You cannot migrate what you have not seen — and you cannot defer what you have not scoped. IFG is the independent practice that enumerates the cryptography in the scope you choose, and states plainly what it could not reach. We produce the map. We never sell the hammer.
No single technique sees the whole cryptographic picture, at any scope. Each mode has its own visibility and its own blind spots. The discipline is the integration of all five into a coherent inventory — and the honesty to mark what none of them reached.
The cryptography in transit announces itself. We read the handshakes traversing your network — the protocols, key exchanges, and cipher suites in active use — without sending a single probe packet.
The capability that ships inside your software, whether or not it is running. We surface the cryptographic libraries and constants embedded in deployed binaries — the dormant algorithms a system could invoke.
What the cryptographic layer does as the system runs. Live observation of cryptographic calls in execution, catching what static inspection cannot — the algorithm constructed at runtime, the path only exercised under load.
The cryptography declared in your stores and config. We parse certificate stores, key stores, and configuration to enumerate the trust material and cryptographic policy the estate is set up to use.
The cryptography held by your cloud and managed services. We enumerate keys, algorithms, and rotation posture exposed through managed key-service interfaces across your cloud footprint.
Every inventory has a boundary. Ours is written down. Where the five modes leave an asset unseen — the hardware-isolated key, the offline system, the path never run — we name it. A coverage map that hides its edges is not an inventory. It is theater.
Every engagement is scoped to the size and shape of your estate. Start with a fast read, move to a full inventory, and license the discipline when discovery becomes a standing capability. No tier sells remediation.
A fast, bounded scan to tell you whether your current inventory holds.
The full discipline across the estate in scope, producing an inventory you can act on.
License the methodology as a standing internal capability.
No published price list. Every estate is different — we scope to yours.
A building inspector who also owned the construction company would not be an inspector. They would be a salesperson with a clipboard. The independence is the value.
IFG enumerates cryptographic assets and stops there. We do not sell the migration, the tooling, or the remediation contract that follows. That boundary is not a limitation — it is the reason the inventory can be trusted. When we tell you what is in your walls, nothing in our business depends on the answer.
It is also why we name the residual. A discovery practice that profits from the fix has every reason to make the map look complete. We have none. So we draw the edge of what we could see, and we hand it to you straight.
IFG, LLC is collaborating with the National Cybersecurity Center of Excellence (NCCoE) in the Migration to Post-Quantum Cryptography Building Block Consortium to bring awareness to the issues involved in migrating to post-quantum algorithms and to develop practices to ease migration from current public-key algorithms to replacement algorithms. NIST does not evaluate commercial products under this Consortium and does not endorse any product or service used. Additional information on this Consortium can be found at: https://www.nccoe.nist.gov/projects/building-blocks/post-quantum-cryptography.
The discipline this practice applies is not proprietary framing. It is published, dated, and citable — so anyone assessing this work, or applying it themselves, can read the reasoning rather than take it on assertion. Both records are open access under CC BY 4.0.
Defines the terms this practice operates on: complete enumeration as a precondition rather than a phase; discovery theater, output that is authoritative in form and silent about its own coverage; the honest residual, the assets a methodology could not reach, named explicitly; and the distinction between automable collection and non-automable coverage — an instrument cannot establish the completeness of its own output.
Inventories record what a cryptographic asset is — algorithm, library, version, location. They do not record what it needs: the external services each operation requires in order to keep functioning. Defines six classes of operational dependency and distinguishes what can be enumerated from what would require intrusive testing to establish.
Tell us the shape of your environment and what you are trying to protect. We scope an engagement to fit — and tell you honestly what we will and will not be able to see.
A 30-minute conversation to size your estate and outline the right engagement depth. No preparation needed.
Choose a time →Share a few details and we will come back with a scoped engagement and an honest read on coverage.
We will read it and come back with a scoped engagement. Expect a reply from a person.