Architectural Cryptographic Discovery & Post-Quantum Readiness.
We audit enterprise codebases, isolate quantum-vulnerable algorithms, and deliver validated CycloneDX 1.6 CBOMs. Zero source code leakage. 100% Deterministic.
OWASP Benchmark Verified
Our engine is validated against industry-standard corpora—not theoretical claims. Every metric is reproducible, auditable, and contractually guaranteed.
100% Precision & Recall
0.00% False Positive Rate across 8,386 source files in the OWASP BenchmarkJava Corpus.
Sub-Second Execution
3,659+ Lines of Code per second scan velocity with a minimal memory footprint.
100% Deterministic Output
Cryptographic SHA-256 fingerprint matching across repeated evaluation runs.
Air-Gapped Telemetry
Zero cloud dependency, zero external API calls, total code confidentiality.
We Provide the Service.
You Keep Full Control.
Clastrums delivers high-precision, air-gapped cryptographic assessment services—not software licenses. Your code never leaves your perimeter. Your engineering decisions remain yours.
Service, not software. Enterprise clients hire us to audit source code, isolate legacy cryptographic risks, and deliver machine-readable CycloneDX 1.6 CBOMs alongside human-readable executive remediation reports. No SaaS. No telemetry. No vendor lock-in.
Scale-Based Engagement
We charge based on enterprise codebase scale, file density, and assessment parameters. Every engagement is scoped to your architecture—not a one-size-fits-all license.
Contractual Guarantee
Every engagement is governed by strict Non-Disclosure Agreements (NDAs), limited liability contracts, and legal compliance frameworks aligned with your jurisdiction.
Zero Enforced Remediation
We provide exact, line-by-line remediation code blocks directing your team toward NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA). Engineering teams retain 100% autonomy—remediation is entirely at your discretion.
What Our Engine Discovers
Deep static analysis engineered for cryptographic precision—not generic SAST noise.
Lexical & Semantic Isolation
Ignores string literals and comment blocks to eliminate false alarms. Only active cryptographic API invocations are flagged.
Multi-Line API Instantiation Tracking
Captures multi-line Java builders, staggered Cipher.getInstance() setups, and complex cryptographic wrapper patterns.
Monorepo Performance
Strict 8 MB individual file-cap guardrails ensure zero memory thrashing across large enterprise monorepos.
Target Vulnerability Matrix
Comprehensive coverage from legacy weak ciphers to NIST PQC migration paths.
- • DES
- • 3DES
- • MD5
- • SHA-1
- • RSA
- • ECC
- • Traditional DH/ECDH
- • NIST ML-KEM
- • ML-DSA
- • SLH-DSA
Dual Deliverables Showcase
Every assessment produces two complementary outputs—one for leadership, one for engineering automation.
C-Suite Executive Vulnerability Summary
Risk Tier Breakdown
Critical and High severity findings categorized by quantum exposure timeline, business impact, and regulatory compliance urgency.
Threat Narratives
Comprehensive explanations of Shor's algorithm exposure for RSA/ECC implementations and Grover's algorithm impact on symmetric key lengths.
Actionable Refactoring Snippets
Ready-to-use, line-by-line remediation code blocks directing engineering teams toward NIST PQC standards—ML-KEM, ML-DSA, and SLH-DSA.
┌─────────────────────────────────────────┐ │ CLASTRUMS EXECUTIVE RISK REPORT │ │ Classification: CONFIDENTIAL │ ├─────────────────────────────────────────┤ │ CRITICAL │ 12 findings │ │ HIGH │ 34 findings │ │ MEDIUM │ 89 findings │ ├─────────────────────────────────────────┤ │ Quantum Timeline: 2030-2035 │ │ Primary Exposure: RSA-2048, ECDH-P256 │ │ Recommended: ML-KEM-768, ML-DSA-65 │ └─────────────────────────────────────────┘
Machine-Readable Cryptography Bill of Materials
Standard-Compliant CBOM
Validated cryptographic component inventories linked to unique Object Identifiers (OIDs) per CycloneDX v1.6 specification.
Precise Location Metadata
Exact file paths, line numbers, character offsets, cipher modes, key lengths, and padding parameters for every finding.
DevSecOps Integration
Ready for instant ingestion into enterprise DevSecOps dashboards, SIEM pipelines, and compliance automation workflows.
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"components": [{
"type": "cryptographic-asset",
"name": "RSA-2048-OAEP-SHA256",
"cryptoProperties": {
"oid": "1.2.840.113549.1.1.1",
"algorithmProperties": {
"primitive": "public-key-encryption",
"parameterSetIdentifier": "rsa2048"
}
},
"evidence": {
"occurrences": [{
"location": "src/crypto/KeyManager.java",
"line": 142
}]
}
}]
}
Enterprise Health & Accuracy Report
Get in Contact
Every enterprise assessment is custom-scoped. Reach out directly to discuss your codebase, compliance requirements, and confidential engagement terms.
Enterprise Inquiries
stefan@clastrums.comAll communications are treated as confidential. NDA execution available prior to any technical discussion.