Rank 7 / Developing band / Confidence MOD

Fortanix Key Insight / PQC Central

Fortanix / PQC discovery capability record for edition 2026.7.

5.74Index score / 10[1]

Cryptographic inventory correlated to key management, with CBOM export generally available since release 25.07. S15

Developing MOD

Seven criterion scores

C19

Discovery

How broadly and deeply does the product find cryptographic assets?

C50

Correctness

Is detection accuracy measured against named ground truth?

C64

Remediation loop

Can a finding move through ownership, action and verified closure?

C77

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

9 / 10

Weight 4/19 · 1.89 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor documents multiple connector/surface types; cited Zeek quote alone is not a complete depth/hybrid proof.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: 7 surfaces documented (a network via Zeek, b certs, c source code, e KMS/HSM/Vault/DSM, f AWS/Azure/GCP services, g file-system agent, h Oracle/MSSQL DBs); key spec/size and PQC algorithms (ML-KEM/ML-DSA/LMS) documented for keys, but parameter depth not documented for code/file-system findings and hybrid detection not documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Fortanix Key Insight integrates with network security monitoring frameworks (for example, Zeek) to passively analyze mirrored network traffic and detect cryptographic artifacts such as certificates, TLS versions, cipher suites, and key exchange mechanisms on Linux systems.

Original scoring anchor: midpoint between 8 (5-6 surfaces with algorithm depth) and 10 (>=7 surfaces with algorithm+parameter depth and PQC/hybrid detection)

Evidence artifact

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor explicitly documents CycloneDX CBOM JSON export across named environments; no signed-export mechanism.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: CycloneDX CBOM export documented (GA 25.07, confirmed); signing/hash integrity and public sample not documented in the URLs searched, so 8 is not reached.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Fortanix Key Insight now supports Cryptography Bill of Materials (CBOM) export in CBOM JSON format, adhering to the CycloneDX standard, for cryptographic assets discovered across cloud environments (AWS, Azure), on-premises deployments, and external key sources

Original scoring anchor: 6: standard-schema export documented, no integrity mechanism

Change detection

5 / 10

Weight 3/19 · 0.79 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor documents manual RESCAN and asset updates; scheduled diff/drift automation needed for higher anchor is absent.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Manual rescan for cloud connections plus systemd-timer scheduling for the on-prem agent are documented; a diff/drift report, change alerts and tamper-evident history are not documented in the URLs searched. 'Continuously analyzes' language has no documented mechanism.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Click RESCAN on the top-right corner of the Overview or Assessment page to perform a rescan and verify if any keys have been added, deleted, or updated in the CSP organization.

Original scoring anchor: midpoint between 4 (point-in-time scans re-run manually) and 6 (scheduled rescans with documented diff/drift reporting)

Risk quantification

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor documents categorical risk counts with context; scoring details and validation are not published.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Critical/High/Medium/Good categories combine algorithm non-compliance with usage/permission context; PQC readiness is a published formula but only percentage = (total - vulnerableTotal)/total (a vulnerable/not flag aggregate). No data-lifetime/HNDL factor documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

A critical risk score indicates the total number of deleted keys, expired certificates, Services encrypted with cross-account key usage, non-compliant certificates by algorithm, and unencrypted cloud services detected that need attention.

Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context

Correctness

0 / 10

Weight 2/19 · 0.00 points of the overall score

Internal 1 October claim review: Claim not verified from accessible evidence. Zero reflects no metric in bounded accessible docs, not an observed correctness result.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: No accuracy metric, test methodology or FP handling documented in any page fetched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

not documented in the URLs listed (no precision, recall, benchmark, accuracy or false-positive handling statement found)

Original scoring anchor: 0: not documented

Remediation loop

4 / 10

Weight 2/19 · 0.42 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor says corrective actions can occur in platform but gives no reproducible ticket/action mechanism.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Docs give recommendations (stronger algorithms, remove unused keys); press release says 'build a roadmap in ... ServiceNow or Jira' and overview claims corrective actions, but no integration or action mechanism is documented on support.fortanix.com (site search for ServiceNow/Jira/ticket in Key Insight returned nothing).

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

This allows organizations not only to identify cryptographic risks but also to take corrective actions from within the same platform.

Original scoring anchor: 4: remediation guidance only (ticketing and in-platform action named without mechanism, capped per rubric line 19)

Reporting

7 / 10

Weight 2/19 · 0.74 points of the overall score

Internal 1 October claim review: Partial or qualified support. PDF assessment report is documented; archived excerpt not reproduced and framework-to-report mapping remains unverified.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Dashboards, PDF assessment report, CSV and CBOM exports, API, and policy mapping to NIST 800-57/PCI DSS/FIPS documented; separate executive vs technical reports and PQC frameworks (IR 8547, CNSA 2.0) not documented; no public sample report.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Click DOWNLOAD REPORT on the top-right corner of the Assessment page to view the Data Security Assessment Report for the AWS connection in PDF format.

Original scoring anchor: midpoint between 6 (dashboards plus exports) and 8 (executive and technical reports with documented compliance mapping)

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Active, same name. Latest Key Insight release listed is 27.0 (2026-06-26, 'Added support for Azure Certificates'); 26.05 (2026-05-15) added Zeek-based network-log scanning. No release after Aug 2026 listed; no rename or acquisition found (searched 2026-09-26).

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

Quotes were extracted through a fetch tool whose intermediary model returns page text; the .md variants of support.fortanix.com pages were used where possible and markup stripped. Two fetches (cloud-connection-scanning-configuration index and policy-center index) returned my own prompt text echoed back and were discarded as evidence. Between-anchor convention: where anchors are 2 apart, the integer midpoint is used and both anchors named. Brief S15's sourcing ('CBOM GA from 25.07') is confirmed by the 25.07 release note. Largest move is C5 5->0: no accuracy evidence in any fetched page. Staging note's 'instant risk score' is marketing on fortanix.com/platform/key-insight; the documented PQC readiness formula is a percentage of non-vulnerable assets.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes