Build your cryptographic inventory of record.
Qinsight Atlas connects enterprise cryptography to the systems that use it, the evidence behind it, and the teams responsible. Build a current, actionable inventory for risk management and post-quantum migration.

Know what uses cryptography, and who can act on it.
A cryptographic inventory brings assets, source evidence and business context into one maintained record. Connect a certificate, key or algorithm to related systems and applications. Add ownership context where available, so findings can reach the right team.
The cryptographic detail behind each system.
Review the assets and attributes reported by your connected sources. Keep their relationships to systems and applications alongside the technical record.
| Record | Useful attributes | What it helps you review |
|---|---|---|
| Algorithms | Algorithm, cryptographic purpose and parameters | Legacy cryptography and post-quantum migration candidates |
| Keys and managed material | Key type, size, state and management location where reported | Key management exposure and affected systems |
| Certificates | Subject, issuer, validity dates and signature algorithm | Expiry, weak signatures and related services |
| Protocols | Protocol versions, cipher suites and endpoint context | Legacy configurations and supported cryptography |
| Libraries and code findings | Cryptographic libraries, algorithm references and source locations | Application teams and code paths that need review |
| Enterprise context | Related system, application, environment and available ownership data | Responsibility, business relevance and change planning |
Key and secret metadata describes the asset. It is separate from private key material, secret values or credentials. Available attributes and relationships depend on the source and access granted.
Keep the source close to the finding.
A record is more useful when you can see where it came from and when it was collected. Atlas supports scheduled and on-demand discovery, with source and collection context to help teams judge freshness.
Use available system relationships to investigate a finding, then confirm missing ownership or application context with the responsible team. A missing field is an information gap to resolve.
payments.example.com
TLS certificate · example business service
- Cryptography
- RSA-2048 · SHA-256 signing hash
- Evidence source
- Network discovery
- Last observed
- 10 September 2026, 14:30 UTC
- Application context
- Payments service · CMDB
- Owner
- Not supplied · review needed
Build the inventory across the sources you use.
Connect supported sources across network services, applications, code repositories, cloud key services, databases, vaults and HSMs. Enrich the record with CMDB context where available.
Set the scope
Choose a business service or environment. Identify its sources, access requirements and the teams who can verify the results.
Review the gaps
Distinguish assessed sources from systems that remain outside coverage. Check missing parameters, relationships and ownership context.
Refresh the evidence
Schedule collection for the source and use case. Revisit findings after relevant application, infrastructure or cryptographic changes.
Explore cryptographic discovery · Review supported integrations
Give risk and migration teams a shared starting point.
Review cryptographic risk
Find records with legacy algorithms, weak parameters or expiring certificates. Use related system context to investigate and prioritize the next assessment.
Plan post-quantum migration
Identify where quantum-vulnerable public-key cryptography appears. Bring the affected systems and available ownership context into migration planning.
Prepare a clear handoff
Give system owners the cryptographic details, source and collection time behind a finding, so they can confirm the next action.
Need to exchange cryptographic evidence?
The inventory is the working record. A CBOM is a portable representation of cryptographic assets within a defined scope.
Cryptographic inventory questions
What is a cryptographic inventory?
A cryptographic inventory is a maintained record of cryptographic assets and their use across an organization. It connects algorithms, keys, certificates, protocols and cryptographic libraries to systems, source evidence and available business context.
How is it different from a certificate inventory?
A certificate inventory focuses on certificates, issuers and validity. A cryptographic inventory also covers key metadata, algorithms, protocol configurations and cryptography found in supported applications and other sources. This broader view supports cryptographic risk assessment and post-quantum migration planning.
How does Atlas keep the inventory current?
Atlas supports scheduled and on-demand discovery. Records reflect the most recent collection from each connected source. Refresh frequency, permissions and source availability determine how current that evidence is.
Does Atlas replace our CMDB?
Atlas adds cryptographic detail to your existing asset context. Supported CMDB integrations can connect records to applications and ownership information where available, helping security and system teams work from shared context.
Start with one environment. Build a record you can use.
Connect supported sources, review the evidence and identify the context your team needs to act.

