Passive network observation
Observe supported protocols and cryptographic exchanges on monitored traffic. Reveal actual use within the sensor’s visibility.
Vista Platform / Cryptographic inventory
Vista Core is free and available now. Use supported discovery channels to find certificates, key metadata, protocols, algorithms, and configurations across connected networks, devices, and cloud environments. Tie each observation to the asset and evidence behind it.
01 / Complementary discovery
Each channel reveals a different part of cryptographic use. Vista brings those observations together while preserving their source and freshness.
Observe supported protocols and cryptographic exchanges on monitored traffic. Reveal actual use within the sensor’s visibility.
Probe selected, authorized assets to investigate supported cryptographic services and known coverage gaps.
Read supported device configurations and opt-in host certificate-store posture, including evidence network traffic may not reveal.
Collect supported cloud certificate, key, and configuration metadata through authorized provider APIs.
Process uploaded captures for cryptographic evidence from a defined collection window.
Bring supported inventory and software bill-of-materials inputs into the same asset context. Imported records retain their provenance.
Discovery is bounded by permissions, protocol support, connected sources, and collection coverage. Vista does not collect private-key bytes or turn selected-asset scanning into indiscriminate network scanning.
02 / Canonical cryptographic inventory
Connect cryptographic observations to durable asset records, services, ownership, and relationships. Move from a posture finding to the protocol, algorithm, certificate, or configuration that explains it.
03 / Monitor change & coverage
Evaluate supported algorithms, protocol settings, key strength, and certificate state against inventory-based controls.
Track observed certificate validity and expiry findings. Connect lifecycle issues to the affected assets and responsible teams.
Keep observation age and assessment gaps visible. A quiet sensor or absent finding does not mean a system is secure.
04 / Post-quantum readiness
Identify configurations that need migration, distinguish quantum-safe symmetric use, and connect readiness findings to the systems and teams responsible for change.
Use ownership and recorded dependencies to plan work, then preserve progress through scoped CBOM artifacts.
Vista evaluates and governs migration. It does not generate PQC keys, reissue certificates, or perform every migration for you.
Explore post-quantum planning ↗05 / Findings → ownership → evidence
Connect findings to accountable work, retain decisions and exceptions, and evaluate new observations as your environment changes. Generate CBOMs at meaningful milestones to document the inventory at that time.
Included in Core
Run Core in infrastructure you control and connect authorized sources to start discovering cryptographic assets. Standard discovery channels, canonical inventory, bundled framework evaluation, PQC assessment, and CBOM generation are included without asset, sensor, seat, or time caps.
Enterprise adds regulated framework content, custom policies, supported CMDB/ITSM sync, and CBOM signing, attestation, and comparison. Passive OT discovery is Core; OT active probing and the dedicated OT lens are Enterprise.
Questions about discovery
Go deeper: Why post-quantum planning starts with inventory · Product documentation.
A cryptographic inventory records certificates, public-key metadata, algorithms, protocols, and configurations, linked to the assets and services that use them. Useful records also identify the observation source, freshness, and coverage gaps.
Passive discovery observes supported cryptographic traffic visible to a sensor. Selected-asset Active Scan queries authorized assets to investigate supported services. Neither sees every configuration: idle services, encrypted handshakes, unreachable hosts, and unsupported sources can leave gaps. Combine sources and retain those limitations.
Inventory identifies cryptographic dependencies and connects affected configurations to assets and accountable teams. Vista evaluates readiness and tracks work and evidence; it does not replace every algorithm or perform the migration itself. Explore post-quantum readiness and migration planning.
Supported device interrogation, host certificate-store collection, cloud APIs, and imports complement passive traffic. Each has its own coverage boundaries; no individual channel proves complete discovery.
No. Vista inventories supported key metadata and cryptographic posture without retrieving private-key bytes from certificate stores or cloud key services.
No. Discovery gathers evidence through the configured channels. Compliance evaluation reads stored inventory; it does not run penetration tests or perform live cryptographic challenge-response.
Yes. Core generates scoped, content-hashed CycloneDX artifacts with provenance and downloadable formats. Enterprise adds HMAC signing, compliance-attestation layers, and artifact comparison.
Self-hosted. Free and source-available.
Free, source-available Core is ready now. Connect supported sources, investigate coverage gaps, and keep findings, ownership, and evidence connected.
Stay in the loop
Get release notes, product updates, and opportunities to share feedback. Joining the mailing list is optional—Core is available without a subscription.