Discovery
How broadly and deeply does the product find cryptographic assets?
Rank 7 / Developing band / Confidence MOD
Fortanix / PQC discovery capability record for edition 2026.7.
Cryptographic inventory correlated to key management, with CBOM export generally available since release 25.07. S15
Developing MOD
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals
Research record · reviewed 2026-09-26
Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.
Weight 4/19 · 1.89 points of the overall score
Internal 1 October claim review: Partial or qualified support. Vendor documents multiple connector/surface types; cited Zeek quote alone is not a complete depth/hybrid proof.
Read the full review record · Cell fortanix-key-insight-pqc-central/C1. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: 7 surfaces documented (a network via Zeek, b certs, c source code, e KMS/HSM/Vault/DSM, f AWS/Azure/GCP services, g file-system agent, h Oracle/MSSQL DBs); key spec/size and PQC algorithms (ML-KEM/ML-DSA/LMS) documented for keys, but parameter depth not documented for code/file-system findings and hybrid detection not documented.
URL availability labels below reflect the historical 30 September source-access screen.
Fortanix Key Insight integrates with network security monitoring frameworks (for example, Zeek) to passively analyze mirrored network traffic and detect cryptographic artifacts such as certificates, TLS versions, cipher suites, and key exchange mechanisms on Linux systems.
Original scoring anchor: midpoint between 8 (5-6 surfaces with algorithm depth) and 10 (>=7 surfaces with algorithm+parameter depth and PQC/hybrid detection)
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Narrow feature documented. Vendor explicitly documents CycloneDX CBOM JSON export across named environments; no signed-export mechanism.
Read the full review record · Cell fortanix-key-insight-pqc-central/C2. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: CycloneDX CBOM export documented (GA 25.07, confirmed); signing/hash integrity and public sample not documented in the URLs searched, so 8 is not reached.
URL availability labels below reflect the historical 30 September source-access screen.
Fortanix Key Insight now supports Cryptography Bill of Materials (CBOM) export in CBOM JSON format, adhering to the CycloneDX standard, for cryptographic assets discovered across cloud environments (AWS, Azure), on-premises deployments, and external key sources
Original scoring anchor: 6: standard-schema export documented, no integrity mechanism
Weight 3/19 · 0.79 points of the overall score
Internal 1 October claim review: Partial or qualified support. Vendor documents manual RESCAN and asset updates; scheduled diff/drift automation needed for higher anchor is absent.
Read the full review record · Cell fortanix-key-insight-pqc-central/C3. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Manual rescan for cloud connections plus systemd-timer scheduling for the on-prem agent are documented; a diff/drift report, change alerts and tamper-evident history are not documented in the URLs searched. 'Continuously analyzes' language has no documented mechanism.
URL availability labels below reflect the historical 30 September source-access screen.
Click RESCAN on the top-right corner of the Overview or Assessment page to perform a rescan and verify if any keys have been added, deleted, or updated in the CSP organization.
Original scoring anchor: midpoint between 4 (point-in-time scans re-run manually) and 6 (scheduled rescans with documented diff/drift reporting)
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Partial or qualified support. Vendor documents categorical risk counts with context; scoring details and validation are not published.
Read the full review record · Cell fortanix-key-insight-pqc-central/C4. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Critical/High/Medium/Good categories combine algorithm non-compliance with usage/permission context; PQC readiness is a published formula but only percentage = (total - vulnerableTotal)/total (a vulnerable/not flag aggregate). No data-lifetime/HNDL factor documented.
URL availability labels below reflect the historical 30 September source-access screen.
A critical risk score indicates the total number of deleted keys, expired certificates, Services encrypted with cross-account key usage, non-compliant certificates by algorithm, and unencrypted cloud services detected that need attention.
Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context
Weight 2/19 · 0.00 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Zero reflects no metric in bounded accessible docs, not an observed correctness result.
Read the full review record · Cell fortanix-key-insight-pqc-central/C5. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: No accuracy metric, test methodology or FP handling documented in any page fetched.
URL availability labels below reflect the historical 30 September source-access screen.
not documented in the URLs listed (no precision, recall, benchmark, accuracy or false-positive handling statement found)
Original scoring anchor: 0: not documented
Archived search note: web search 2026-09-26: site:support.fortanix.com "Key Insight" "false positive" OR accuracy OR precision (no correctness content). This is not a source URL or a reproducible capability test.
Weight 2/19 · 0.42 points of the overall score
Internal 1 October claim review: Partial or qualified support. Vendor says corrective actions can occur in platform but gives no reproducible ticket/action mechanism.
Read the full review record · Cell fortanix-key-insight-pqc-central/C6. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Docs give recommendations (stronger algorithms, remove unused keys); press release says 'build a roadmap in ... ServiceNow or Jira' and overview claims corrective actions, but no integration or action mechanism is documented on support.fortanix.com (site search for ServiceNow/Jira/ticket in Key Insight returned nothing).
URL availability labels below reflect the historical 30 September source-access screen.
This allows organizations not only to identify cryptographic risks but also to take corrective actions from within the same platform.
Original scoring anchor: 4: remediation guidance only (ticketing and in-platform action named without mechanism, capped per rubric line 19)
Weight 2/19 · 0.74 points of the overall score
Internal 1 October claim review: Partial or qualified support. PDF assessment report is documented; archived excerpt not reproduced and framework-to-report mapping remains unverified.
Read the full review record · Cell fortanix-key-insight-pqc-central/C7. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Dashboards, PDF assessment report, CSV and CBOM exports, API, and policy mapping to NIST 800-57/PCI DSS/FIPS documented; separate executive vs technical reports and PQC frameworks (IR 8547, CNSA 2.0) not documented; no public sample report.
URL availability labels below reflect the historical 30 September source-access screen.
Click DOWNLOAD REPORT on the top-right corner of the Assessment page to view the Data Security Assessment Report for the AWS connection in PDF format.
Original scoring anchor: midpoint between 6 (dashboards plus exports) and 8 (executive and technical reports with documented compliance mapping)
Documentation reviewed 2026-09-26: Active, same name. Latest Key Insight release listed is 27.0 (2026-06-26, 'Added support for Azure Certificates'); 26.05 (2026-05-15) added Zeek-based network-log scanning. No release after Aug 2026 listed; no rename or acquisition found (searched 2026-09-26).
Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.
Quotes were extracted through a fetch tool whose intermediary model returns page text; the .md variants of support.fortanix.com pages were used where possible and markup stripped. Two fetches (cloud-connection-scanning-configuration index and policy-center index) returned my own prompt text echoed back and were discarded as evidence. Between-anchor convention: where anchors are 2 apart, the integer midpoint is used and both anchors named. Brief S15's sourcing ('CBOM GA from 25.07') is confirmed by the 25.07 release note. Largest move is C5 5->0: no accuracy evidence in any fetched page. Staging note's 'instant risk score' is marketing on fortanix.com/platform/key-insight; the documented PQC readiness formula is a percentage of non-vulnerable assets.
Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes