{
  "slug": "isara-advance",
  "name": "ISARA Advance",
  "vendor": "ISARA",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Still offered. ISARA is operating and has not wound down or been acquired. On 2026-06-30 ISARA posted a vendor press release (BusinessWire newsitemid 20260630023670) announcing an award for ISARA Advance, now positioned as the 'Autonomous Crypto Posture Management (ACPM) platform'. The product page is live, and an 'ISARA Advance on Microsoft Azure' offering now exists (partner-msazure.html). I found no vendor-documented major release after Aug 2026. A web search found no acquisition or wind-down news.",
    "url": "https://www.isara.com/company/newsroom/isara-wins-best-critical-infrastructure-platform-in-the-2026-cybersecurity-stars-awards.html"
  },
  "cells": {
    "C1": {
      "score": 8,
      "anchor": "8: 5-6 surfaces with algorithm depth; 10 not met because PQC/hybrid detection is not documented for the product",
      "urls": [
        "https://www.isara.com/",
        "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
        "https://www.isara.com/partner-msazure.html",
        "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf"
      ],
      "quote": "Agentless-first discovery across networks, servers, databases, code, CMDBs, KMSs, and more to map your complete cryptographic posture",
      "rationale": "The Azure whitepaper (§5–6) documents mechanisms for passive network monitoring of TLS and SSH via vTAP and the ISARA Network Analyzer, which covers surfaces (a) and (i). It also documents Azure Key Vault (e/f), endpoint scans (g) and database encryption queries (h). Certificates (b) are covered across pages. Depth: 'Inventory algorithms, protocols, primitives, key lengths, and device information.' That is 6 surfaces. Code (c) and OT/SCADA (j) are claimed without a mechanism. PQC/hybrid detection by the product is not documented in the URLs searched; only a vendor blog checklist mentions PQC validators.",
      "delta_vs_published": 1
    },
    "C2": {
      "score": 3,
      "anchor": "midpoint between 2 (dashboard-only) and 4 (proprietary export)",
      "urls": [
        "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
        "https://www.isara.com/",
        "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
        "https://www.isara.com/blog-posts/beyond-the-cbom-hype-setting-the-record-straight.html"
      ],
      "quote": "Provides dashboards and APIs for remediation prioritization",
      "rationale": "Dashboards, APIs and webhook integrations are documented, but no export format (CSV/PDF/JSON/CBOM) is documented in the URLs searched. I found no integrity mechanism or public sample. The vendor's own blog argues CBOMs are not essential, and I found no CBOM export claim. The 'Cryptography Validator Report' is form-gated and I did not fetch it.",
      "delta_vs_published": -2
    },
    "C3": {
      "score": 6,
      "anchor": "6: continuous monitoring with documented trend/historical reporting; 8 not met because no tamper-evident history is documented",
      "urls": [
        "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
        "https://www.isara.com/partner-msazure.html",
        "https://www.isara.com/solutions.html"
      ],
      "quote": "Supports continuous monitoring and historical analysis of cryptographic trends",
      "rationale": "Continuous monitoring, historical trend analysis and 'snapshots, trend views, and burn-down reporting' are documented. I found no drift alert mechanism, signed or hash-chained change history, or published latency. Drift detection appears only in a generic best-practice guide, not as a product mechanism.",
      "delta_vs_published": -2
    },
    "C4": {
      "score": 7,
      "anchor": "midpoint between 6 (categorical plus context) and 8 (numeric multi-factor score including data lifetime/HNDL)",
      "urls": [
        "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
        "https://www.isara.com/solutions.html",
        "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html"
      ],
      "quote": "Assigns risk-based posture scores based on algorithm strength, key size, and usage context",
      "rationale": "The posture score combines several factors and drives prioritized remediation. The Solutions page adds 'Risk scoring aligned to data sensitivity and exposure'. Data lifetime or HNDL is not documented as a scoring input; HNDL appears only as risk framing. No formula is published.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 0,
      "anchor": "0: not documented",
      "urls": [
        "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
        "https://www.isara.com/partner-msazure.html",
        "https://www.isara.com/",
        "https://www.isara.com/solutions.html",
        "https://www.isara.com/resources/index.html"
      ],
      "quote": "ISARA Advance uses automated agentless scanning to discover cryptographic assets across your environment, then analyzes each asset against current standards and best practices to identify risks, misconfigurations, and vulnerabilities.",
      "rationale": "This text describes the analysis method only. Accuracy metrics, false-positive handling and benchmarks are not documented in the URLs searched.",
      "delta_vs_published": -5
    },
    "C6": {
      "score": 6,
      "anchor": "6: one-way ticket/export plus guidance",
      "urls": [
        "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
        "https://www.isara.com/"
      ],
      "quote": "Remediate vulnerabilities through ticket-based workflows and CMDB integrations.",
      "rationale": "Ticketing and CMDB integration are documented ('connects with CMDBs, cloud-based KMSs, databases, and ticketing systems through built-in or webhook integrations'), along with prioritized remediation actions. I found no documented automated remediation action by the product itself. The key-rotation text in the Azure guide is generic advice. Bidirectional sync and verified closure are not documented.",
      "delta_vs_published": 0
    },
    "C7": {
      "score": 7,
      "anchor": "midpoint between 6 (dashboards plus exports) and 8 (exec and technical reports with documented compliance mapping)",
      "urls": [
        "https://www.isara.com/partner-msazure.html",
        "https://www.isara.com/",
        "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html"
      ],
      "quote": "Gain visibility into enterprise cryptographic risk through snapshots, trend views, and burn-down reporting that support executive decision-making.",
      "rationale": "Separate stakeholder views are documented: executive and board, GRC and application owners, and engineers. Compliance support is claimed ('Meet cryptographic inventory and reporting requirements under NSM-10 and OMB M-23-02'; PCI-DSS, DORA, NERC CIP), but no mapping mechanism, export or sample report is documented.",
      "delta_vs_published": 0
    }
  },
  "total": 5.58,
  "published_total": 6.53,
  "urls_that_failed": [
    "https://www.isara.com/resources/resource-center/addressing-the-quantum-threat-with-cryptographic-posture-management.html (no response, HTTP 000; the landing page was then found at /resource-center/..., but the whitepaper itself is form-gated and was NOT fetched)",
    "https://isara.com/company/crypto-validation-report.html (fetched; the sample 'Cryptographic Validation Report' is form-gated and was NOT fetched)"
  ],
  "notes": "The brief says the 2026.6 row was 'Not re-fetched this refresh; carried from 2026.4'. This is the first re-fetch. published_total is not stored in the brief. I computed it from the published cells [7,5,8,7,5,6,7] with the rubric weights. Half-point convention: a non-anchor score means the midpoint between the two named anchors. ISARA publishes no public docs portal, datasheet or release notes for Advance. The resources page lists only 2019–2020 datasheets, for Radiate and Catalyst. The most specific admissible evidence is three short (2–4 page) Azure partnership PDFs. They are largely generic best-practice text; only Whitepaper §6 and the Integration Brief §3 describe Advance specifically, and I did not credit generic advice (for example automated key rotation or drift detection) as product capability. The vendor's quantum-readiness blog maps its modules (Network Discovery, Validators, Application Discovery, Risk Prioritization, Actionability, Company-Wide Reporting) to a checklist. That mapping is a vendor self-assessment and was not used as evidence. The 2026 award is third-party recognition and inadmissible. C3 and C5 drops are rubric-systematic across all three products I scored. All quotes were checked by exact string match against fetched page or PDF text on 2026-09-26."
}
