Home
/
Platform
/
Cryptographic inventory
Cryptographic inventory

Build your cryptographic inventory of record.

Qinsight Atlas connects enterprise cryptography to the systems that use it, the evidence behind it, and the teams responsible. Build a current, actionable inventory for risk management and post-quantum migration.

Plan a pilot
What is a CBOM
Illustrative Atlas certificate inventory filtered by posture, expiry and production environment
Context changes the answer

Know what uses cryptography, and who can act on it.

A cryptographic inventory brings assets, source evidence and business context into one maintained record. Connect a certificate, key or algorithm to related systems and applications. Add ownership context where available, so findings can reach the right team.

Cryptographic
Algorithms
Keys
Certificates
Protocols
Libraries
Enterprise context
Systems
Deployments
Owners
Data classes
Observations
What the inventory contains

The cryptographic detail behind each system.

Review the assets and attributes reported by your connected sources. Keep their relationships to systems and applications alongside the technical record.

Examples of cryptographic inventory data and its use. Available fields depend on the source.
RecordUseful attributesWhat it helps you review
AlgorithmsAlgorithm, cryptographic purpose and parametersLegacy cryptography and post-quantum migration candidates
Keys and managed materialKey type, size, state and management location where reportedKey management exposure and affected systems
CertificatesSubject, issuer, validity dates and signature algorithmExpiry, weak signatures and related services
ProtocolsProtocol versions, cipher suites and endpoint contextLegacy configurations and supported cryptography
Libraries and code findingsCryptographic libraries, algorithm references and source locationsApplication teams and code paths that need review
Enterprise contextRelated system, application, environment and available ownership dataResponsibility, business relevance and change planning

Key and secret metadata describes the asset. It is separate from private key material, secret values or credentials. Available attributes and relationships depend on the source and access granted.

Explore a sample inventory
A current, traceable record

Keep the source close to the finding.

A record is more useful when you can see where it came from and when it was collected. Atlas supports scheduled and on-demand discovery, with source and collection context to help teams judge freshness.

Use available system relationships to investigate a finding, then confirm missing ownership or application context with the responsible team. A missing field is an information gap to resolve.

Inventory recordIllustrative

payments.example.com

TLS certificate · example business service

Cryptography
RSA-2048 · SHA-256 signing hash
Evidence source
Network discovery
Last observed
10 September 2026, 14:30 UTC
Application context
Payments service · CMDB
Owner
Not supplied · review needed
Example fields for explanation. Source coverage and available context vary.
Define your coverage

Build the inventory across the sources you use.

Connect supported sources across network services, applications, code repositories, cloud key services, databases, vaults and HSMs. Enrich the record with CMDB context where available.

Set the scope

Choose a business service or environment. Identify its sources, access requirements and the teams who can verify the results.

Review the gaps

Distinguish assessed sources from systems that remain outside coverage. Check missing parameters, relationships and ownership context.

Refresh the evidence

Schedule collection for the source and use case. Revisit findings after relevant application, infrastructure or cryptographic changes.

Explore cryptographic discovery · Review supported integrations

Put the inventory to work

Give risk and migration teams a shared starting point.

Review cryptographic risk

Find records with legacy algorithms, weak parameters or expiring certificates. Use related system context to investigate and prioritize the next assessment.

Plan post-quantum migration

Identify where quantum-vulnerable public-key cryptography appears. Bring the affected systems and available ownership context into migration planning.

Prepare a clear handoff

Give system owners the cryptographic details, source and collection time behind a finding, so they can confirm the next action.

Need to exchange cryptographic evidence?

The inventory is the working record. A CBOM is a portable representation of cryptographic assets within a defined scope.

Explore CBOM import and export

Cryptographic inventory questions

What is a cryptographic inventory?

A cryptographic inventory is a maintained record of cryptographic assets and their use across an organization. It connects algorithms, keys, certificates, protocols and cryptographic libraries to systems, source evidence and available business context.

How is it different from a certificate inventory?

A certificate inventory focuses on certificates, issuers and validity. A cryptographic inventory also covers key metadata, algorithms, protocol configurations and cryptography found in supported applications and other sources. This broader view supports cryptographic risk assessment and post-quantum migration planning.

How does Atlas keep the inventory current?

Atlas supports scheduled and on-demand discovery. Records reflect the most recent collection from each connected source. Refresh frequency, permissions and source availability determine how current that evidence is.

Does Atlas replace our CMDB?

Atlas adds cryptographic detail to your existing asset context. Supported CMDB integrations can connect records to applications and ownership information where available, helping security and system teams work from shared context.

Start with one environment. Build a record you can use.

Connect supported sources, review the evidence and identify the context your team needs to act.