Crypto Finder is a powerful CLI tool for detecting cryptographic algorithm usage in source code repositories. Crypto Finder scans codebases using multiple scanning engines and outputs results in standardised formats including JSON and CycloneDX.
What cryptography is in your codebase?Algorithms, certificates, protocols, and keys — critical components that many teams struggle to inventory and assess with confidence.Without clear visibility, organisations face serious challenges:
Compliance: Standards like PCI-DSS, NIST, and other regulatory frameworks require an accurate cryptographic inventory.
Security: Outdated or weak cryptographic implementations introduce exploitable vulnerabilities.
Post-Quantum Readiness: Emerging quantum computing capabilities will render current encryption schemes obsolete.
Visibility: Manual audits are slow, inconsistent, and unscalable across large or fast-changing codebases.
Crypto Finder solves these challenges by automating cryptographic discovery, giving teams the insight they need to secure and modernise their code.
When the SCANOSS API is unavailable or the environment is air-gapped, Crypto Finder automatically switches to offline mode, using the most recent cached rules to continue scanning without interruption.