Assisted static CBOM

Map legacy crypto before migration.

VAJRA RECON scans source code and lockfiles you provide (zip export) for pattern-matched weak cryptography — MD5, SHA-1, weak TLS, RSA references, and more. Findings require engineering validation; this is not a full HSM, network, or regulatory sign-off.

Honest scope: static analysis only. No live GitHub/AWS connector on this page. CI/CD webhooks and admin assessment are available for enterprise deployments.

What you receive (enterprise pilot)

  • Engineer report pack (JSON, Markdown, HTML)
  • SARIF for CI + PDF after triage session
  • RBI / NIST mapping on validated findings only
  • PQC migration path (VajraShield stack)

Executive summary is drafted after your engineer validates findings — not from raw scanner grades.

For banks & fintech

  • You export the zip — we do not clone your GitHub or hold standing repo access.
  • NDA + secure transfer before any source is shared.
  • India-hosted assessment infrastructure; on-prem path available.
  • Complements VAPT — crypto inventory for PQC planning, not a penetration test or regulatory sign-off.
  • API docsCBOM API reference for platform engineers (pre-flight, upload, CI).

Three-step assessment

Production CBOM engine — scoped export, static scan, engineer validation, then executive readout.

1. Export zip

Client exports repository source + lockfiles. Exclude .env, keys, node_modules, and secrets.

2. Static CBOM scan

Pattern + dependency audit with false-positive policy. Optional AST/taint when tree-sitter is available in the deployment image.

3. Report pack

Full bundle (JSON, MD, HTML, SARIF, PDF + manifest) delivered after pilot kickoff. Your team validates findings before any audit claim.

Request enterprise briefing

Full report bundle + PQC migration path on VajraShield. We respond to verified corporate email.