system of record and turns evidence into risk and action.

01

Sources

Estate signals

02

Collect

Purpose-built methods

03

Normalise

CycloneDX 1.6 evidence

04

Correlate

Deduplicate and enrich

05

Inventory

Governed system of record

06

Outcomes

Risk, roadmap and reporting

The handover is a CycloneDX 1.6 document carrying the observation, provenance, time and confidence. Discovery does not maintain a competing inventory of its own.

Deployment and reach

Reach segmented estates without bypassing their boundaries.

The engine can run in CipherWyze cloud, inside your tenancy or fully isolated. A Runner placed in each unreachable zone performs collection locally and dials out over 443—without an inbound port or stored target credentials.

01

In our cloud

CipherWyze hosts the engine. Runners provide controlled reach into internal zones where required.

02

In your tenancy

The engine runs inside your cloud boundary, with normalised evidence handed to Navigator.

03

Fully isolated

The engine and runners operate inside the estate, with evidence exported for governed import.

Scan controls and audit trail

Every active scan must earn its dispatch.

Controls are evaluated in the pipeline at dispatch time, then recorded against the scan so teams can show what ran, when, on whose authority and what it could touch.

01

Window

Run only inside an approved maintenance window.

02

Safe mode

Restrict sensitive targets to permitted collection methods.

03

Authorisation

Require named approval before active production scans.

04

Credentials

Dispatch only with a valid, least-privilege credential reference.

Coverage and assurance

What was never examined matters as much as what was found.

A scanner can report its findings. Discovery compares examined assets with the estate known through CMDB and PKI context, making the unexamined population visible.

Known to exist
Estate denominator
Examined
Evidence returned
Never examined
Visible coverage gap
Discovery briefing

See what your current tools can find—and what remains unseen.

Talk to CipherWyze about Discovery coverage, deployment options and the handover into Navigator's governed cryptographic inventory.

Discuss Discovery