Vista Platform / Cryptographic inventory

Find your cryptographic assets.
Start free with Core.

Vista Core is free and available now. Use supported discovery channels to find certificates, key metadata, protocols, algorithms, and configurations across connected networks, devices, and cloud environments. Tie each observation to the asset and evidence behind it.

Free CoreSelf-hostedNo asset cap
Cryptography, continuously in context02 / VISTA
Cryptography, continuously in contextMoving signal paths connect certificates, keys, protocols and algorithms to asset posture. Orbiting markers illustrate ongoing monitoring, not a complete security assessment. POSTURECERTIFICATESKEYSPROTOCOLSALGORITHMS
Observed evidence · ongoing evaluation · coverage remains explicit

01 / Complementary discovery

Different sources.
A shared cryptographic inventory.

Each channel reveals a different part of cryptographic use. Vista brings those observations together while preserving their source and freshness.

01

Passive network observation

Observe supported protocols and cryptographic exchanges on monitored traffic. Reveal actual use within the sensor’s visibility.

02

Selected-asset Active Scan

Probe selected, authorized assets to investigate supported cryptographic services and known coverage gaps.

03

Device & host collection

Read supported device configurations and opt-in host certificate-store posture, including evidence network traffic may not reveal.

04

Cloud APIs

Collect supported cloud certificate, key, and configuration metadata through authorized provider APIs.

05

PCAP analysis

Process uploaded captures for cryptographic evidence from a defined collection window.

06

Existing inventory & imports

Bring supported inventory and software bill-of-materials inputs into the same asset context. Imported records retain their provenance.

Discovery is bounded by permissions, protocol support, connected sources, and collection coverage. Vista does not collect private-key bytes or turn selected-asset scanning into indiscriminate network scanning.

02 / Canonical cryptographic inventory

Follow the configuration.
Find the asset.

Connect cryptographic observations to durable asset records, services, ownership, and relationships. Move from a posture finding to the protocol, algorithm, certificate, or configuration that explains it.

Explore the wider asset inventory ↗
Existing product view · cryptographic configuration and supporting context

03 / Monitor change & coverage

Keep attention on what needs action.

01

Cryptographic posture

Evaluate supported algorithms, protocol settings, key strength, and certificate state against inventory-based controls.

02

Certificate lifecycle

Track observed certificate validity and expiry findings. Connect lifecycle issues to the affected assets and responsible teams.

03

Coverage & freshness

Keep observation age and assessment gaps visible. A quiet sensor or absent finding does not mean a system is secure.

Existing product view · move from summarized posture into supporting evidence

04 / Post-quantum readiness

Turn quantum exposure
into a worklist.

Identify configurations that need migration, distinguish quantum-safe symmetric use, and connect readiness findings to the systems and teams responsible for change.

Use ownership and recorded dependencies to plan work, then preserve progress through scoped CBOM artifacts.

Vista evaluates and governs migration. It does not generate PQC keys, reissue certificates, or perform every migration for you.

Explore post-quantum planning ↗
From cryptographic configuration to prioritized migration work

05 / Findings → ownership → evidence

Keep remediation connected
to the condition that caused it.

Connect findings to accountable work, retain decisions and exceptions, and evaluate new observations as your environment changes. Generate CBOMs at meaningful milestones to document the inventory at that time.

Included in Core

Find cryptographic assets with free Core today.

Run Core in infrastructure you control and connect authorized sources to start discovering cryptographic assets. Standard discovery channels, canonical inventory, bundled framework evaluation, PQC assessment, and CBOM generation are included without asset, sensor, seat, or time caps.

Enterprise adds regulated framework content, custom policies, supported CMDB/ITSM sync, and CBOM signing, attestation, and comparison. Passive OT discovery is Core; OT active probing and the dedicated OT lens are Enterprise.

Questions about discovery

Make the boundaries clear.

Go deeper: Why post-quantum planning starts with inventory · Product documentation.

What belongs in a cryptographic inventory?

A cryptographic inventory records certificates, public-key metadata, algorithms, protocols, and configurations, linked to the assets and services that use them. Useful records also identify the observation source, freshness, and coverage gaps.

How do passive and active cryptographic discovery differ?

Passive discovery observes supported cryptographic traffic visible to a sensor. Selected-asset Active Scan queries authorized assets to investigate supported services. Neither sees every configuration: idle services, encrypted handshakes, unreachable hosts, and unsupported sources can leave gaps. Combine sources and retain those limitations.

How does inventory support post-quantum migration planning?

Inventory identifies cryptographic dependencies and connects affected configurations to assets and accountable teams. Vista evaluates readiness and tracks work and evidence; it does not replace every algorithm or perform the migration itself. Explore post-quantum readiness and migration planning.

Can Vista see cryptography that is not on the wire?

Supported device interrogation, host certificate-store collection, cloud APIs, and imports complement passive traffic. Each has its own coverage boundaries; no individual channel proves complete discovery.

Does Vista retain private keys?

No. Vista inventories supported key metadata and cryptographic posture without retrieving private-key bytes from certificate stores or cloud key services.

Is monitoring the same as live security testing?

No. Discovery gathers evidence through the configured channels. Compliance evaluation reads stored inventory; it does not run penetration tests or perform live cryptographic challenge-response.

Can I generate a CBOM with Core?

Yes. Core generates scoped, content-hashed CycloneDX artifacts with provenance and downloadable formats. Enterprise adds HMAC signing, compliance-attestation layers, and artifact comparison.

Self-hosted. Free and source-available.

Start finding your cryptography.

Free, source-available Core is ready now. Connect supported sources, investigate coverage gaps, and keep findings, ownership, and evidence connected.

Stay in the loop

Keep up with Vista.

Get release notes, product updates, and opportunities to share feedback. Joining the mailing list is optional—Core is available without a subscription.

Join the mailing list