{
  "slug": "keyfactor-agilesec-command",
  "name": "Keyfactor AgileSec + Command",
  "vendor": "Keyfactor",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Not renamed. The product is still called Keyfactor AgileSec, and the newest release in the docs navigation is 3.6.4, a maintenance release with no new features. Keyfactor bought CipherInsights from Quantum Xchange together with InfoSec Global in May 2025, and this did change the product. AgileSec now has a 'CipherInsights Connector' that imports passive-network TLS and SSH findings. CipherInsights also continues as a separate product (docs v13.0.0) that pushes certificates into Keyfactor Command. AgileSec 3.6 added a GCP KMS connector.",
    "url": "https://docs.keyfactor.com/agilesec/latest/cipher-insights-sensor-user-guide"
  },
  "cells": {
    "C1": {
      "score": 9,
      "anchor": "between 8 and 10: 8+ surfaces with PQC/hybrid detection documented, but algorithm+parameter depth documented for only some surfaces",
      "urls": [
        "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
        "https://docs.keyfactor.com/agilesec/latest/modules",
        "https://docs.keyfactor.com/agilesec/latest/cipher-insights-sensor-user-guide",
        "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
        "https://docs.keyfactor.com/agilesec/latest/agilesec-3-6-release-notes"
      ],
      "quote": "Resolved an issue where PQC hybrid algorithms ( X25519MLKEM768 ) and secure DH groups ( group14 and higher) were being incorrectly flagged as insecure.",
      "rationale": "Documented surfaces: (a) Network Sensor and the CipherInsights TLS connector; (b) Cert Store Sensor and Command connector; (c) Git, GitHub, GitLab and Bitbucket source scans; (d) binaries, JAR/WAR and Docker/OCI images through the Container and Artifactory sensors; (e) Thales Luna HSM, PKCS#11 and Thales CTM; (f) AWS KMS, Azure Key Vault and GCP KMS; (g) Host Sensor through CrowdStrike and Tanium EDR; (h) MSSQL; (i) SSH key-exchange, encryption and MAC algorithms through CipherInsights. Hybrid KEX and DH-group parameters are handled. Key-size depth is not documented for each surface.",
      "delta_vs_published": 0
    },
    "C2": {
      "score": 6,
      "anchor": "6: standard-schema export documented, no integrity mechanism",
      "urls": [
        "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes",
        "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes"
      ],
      "quote": "Generate and download findings in Cyclone DX CBOM format (spec v1.6). CBOM can be downloaded per source.",
      "rationale": "CycloneDX 1.6 CBOM export is documented, and 3.5.1 fixed its conformance. Signing, hashing or any other integrity mechanism for the exported CBOM is not documented in the 3.4, 3.5.1, 3.6 or 3.6.4 release notes, the sensors-architecture page or the product page. A web search for signed CBOM export from Keyfactor returned nothing. The published 8 required an integrity mechanism.",
      "delta_vs_published": -2
    },
    "C3": {
      "score": 6,
      "anchor": "6: scheduled rescans with documented diff/drift reporting",
      "urls": [
        "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
        "https://www.keyfactor.com/products/cryptographic-discovery-inventory/"
      ],
      "quote": "It automatically marks findings as \"resolved\" when they were detected in previous scans but are no longer present in the latest full scan.",
      "rationale": "Documented mechanisms: scheduled scans, incremental scans that compare the current context with the stored one, and auto-resolution between full scans. The product page's continuous-alert language is marketing. Tamper-evident (hash-chained or signed) history is not documented, so anchor 8 is not met.",
      "delta_vs_published": -2
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical risk levels from algorithm vulnerability plus some context",
      "urls": [
        "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
        "https://www.keyfactor.com/products/cryptographic-discovery-inventory/"
      ],
      "quote": "At this point, findings are no longer considered pending, and each is assigned a score classification displayed as: compliant, high risk, medium risk, or low risk.",
      "rationale": "Each finding gets a policy-based risk score and a categorical class. The product page claims prioritization by 'exposure, severity, and business impact'. Data lifetime, HNDL and the formula are not documented.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 4,
      "anchor": "4: accuracy or false-positive handling described, no metric",
      "urls": [
        "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes"
      ],
      "quote": "Fixed: protocol_insecure_kex Policy False Positives on Secure Key Exchange Algorithms.",
      "rationale": "False-positive corrections appear in the release notes. No precision or recall metric or benchmark was found in the AgileSec docs, the release notes 3.4 to 3.6.4, or a search of docs.keyfactor.com.",
      "delta_vs_published": 0
    },
    "C6": {
      "score": 7,
      "anchor": "7: one-way ticket creation plus automated remediation actions",
      "urls": [
        "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr",
        "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr-operations",
        "https://www.keyfactor.com/servicenow-announcement/"
      ],
      "quote": "The Connector is used to query AgileSec’s API at a given schedule to perform the following actions: Get aggregation of Vulnerabilities from AgileSec Analytics.",
      "rationale": "The ServiceNow VR connector pulls vulnerabilities and vulnerable items from AgileSec into ServiceNow on a schedule, one way. The raw pages were searched for clos, resolv, reopen, state and bidirection, and no write-back or VI closure logic was found. Command automates certificate enrollment, renewal and revocation from ServiceNow. Inside AgileSec, closure is verified by rescan through auto-resolution. The published 9 required documented bidirectional live write-back, which was not found.",
      "delta_vs_published": -2
    },
    "C7": {
      "score": 6,
      "anchor": "6: dashboards plus exports",
      "urls": [
        "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
        "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes"
      ],
      "quote": "Continuously assess and report on your compliance posture against industry standards like NIST, and regulatory frameworks like PCI-DSS.",
      "rationale": "Dashboards (OpenSearch), CBOM export and an API are documented. The NIST and PCI-DSS compliance mapping appears only as a product-page marketing line with no mechanism. Separate executive and technical reports and a published sample report were not found.",
      "delta_vs_published": 0
    }
  },
  "total": 6.53,
  "published_total": 7.37,
  "urls_that_failed": [
    "https://docs.keyfactor.com/agilesec/latest/cipherinsights-connector-user-guide (404; the correct slug is cipher-insights-sensor-user-guide)"
  ],
  "notes": "The Keyfactor docs and keyfactor.com quotes were byte-verified by curl plus a text grep on the research host. The CipherInsights v13.0.0 intro at software.keyfactor.com was read only through WebFetch. The sensors-architecture page cited is the 3.4 docs version, and later versions were not diffed. AgileSec release notes carry no dates for 3.6 and 3.6.4. The 3.4 page dates itself December 2025, per WebFetch. The published C6=9 relied on ServiceNow Store listings and announcements (S25) that have no URL in the brief. The admissible docs show a one-way scheduled pull, not tenant write-back. The published C2=8 and C3=8 had no documented integrity or tamper-evident mechanism behind them. CipherInsights adds real-time passive network monitoring, but as a separately licensed product brought in through a connector. Whether it belongs to the 'AgileSec + Command' row is a scoping choice. It affects C1 (the SSH surface) and would not raise C3 without a documented tamper-evident history. PUBLISHED_TOTAL: the brief gives no total, so 7.37 is recomputed from published_cells with the rubric formula."
}
