Cryptographic Asset Discovery & Inventory

Enumerate
first.

You cannot migrate what you have not seen — and you cannot defer what you have not scoped. IFG is the independent practice that enumerates the cryptography in the scope you choose, and states plainly what it could not reach. We produce the map. We never sell the hammer.

Vendor-neutral
We do not sell remediation, migration, or tooling. The inventory carries no conflict of interest.
Multi-modal
No single technique sees the whole estate. Five enumeration modes, integrated into one discipline.
Honest by design
We name what we could not reach. The residual is stated, not hidden behind an authoritative-looking report.
The premise

Every migration decision is a decision about scope — what to move first, what to defer, what to accept. Those are decisions about an estate you have to be able to see. Most are made against an inventory nobody has tested.

You cannot secure what you cannot see — and you cannot see it from a vendor who profits from the fix.
01
The discipline

Five modes.
One enumeration.

No single technique sees the whole cryptographic picture, at any scope. Each mode has its own visibility and its own blind spots. The discipline is the integration of all five into a coherent inventory — and the honesty to mark what none of them reached.

Mode 01

Network self-disclosure

The cryptography in transit announces itself. We read the handshakes traversing your network — the protocols, key exchanges, and cipher suites in active use — without sending a single probe packet.

Does not seeCryptography that is not on the wire during observation, and data at rest.
Mode 02

Binary inspection

The capability that ships inside your software, whether or not it is running. We surface the cryptographic libraries and constants embedded in deployed binaries — the dormant algorithms a system could invoke.

Does not seeCryptography not on disk in inspectable form, and hardware-isolated operations.
Mode 03

Runtime observation

What the cryptographic layer does as the system runs. Live observation of cryptographic calls in execution, catching what static inspection cannot — the algorithm constructed at runtime, the path only exercised under load.

Does not seeCode paths never executed during the observation window.
Mode 04

Configuration & certificate parsing

The cryptography declared in your stores and config. We parse certificate stores, key stores, and configuration to enumerate the trust material and cryptographic policy the estate is set up to use.

Does not seeCryptography used outside declared configuration, or undocumented overrides.
Mode 05

Managed key-service enumeration

The cryptography held by your cloud and managed services. We enumerate keys, algorithms, and rotation posture exposed through managed key-service interfaces across your cloud footprint.

Does not seeOperations inside services that expose no enumerable interface.
The residual

What no mode reached

Every inventory has a boundary. Ours is written down. Where the five modes leave an asset unseen — the hardware-isolated key, the offline system, the path never run — we name it. A coverage map that hides its edges is not an inventory. It is theater.

02
Engagements

Three depths
of seeing.

Every engagement is scoped to the size and shape of your estate. Start with a fast read, move to a full inventory, and license the discipline when discovery becomes a standing capability. No tier sells remediation.

Depth I

The Read

A fast, bounded scan to tell you whether your current inventory holds.

  • Targeted enumeration across a defined scope — a segment, an application tier, a footprint
  • Common scope: TLS termination across the network edge — what is terminating, on which library and version
  • Findings mapped to the five modes — with the residual named
  • A plain assessment of whether your existing CBOM is honest or hollow
  • Read-out call with the findings
Fixed-scope · scoped on request
Request the Read
Most engaged
Depth II

The Inventory

The full discipline across the estate in scope, producing an inventory you can act on.

  • All five enumeration modes, integrated across network, binary, runtime, configuration, and managed key services
  • A defensible cryptographic inventory in standard CBOM form (CycloneDX)
  • Honest coverage map — what was enumerated, what is partial, what requires judgment
  • M-23-02 / migration-readiness alignment
  • Findings briefing for security leadership
Scoped to estate size · scoped on request
Request scoping
Depth III

The Discipline

License the methodology as a standing internal capability.

  • Methodology licensing — the integration discipline, run by your team
  • Practitioner enablement and the coverage-honesty framework
  • Recurring inventory cadence as your estate changes
  • Independent review of inventories you already hold
Annual · scoped on request
Start a conversation

No published price list. Every estate is different — we scope to yours.

03
The stance

The inspector,
never the builder.

A building inspector who also owned the construction company would not be an inspector. They would be a salesperson with a clipboard. The independence is the value.

IFG enumerates cryptographic assets and stops there. We do not sell the migration, the tooling, or the remediation contract that follows. That boundary is not a limitation — it is the reason the inventory can be trusted. When we tell you what is in your walls, nothing in our business depends on the answer.

It is also why we name the residual. A discovery practice that profits from the fix has every reason to make the map look complete. We have none. So we draw the edge of what we could see, and we hand it to you straight.

Enumerate cryptographic assetsWe do
Produce the inventory & coverage mapWe do
Read whether your CBOM is honestWe do
Sell remediationWe don't
Sell migration or orchestrationWe don't
Resell a vendor's platformWe don't
Consortium participation

IFG, LLC is collaborating with the National Cybersecurity Center of Excellence (NCCoE) in the Migration to Post-Quantum Cryptography Building Block Consortium to bring awareness to the issues involved in migrating to post-quantum algorithms and to develop practices to ease migration from current public-key algorithms to replacement algorithms. NIST does not evaluate commercial products under this Consortium and does not endorse any product or service used. Additional information on this Consortium can be found at: https://www.nccoe.nist.gov/projects/building-blocks/post-quantum-cryptography.

04
Writing

The methodology
is published.

The discipline this practice applies is not proprietary framing. It is published, dated, and citable — so anyone assessing this work, or applying it themselves, can read the reasoning rather than take it on assertion. Both records are open access under CC BY 4.0.

  1. Step Zero: The Cryptographic Inventory Imperative — Doctrine Summary Jenkins-Bey, S.E. · 2026 · 10.5281/zenodo.22086669

    Defines the terms this practice operates on: complete enumeration as a precondition rather than a phase; discovery theater, output that is authoritative in form and silent about its own coverage; the honest residual, the assets a methodology could not reach, named explicitly; and the distinction between automable collection and non-automable coverage — an instrument cannot establish the completeness of its own output.

  2. Operational Dependency: What Cryptographic Inventories Omit Jenkins-Bey, S.E. · 2026 · 10.5281/zenodo.22086989

    Inventories record what a cryptographic asset is — algorithm, library, version, location. They do not record what it needs: the external services each operation requires in order to keep functioning. Defines six classes of operational dependency and distinguishes what can be enumerated from what would require intrusive testing to establish.

Request scoping

Start with the truth
about your estate.

Tell us the shape of your environment and what you are trying to protect. We scope an engagement to fit — and tell you honestly what we will and will not be able to see.

Talk now

Book a scoping call

A 30-minute conversation to size your estate and outline the right engagement depth. No preparation needed.

Choose a time →
Describe your estate

Send a scoping request

Share a few details and we will come back with a scoped engagement and an honest read on coverage.

No exposed inbox. Routed privately. We reply from a person, not an autoresponder.

Received.

We will read it and come back with a scoped engagement. Expect a reply from a person.