{
  "slug": "fortanix-key-insight-pqc-central",
  "name": "Fortanix Key Insight / PQC Central",
  "vendor": "Fortanix",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Active, same name. Latest Key Insight release listed is 27.0 (2026-06-26, 'Added support for Azure Certificates'); 26.05 (2026-05-15) added Zeek-based network-log scanning. No release after Aug 2026 listed; no rename or acquisition found (searched 2026-09-26).",
    "url": "https://support.fortanix.com/docs/key-insight-release-notes"
  },
  "cells": {
    "C1": {
      "score": 9,
      "anchor": "midpoint between 8 (5-6 surfaces with algorithm depth) and 10 (>=7 surfaces with algorithm+parameter depth and PQC/hybrid detection)",
      "urls": [
        "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
        "https://support.fortanix.com/docs/fortanix-key-insight-for-on-premises-concepts",
        "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
        "https://support.fortanix.com/docs/fortanix-key-insight-on-premises-source-code",
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
        "https://support.fortanix.com/docs/26-05-ki-may-15-2026.md"
      ],
      "quote": "Fortanix Key Insight integrates with network security monitoring frameworks (for example, Zeek) to passively analyze mirrored network traffic and detect cryptographic artifacts such as certificates, TLS versions, cipher suites, and key exchange mechanisms on Linux systems.",
      "rationale": "7 surfaces documented (a network via Zeek, b certs, c source code, e KMS/HSM/Vault/DSM, f AWS/Azure/GCP services, g file-system agent, h Oracle/MSSQL DBs); key spec/size and PQC algorithms (ML-KEM/ML-DSA/LMS) documented for keys, but parameter depth not documented for code/file-system findings and hybrid detection not documented.",
      "delta_vs_published": 1
    },
    "C2": {
      "score": 6,
      "anchor": "6: standard-schema export documented, no integrity mechanism",
      "urls": [
        "https://support.fortanix.com/docs/25-07-ki-july-16-2025.md",
        "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md"
      ],
      "quote": "Fortanix Key Insight now supports Cryptography Bill of Materials (CBOM) export in CBOM JSON format, adhering to the CycloneDX standard, for cryptographic assets discovered across cloud environments (AWS, Azure), on-premises deployments, and external key sources",
      "rationale": "CycloneDX CBOM export documented (GA 25.07, confirmed); signing/hash integrity and public sample not documented in the URLs searched, so 8 is not reached.",
      "delta_vs_published": -1
    },
    "C3": {
      "score": 5,
      "anchor": "midpoint between 4 (point-in-time scans re-run manually) and 6 (scheduled rescans with documented diff/drift reporting)",
      "urls": [
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
        "https://support.fortanix.com/docs/fortanix-key-insight-file-system-and-network-scanner-agent-configuration-linux",
        "https://support.fortanix.com/docs/fortanix-key-insight-overview"
      ],
      "quote": "Click RESCAN on the top-right corner of the Overview or Assessment page to perform a rescan and verify if any keys have been added, deleted, or updated in the CSP organization.",
      "rationale": "Manual rescan for cloud connections plus systemd-timer scheduling for the on-prem agent are documented; a diff/drift report, change alerts and tamper-evident history are not documented in the URLs searched. 'Continuously analyzes' language has no documented mechanism.",
      "delta_vs_published": -1
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical risk levels from algorithm vulnerability plus some context",
      "urls": [
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
        "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness"
      ],
      "quote": "A critical risk score indicates the total number of deleted keys, expired certificates, Services encrypted with cross-account key usage, non-compliant certificates by algorithm, and unencrypted cloud services detected that need attention.",
      "rationale": "Critical/High/Medium/Good categories combine algorithm non-compliance with usage/permission context; PQC readiness is a published formula but only percentage = (total - vulnerableTotal)/total (a vulnerable/not flag aggregate). No data-lifetime/HNDL factor documented.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 0,
      "anchor": "0: not documented",
      "urls": [
        "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
        "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
        "https://support.fortanix.com/docs/fortanix-key-insight-for-on-premises-concepts",
        "https://support.fortanix.com/docs/fortanix-key-insight-overview",
        "https://support.fortanix.com/docs/key-insight-release-notes.md",
        "https://www.fortanix.com/platform/key-insight",
        "web search 2026-09-26: site:support.fortanix.com \"Key Insight\" \"false positive\" OR accuracy OR precision (no correctness content)"
      ],
      "quote": "not documented in the URLs listed (no precision, recall, benchmark, accuracy or false-positive handling statement found)",
      "rationale": "No accuracy metric, test methodology or FP handling documented in any page fetched.",
      "delta_vs_published": -5
    },
    "C6": {
      "score": 4,
      "anchor": "4: remediation guidance only (ticketing and in-platform action named without mechanism, capped per rubric line 19)",
      "urls": [
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
        "https://support.fortanix.com/docs/fortanix-key-insight-overview",
        "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness"
      ],
      "quote": "This allows organizations not only to identify cryptographic risks but also to take corrective actions from within the same platform.",
      "rationale": "Docs give recommendations (stronger algorithms, remove unused keys); press release says 'build a roadmap in ... ServiceNow or Jira' and overview claims corrective actions, but no integration or action mechanism is documented on support.fortanix.com (site search for ServiceNow/Jira/ticket in Key Insight returned nothing).",
      "delta_vs_published": -2
    },
    "C7": {
      "score": 7,
      "anchor": "midpoint between 6 (dashboards plus exports) and 8 (executive and technical reports with documented compliance mapping)",
      "urls": [
        "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
        "https://support.fortanix.com/docs/fortanix-key-insight-cryptographic-policy-management",
        "https://support.fortanix.com/docs/programmatic-access-to-fortanix-key-insight-apis"
      ],
      "quote": "Click DOWNLOAD REPORT on the top-right corner of the Assessment page to view the Data Security Assessment Report for the AWS connection in PDF format.",
      "rationale": "Dashboards, PDF assessment report, CSV and CBOM exports, API, and policy mapping to NIST 800-57/PCI DSS/FIPS documented; separate executive vs technical reports and PQC frameworks (IR 8547, CNSA 2.0) not documented; no public sample report.",
      "delta_vs_published": 1
    }
  },
  "total": 5.74,
  "published_total": 6.47,
  "urls_that_failed": [],
  "notes": "Quotes were extracted through a fetch tool whose intermediary model returns page text; the .md variants of support.fortanix.com pages were used where possible and markup stripped. Two fetches (cloud-connection-scanning-configuration index and policy-center index) returned my own prompt text echoed back and were discarded as evidence. Between-anchor convention: where anchors are 2 apart, the integer midpoint is used and both anchors named. Brief S15's sourcing ('CBOM GA from 25.07') is confirmed by the 25.07 release note. Largest move is C5 5->0: no accuracy evidence in any fetched page. Staging note's 'instant risk score' is marketing on fortanix.com/platform/key-insight; the documented PQC readiness formula is a percentage of non-vulnerable assets."
}