Two ways in, one inventory out.
Most organisations cannot answer a simple question: where is RSA or classical ECC running, and what relies on it? Vyuh answers it from the outside in via protocol handshakes, or from the source out across repositories.
Public Web Endpoints
Vyuh negotiates directly with internet-facing services the way a client browser or API partner would, evaluating negotiated and fallback cryptographic suites.
- TLS 1.3/1.2 versions, negotiated cipher suites, and key exchange groups
- Full X.509 certificate chain inspection: signature algorithms, key sizes, CA roots
- Detection of hybrid post-quantum key encapsulation (e.g. X25519MLKEM768)
- HSTS, OCSP stapling validation, session ticket secrecy, and downgrade behavior
- Discovered subdomains and APIs harvested from Certificate Transparency logs
Code Repositories
Point Vyuh at a public repository or connect a private repo with a scoped read-only token. Vyuh traverses the code tree to parse cryptographic primitives and dependencies.
- Cryptographic API calls across Java, Python, Go, C/C++, TypeScript, and .NET
- Library versions: OpenSSL, BouncyCastle, PyCA/cryptography, libsodium
- Hardcoded private keys, weak pseudo-random generators, and legacy SHA-1/MD5 digests
- Certificates, keystores (JKS/PKCS12), and PEM credentials committed to version control
- Infrastructure-as-Code (Terraform, Kubernetes) and CI/CD TLS configuration audit
What comes back in ninety seconds.
A comprehensive, verifiable report your security architects can execute on and your audit committee can circulate, immediately downloadable as a PDF and exportable in CycloneDX 1.6 format.
Cryptographic Bill of Materials
Every algorithm, key length, protocol, and certificate mapped to where it lives, exportable directly to CycloneDX 1.6 for automated SBOM pipelines.
Quantum Readiness Score
A single 0–100 index with full arithmetic exposed: assessing what survives Shor and Grover, and how much is mission-critical.
Harvest-Now-Decrypt-Later Exposure
Weighs exposure using your data retention timeline against the estimated quantum arrival horizon to quantify active risk today.
Mapping to NIST FIPS 203/204/205
Each vulnerable asset is mapped to standardized replacements: ML-KEM, ML-DSA, and SLH-DSA, with hybrid transitional paths.
Severity-Ranked Findings
Actionable findings prioritized by risk, including exact remediation recommendations rather than vague vendor advisories.
4-Phase Migration Roadmap
Discovery, crypto-agility, hybrid deployment, and classical retirement sequenced specifically against your actual inventory.
NIST Quantum Vulnerability & Replacement Matrix.
How classical cryptographic primitives perform under Shor’s and Grover’s algorithms, and their certified NIST FIPS 203, 204, and 205 post-quantum replacements.
Algorithm Vulnerability & Replacement Matrix
Classical primitives vs quantum threats and NIST FIPS targets
| Classical Primitive | Enterprise Location | Quantum Verdict | NIST FIPS Replacement |
|---|---|---|---|
| RSA-2048 / RSA-4096 | TLS certificates, code signing, JWT tokens | Broken by Shor | ML-KEM-768 · ML-DSA-65 |
| ECDSA P-256 / P-384 | Certificate signatures, mTLS, zero-trust tokens | Broken by Shor | ML-DSA-65 · SLH-DSA |
| ECDH / X25519 | TLS session key exchange, VPN tunnels, SSH | Broken by Shor | X25519MLKEM768 Hybrid |
| AES-128-GCM | Symmetric session encryption, database columns | Halved by Grover | AES-256-GCM |
| SHA-1 / MD5 | Legacy HMACs, file integrity, older microservices | Already Insecure | SHA-384 · SHA-3 |
| AES-256-GCM / SHA-384 | Modern high-assurance envelope encryption | Quantum-Safe | No modification required |
How a scan runs.
Vyuh is free to use and gated only by a verified professional identity, ensuring diagnostic telemetry and cryptographic discoveries are shared strictly with verified organizational stewards.
Verify who you are
Name the target
Vyuh probes and classifies
Inspect, export, and download
Classified against the standards your regulator cites.
Vyuh’s risk ratings and remediation mandates trace directly to authoritative guidance from global and sovereign cryptographic bodies.
Questions asked before scanning.
You cannot migrate what you have not inventoried.
Start with one internet-facing endpoint or one critical repository. The first actionable CBOM and quantum readiness verdict is ready in ninety seconds.
