Validation Services Architecture Deliverables Benchmark Contact
Enterprise PQC Assessment Services

Architectural Cryptographic Discovery & Post-Quantum Readiness.

We audit enterprise codebases, isolate quantum-vulnerable algorithms, and deliver validated CycloneDX 1.6 CBOMs. Zero source code leakage. 100% Deterministic.

View Benchmark Results
clastrums-scan-engine — enterprise-evaluation
Source Scan
Executive Risk Narrative PDF

            
SHA-256: a3f8c2…9e1d4b DETERMINISTIC ✓
Empirical Validation

OWASP Benchmark Verified

Our engine is validated against industry-standard corpora—not theoretical claims. Every metric is reproducible, auditable, and contractually guaranteed.

0%
Accuracy

100% Precision & Recall

0.00% False Positive Rate across 8,386 source files in the OWASP BenchmarkJava Corpus.

0+
LOC/sec

Sub-Second Execution

3,659+ Lines of Code per second scan velocity with a minimal memory footprint.

0%
Determinism

100% Deterministic Output

Cryptographic SHA-256 fingerprint matching across repeated evaluation runs.

0
External Calls

Air-Gapped Telemetry

Zero cloud dependency, zero external API calls, total code confidentiality.

We Provide the Service.
You Keep Full Control.

Clastrums delivers high-precision, air-gapped cryptographic assessment services—not software licenses. Your code never leaves your perimeter. Your engineering decisions remain yours.

Service, not software. Enterprise clients hire us to audit source code, isolate legacy cryptographic risks, and deliver machine-readable CycloneDX 1.6 CBOMs alongside human-readable executive remediation reports. No SaaS. No telemetry. No vendor lock-in.

Scale-Based Engagement

We charge based on enterprise codebase scale, file density, and assessment parameters. Every engagement is scoped to your architecture—not a one-size-fits-all license.

Contractual Guarantee

Every engagement is governed by strict Non-Disclosure Agreements (NDAs), limited liability contracts, and legal compliance frameworks aligned with your jurisdiction.

Zero Enforced Remediation

We provide exact, line-by-line remediation code blocks directing your team toward NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA). Engineering teams retain 100% autonomy—remediation is entirely at your discretion.

Engine Architecture

What Our Engine Discovers

Deep static analysis engineered for cryptographic precision—not generic SAST noise.

Lexical & Semantic Isolation

Ignores string literals and comment blocks to eliminate false alarms. Only active cryptographic API invocations are flagged.

Multi-Line API Instantiation Tracking

Captures multi-line Java builders, staggered Cipher.getInstance() setups, and complex cryptographic wrapper patterns.

Monorepo Performance

Strict 8 MB individual file-cap guardrails ensure zero memory thrashing across large enterprise monorepos.

Target Vulnerability Matrix

Comprehensive coverage from legacy weak ciphers to NIST PQC migration paths.

Legacy Cryptography
  • • DES
  • • 3DES
  • • MD5
  • • SHA-1
Quantum-Vulnerable Asymmetric
  • • RSA
  • • ECC
  • • Traditional DH/ECDH
Quantum-Safe Migration Targets
  • • NIST ML-KEM
  • • ML-DSA
  • • SLH-DSA

Dual Deliverables Showcase

Every assessment produces two complementary outputs—one for leadership, one for engineering automation.

PDF

C-Suite Executive Vulnerability Summary

Risk Tier Breakdown

Critical and High severity findings categorized by quantum exposure timeline, business impact, and regulatory compliance urgency.

Threat Narratives

Comprehensive explanations of Shor's algorithm exposure for RSA/ECC implementations and Grover's algorithm impact on symmetric key lengths.

Actionable Refactoring Snippets

Ready-to-use, line-by-line remediation code blocks directing engineering teams toward NIST PQC standards—ML-KEM, ML-DSA, and SLH-DSA.

Sample Output Preview
┌─────────────────────────────────────────┐
│  CLASTRUMS EXECUTIVE RISK REPORT        │
│  Classification: CONFIDENTIAL           │
├─────────────────────────────────────────┤
│  CRITICAL  │ 12 findings               │
│  HIGH      │ 34 findings               │
│  MEDIUM    │ 89 findings               │
├─────────────────────────────────────────┤
│  Quantum Timeline: 2030-2035           │
│  Primary Exposure: RSA-2048, ECDH-P256  │
│  Recommended: ML-KEM-768, ML-DSA-65     │
└─────────────────────────────────────────┘
JSON

Machine-Readable Cryptography Bill of Materials

Standard-Compliant CBOM

Validated cryptographic component inventories linked to unique Object Identifiers (OIDs) per CycloneDX v1.6 specification.

Precise Location Metadata

Exact file paths, line numbers, character offsets, cipher modes, key lengths, and padding parameters for every finding.

DevSecOps Integration

Ready for instant ingestion into enterprise DevSecOps dashboards, SIEM pipelines, and compliance automation workflows.

Sample Output Preview
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "components": [{
    "type": "cryptographic-asset",
    "name": "RSA-2048-OAEP-SHA256",
    "cryptoProperties": {
      "oid": "1.2.840.113549.1.1.1",
      "algorithmProperties": {
        "primitive": "public-key-encryption",
        "parameterSetIdentifier": "rsa2048"
      }
    },
    "evidence": {
      "occurrences": [{
        "location": "src/crypto/KeyManager.java",
        "line": 142
      }]
    }
  }]
}
Verified Benchmark Proof

Enterprise Health & Accuracy Report

clastrums@airgap:~ — benchmark-report
==============================================================================
QUANTUM-SAFE CBOM ANALYZER - ENTERPRISE HEALTH & ACCURACY REPORT
==============================================================================

Get in Contact

Every enterprise assessment is custom-scoped. Reach out directly to discuss your codebase, compliance requirements, and confidential engagement terms.

Enterprise Inquiries

stefan@clastrums.com

All communications are treated as confidential. NDA execution available prior to any technical discussion.