Rank 3 / Established band / Confidence MOD

Keyfactor AgileSec + Command

Keyfactor / PQC discovery capability record for edition 2026.7.

6.53Index score / 10[1]

AgileSec’s scheduled ServiceNow connector imports cryptographic vulnerabilities and detections for investigation. S08S25

Established MOD

Seven criterion scores

C19

Discovery

How broadly and deeply does the product find cryptographic assets?

C54

Correctness

Is detection accuracy measured against named ground truth?

C67

Remediation loop

Can a finding move through ownership, action and verified closure?

C76

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

9 / 10

Weight 4/19 · 1.89 points of the overall score

Internal 1 October claim review: Partial or qualified support. Hybrid group handling is documented, but full surface count and parameter depth require multi-document reconciliation.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Documented surfaces: (a) Network Sensor and the CipherInsights TLS connector; (b) Cert Store Sensor and Command connector; (c) Git, GitHub, GitLab and Bitbucket source scans; (d) binaries, JAR/WAR and Docker/OCI images through the Container and Artifactory sensors; (e) Thales Luna HSM, PKCS#11 and Thales CTM; (f) AWS KMS, Azure Key Vault and GCP KMS; (g) Host Sensor through CrowdStrike and Tanium EDR; (h) MSSQL; (i) SSH key-exchange, encryption and MAC algorithms through CipherInsights. Hybrid KEX and DH-group parameters are handled. Key-size depth is not documented for each surface.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Resolved an issue where PQC hybrid algorithms ( X25519MLKEM768 ) and secure DH groups ( group14 and higher) were being incorrectly flagged as insecure.

Original scoring anchor: between 8 and 10: 8+ surfaces with PQC/hybrid detection documented, but algorithm+parameter depth documented for only some surfaces

Evidence artifact

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor explicitly documents CycloneDX CBOM 1.6 export per source, without export signature.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: CycloneDX 1.6 CBOM export is documented, and 3.5.1 fixed its conformance. Signing, hashing or any other integrity mechanism for the exported CBOM is not documented in the 3.4, 3.5.1, 3.6 or 3.6.4 release notes, the sensors-architecture page or the product page. A web search for signed CBOM export from Keyfactor returned nothing. The published 8 required an integrity mechanism.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Generate and download findings in Cyclone DX CBOM format (spec v1.6). CBOM can be downloaded per source.

Original scoring anchor: 6: standard-schema export documented, no integrity mechanism

Change detection

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents findings resolved across full scans, a concrete change-state rule.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Documented mechanisms: scheduled scans, incremental scans that compare the current context with the stored one, and auto-resolution between full scans. The product page's continuous-alert language is marketing. Tamper-evident (hash-chained or signed) history is not documented, so anchor 8 is not met.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

It automatically marks findings as "resolved" when they were detected in previous scans but are no longer present in the latest full scan.

Original scoring anchor: 6: scheduled rescans with documented diff/drift reporting

Risk quantification

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents compliant/high/medium/low classification; no numerical asset model inferred.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Each finding gets a policy-based risk score and a categorical class. The product page claims prioritization by 'exposure, severity, and business impact'. Data lifetime, HNDL and the formula are not documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

At this point, findings are no longer considered pending, and each is assigned a score classification displayed as: compliant, high risk, medium risk, or low risk.

Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context

Correctness

4 / 10

Weight 2/19 · 0.42 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor records false-positive correction for secure key exchange, without published precision/recall.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: False-positive corrections appear in the release notes. No precision or recall metric or benchmark was found in the AgileSec docs, the release notes 3.4 to 3.6.4, or a search of docs.keyfactor.com.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Fixed: protocol_insecure_kex Policy False Positives on Secure Key Exchange Algorithms.

Original scoring anchor: 4: accuracy or false-positive handling described, no metric

Remediation loop

7 / 10

Weight 2/19 · 0.74 points of the overall score

Internal 1 October claim review: Partial or qualified support. Connector API query is documented; ticket creation/automated remediation attribution requires closer source binding.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The ServiceNow VR connector pulls vulnerabilities and vulnerable items from AgileSec into ServiceNow on a schedule, one way. The raw pages were searched for clos, resolv, reopen, state and bidirection, and no write-back or VI closure logic was found. Command automates certificate enrollment, renewal and revocation from ServiceNow. Inside AgileSec, closure is verified by rescan through auto-resolution. The published 9 required documented bidirectional live write-back, which was not found.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

The Connector is used to query AgileSec’s API at a given schedule to perform the following actions: Get aggregation of Vulnerabilities from AgileSec Analytics.

Original scoring anchor: 7: one-way ticket creation plus automated remediation actions

Reporting

6 / 10

Weight 2/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents compliance dashboard/export, not a verified per-framework evidence mapping.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Dashboards (OpenSearch), CBOM export and an API are documented. The NIST and PCI-DSS compliance mapping appears only as a product-page marketing line with no mechanism. Separate executive and technical reports and a published sample report were not found.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Continuously assess and report on your compliance posture against industry standards like NIST, and regulatory frameworks like PCI-DSS.

Original scoring anchor: 6: dashboards plus exports

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Not renamed. The product is still called Keyfactor AgileSec, and the newest release in the docs navigation is 3.6.4, a maintenance release with no new features. Keyfactor bought CipherInsights from Quantum Xchange together with InfoSec Global in May 2025, and this did change the product. AgileSec now has a 'CipherInsights Connector' that imports passive-network TLS and SSH findings. CipherInsights also continues as a separate product (docs v13.0.0) that pushes certificates into Keyfactor Command. AgileSec 3.6 added a GCP KMS connector.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

The Keyfactor docs and keyfactor.com quotes were byte-verified by curl plus a text grep on the research host. The CipherInsights v13.0.0 intro at software.keyfactor.com was read only through WebFetch. The sensors-architecture page cited is the 3.4 docs version, and later versions were not diffed. AgileSec release notes carry no dates for 3.6 and 3.6.4. The 3.4 page dates itself December 2025, per WebFetch. The published C6=9 relied on ServiceNow Store listings and announcements (S25) that have no URL in the brief. The admissible docs show a one-way scheduled pull, not tenant write-back. The published C2=8 and C3=8 had no documented integrity or tamper-evident mechanism behind them. CipherInsights adds real-time passive network monitoring, but as a separately licensed product brought in through a connector. Whether it belongs to the 'AgileSec + Command' row is a scoping choice. It affects C1 (the SSH surface) and would not raise C3 without a documented tamper-evident history. PUBLISHED_TOTAL: the brief gives no total, so 7.37 is recomputed from published_cells with the rubric formula.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes