VISTASecurity
  • Vista Platform
  • How it works
  • Insights
  • Docs
  • Release status
  • Mailing list
Try Core
Vista Documentation
  • Editions
  • Vista Platform Platform Overview
  • Cbom
    • CBOM Artifacts
  • Features
    • Algorithm Reference
    • AI Assistant Integration (MCP)
    • Asset Approval Workflow
    • Asset Lifecycle Management
    • AWS Cloud Resource Discovery
    • Azure Cloud Resource Discovery
    • Certificate Chain Management
    • CMDB Integrations
    • CMDB Terminology Glossary
    • Compliance Framework Management
    • Crypto Risks Dashboard
    • Cryptographic Keys
    • Device Interrogation Feature
    • Discovery Feature
    • Fortinet Device Interrogation
    • Viewing Frameworks, Controls & Measurements
    • GCP Cloud Resource Discovery
    • Getting Started checklist
    • Global search (⌘K)
    • Inventory and Lenses
    • Measurement Templates
    • Inviting Members
    • Infrastructure Assets and Crypto Configurations
    • Network Spaces Feature
    • Operational Context
    • Page-local Export
    • PCAP File Ingestion
    • Remediation
    • Scopes
    • Enhanced Sensor Registration & Management Guide
    • Spreadsheet Import
    • Third-Party Systems and External Connections
    • Unified Crypto Inventory
  • Guides
    • Audit Logging User Guide
    • Cloud and Device Management Separation – Migration Guide
    • Device Auto-Discovery Troubleshooting Guide
    • Device Interrogation User Guide
    • Tenant Administrator Guide
    • Tenant User Guide
  • Operating VistaPlatform
    • Container runtime images (source of truth)
    • Platform Administrator Guide
    • Releases & Versioning
    • Service Startup and Shutdown Procedures
    • Configuration
      • Platform Integrations Configuration Guide
    • Deployment Documentation
      • Database Deployment Readiness – Sensor Management Enhancements
      • Database Migration Guide
      • Device Agent Deployment Guide
      • Managed vs In-Cluster Data Services (EKS)
      • Deployment Migration Checklist
      • Production Deployment Checklist
      • Deployment Propagation Guide
      • Vista RKE2 v1 — Customer Documentation
        • Vista — RKE2 Cluster Provisioning Guide
        • Vista Deployment Guide — RKE2 v1
        • Vista RKE2 Deployment — Pre-Flight Checklist
        • Vista Security Overview — RKE2 v1
        • Vista Support Bundle
    • Monitoring
      • Compliance Engine Event Processing Alerts
      • Compliance Log Management & Retention
      • Production Monitoring & Alerting Setup
      • System Monitoring & Alerting Guide
    • Operations
      • Notification Provider Integration Guide
    • Security
      • 🔒 Security Architecture for Cloud-Hosted Control Plane
      • Bootstrap Certificate Management
      • Certificate Management Operations Guide
      • Secrets Management Guide
    • Troubleshooting
      • Asset Approval Workflow Issues – Resolution Documentation
      • Troubleshooting Guide
      • Runbooks
        • Gateway Runbook
        • Recovery and Resume After Reboot
Vista/Docs

Algorithm Reference

The Algorithm Reference is a read-only catalogue of every cryptographic algorithm the platform knows about, together with our assessment of each one — how strong it is, whether it's deprecated, whether it resists quantum attack, and what to migrate to. It's the same source-of-truth rating the platform uses to flag risk across your inventory, made visible so a "weak" or "deprecated" verdict is something you can understand and act on, not just take on faith.

Where to find it

Risk & Compliance → Posture → Algorithm Reference tab.

Anyone who can view the Posture page can browse it — no special permission required.

What you can do

Browse and filter

The tab opens on the full catalogue, sorted with the highest-risk algorithms first. Narrow it with:

  • Search — match on name, code, family, or primitive (e.g. RSA, ML-KEM, aead).
  • Strength — Recommended / Strong / Acceptable / Weak.
  • Status — Current / Deprecated / Obsolete.
  • Quantum — PQC (post-quantum) vs Classical.

Each row shows the algorithm's family, type, strength, deprecation status, whether it's post-quantum, and a risk score (0–100, higher is worse).

Open an algorithm for the full assessment

Click any row to open a detail panel with:

  • Our assessment — strength, deprecation status (and date, if set), risk score, and post-quantum standardization status.
  • Migration guidance — our plain-language recommendation, plus the specific recommended alternatives to move to.
  • Identity & parameters — the technical detail (family, primitive, mode, padding, curve, parameter set, classical/quantum security levels, OID, and crypto functions) for anyone who needs it.

How this connects to the rest of the platform

When the platform marks an asset, certificate, or configuration as risky because of the algorithm it uses, the reasoning lives here. The Algorithm Reference is the "why" behind those flags — and the Frameworks tab next to it explains the compliance side the same way: which controls you're measured against and exactly what each one checks.

This is literal, not a figure of speech: the risk score shown on a crypto configuration is the risk score of its worst component algorithm, read from this catalogue. If a finding says a service is High risk, you can look the algorithm up here and see the assessment that produced it. See Crypto Risks → Risk Score Calculation.

The assessment is maintained by the platform. Tenants view it; they don't edit it. Platform administrators manage these ratings centrally so every tenant is measured against the same standard.

← Features AI Assistant Integration (MCP) →

View source on GitHub · Published from 470d8ee

On this page
  • Where to find it
  • What you can do
  • Browse and filter
  • Open an algorithm for the full assessment
  • How this connects to the rest of the platform
VISTASecurity

Vista Platform is a self-hosted cryptographic system of record for continuous discovery, evaluation, action, and proof.

Vista Platform

How it works
Governance
Post-Quantum
Core, Enterprise & MSP
Try Core

Resources

About
Insights
Documentation
Release status
GitHub ↗
info@vistasecurity.io
Join the mailing list

© 2026 Lakeshore Labs LLC. Vista Security is a brand of Lakeshore Labs LLC. All rights reserved.