Discovery
How broadly and deeply does the product find cryptographic assets?
Rank 3 / Established band / Confidence MOD
Keyfactor / PQC discovery capability record for edition 2026.7.
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals
Research record · reviewed 2026-09-26
Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.
Weight 4/19 · 1.89 points of the overall score
Internal 1 October claim review: Partial or qualified support. Hybrid group handling is documented, but full surface count and parameter depth require multi-document reconciliation.
Read the full review record · Cell keyfactor-agilesec-command/C1. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Documented surfaces: (a) Network Sensor and the CipherInsights TLS connector; (b) Cert Store Sensor and Command connector; (c) Git, GitHub, GitLab and Bitbucket source scans; (d) binaries, JAR/WAR and Docker/OCI images through the Container and Artifactory sensors; (e) Thales Luna HSM, PKCS#11 and Thales CTM; (f) AWS KMS, Azure Key Vault and GCP KMS; (g) Host Sensor through CrowdStrike and Tanium EDR; (h) MSSQL; (i) SSH key-exchange, encryption and MAC algorithms through CipherInsights. Hybrid KEX and DH-group parameters are handled. Key-size depth is not documented for each surface.
URL availability labels below reflect the historical 30 September source-access screen.
Resolved an issue where PQC hybrid algorithms ( X25519MLKEM768 ) and secure DH groups ( group14 and higher) were being incorrectly flagged as insecure.
Original scoring anchor: between 8 and 10: 8+ surfaces with PQC/hybrid detection documented, but algorithm+parameter depth documented for only some surfaces
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Narrow feature documented. Vendor explicitly documents CycloneDX CBOM 1.6 export per source, without export signature.
Read the full review record · Cell keyfactor-agilesec-command/C2. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: CycloneDX 1.6 CBOM export is documented, and 3.5.1 fixed its conformance. Signing, hashing or any other integrity mechanism for the exported CBOM is not documented in the 3.4, 3.5.1, 3.6 or 3.6.4 release notes, the sensors-architecture page or the product page. A web search for signed CBOM export from Keyfactor returned nothing. The published 8 required an integrity mechanism.
URL availability labels below reflect the historical 30 September source-access screen.
Generate and download findings in Cyclone DX CBOM format (spec v1.6). CBOM can be downloaded per source.
Original scoring anchor: 6: standard-schema export documented, no integrity mechanism
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Narrow feature documented. Vendor documents findings resolved across full scans, a concrete change-state rule.
Read the full review record · Cell keyfactor-agilesec-command/C3. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Documented mechanisms: scheduled scans, incremental scans that compare the current context with the stored one, and auto-resolution between full scans. The product page's continuous-alert language is marketing. Tamper-evident (hash-chained or signed) history is not documented, so anchor 8 is not met.
URL availability labels below reflect the historical 30 September source-access screen.
It automatically marks findings as "resolved" when they were detected in previous scans but are no longer present in the latest full scan.
Original scoring anchor: 6: scheduled rescans with documented diff/drift reporting
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Narrow feature documented. Vendor documents compliant/high/medium/low classification; no numerical asset model inferred.
Read the full review record · Cell keyfactor-agilesec-command/C4. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Each finding gets a policy-based risk score and a categorical class. The product page claims prioritization by 'exposure, severity, and business impact'. Data lifetime, HNDL and the formula are not documented.
URL availability labels below reflect the historical 30 September source-access screen.
At this point, findings are no longer considered pending, and each is assigned a score classification displayed as: compliant, high risk, medium risk, or low risk.
Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context
Weight 2/19 · 0.42 points of the overall score
Internal 1 October claim review: Narrow feature documented. Vendor records false-positive correction for secure key exchange, without published precision/recall.
Read the full review record · Cell keyfactor-agilesec-command/C5. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: False-positive corrections appear in the release notes. No precision or recall metric or benchmark was found in the AgileSec docs, the release notes 3.4 to 3.6.4, or a search of docs.keyfactor.com.
URL availability labels below reflect the historical 30 September source-access screen.
Fixed: protocol_insecure_kex Policy False Positives on Secure Key Exchange Algorithms.
Original scoring anchor: 4: accuracy or false-positive handling described, no metric
Weight 2/19 · 0.74 points of the overall score
Internal 1 October claim review: Partial or qualified support. Connector API query is documented; ticket creation/automated remediation attribution requires closer source binding.
Read the full review record · Cell keyfactor-agilesec-command/C6. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: The ServiceNow VR connector pulls vulnerabilities and vulnerable items from AgileSec into ServiceNow on a schedule, one way. The raw pages were searched for clos, resolv, reopen, state and bidirection, and no write-back or VI closure logic was found. Command automates certificate enrollment, renewal and revocation from ServiceNow. Inside AgileSec, closure is verified by rescan through auto-resolution. The published 9 required documented bidirectional live write-back, which was not found.
URL availability labels below reflect the historical 30 September source-access screen.
The Connector is used to query AgileSec’s API at a given schedule to perform the following actions: Get aggregation of Vulnerabilities from AgileSec Analytics.
Original scoring anchor: 7: one-way ticket creation plus automated remediation actions
Weight 2/19 · 0.63 points of the overall score
Internal 1 October claim review: Narrow feature documented. Vendor documents compliance dashboard/export, not a verified per-framework evidence mapping.
Read the full review record · Cell keyfactor-agilesec-command/C7. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Dashboards (OpenSearch), CBOM export and an API are documented. The NIST and PCI-DSS compliance mapping appears only as a product-page marketing line with no mechanism. Separate executive and technical reports and a published sample report were not found.
URL availability labels below reflect the historical 30 September source-access screen.
Continuously assess and report on your compliance posture against industry standards like NIST, and regulatory frameworks like PCI-DSS.
Original scoring anchor: 6: dashboards plus exports
Documentation reviewed 2026-09-26: Not renamed. The product is still called Keyfactor AgileSec, and the newest release in the docs navigation is 3.6.4, a maintenance release with no new features. Keyfactor bought CipherInsights from Quantum Xchange together with InfoSec Global in May 2025, and this did change the product. AgileSec now has a 'CipherInsights Connector' that imports passive-network TLS and SSH findings. CipherInsights also continues as a separate product (docs v13.0.0) that pushes certificates into Keyfactor Command. AgileSec 3.6 added a GCP KMS connector.
Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.
The Keyfactor docs and keyfactor.com quotes were byte-verified by curl plus a text grep on the research host. The CipherInsights v13.0.0 intro at software.keyfactor.com was read only through WebFetch. The sensors-architecture page cited is the 3.4 docs version, and later versions were not diffed. AgileSec release notes carry no dates for 3.6 and 3.6.4. The 3.4 page dates itself December 2025, per WebFetch. The published C6=9 relied on ServiceNow Store listings and announcements (S25) that have no URL in the brief. The admissible docs show a one-way scheduled pull, not tenant write-back. The published C2=8 and C3=8 had no documented integrity or tamper-evident mechanism behind them. CipherInsights adds real-time passive network monitoring, but as a separately licensed product brought in through a connector. Whether it belongs to the 'AgileSec + Command' row is a scoping choice. It affects C1 (the SSH surface) and would not raise C3 without a documented tamper-evident history. PUBLISHED_TOTAL: the brief gives no total, so 7.37 is recomputed from published_cells with the rubric formula.
Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes