Skip to content
KOR IT

Projects / 06

Cryptagion

A KOR IT venture for cryptographic discovery, inventory and post-quantum migration planning. Full detail lives on the venture page and at cryptagion.io.

ProductCryptographic Security · Cryptographic SecurityJanuary 2026

Overview

Cryptagion addresses cryptographic discovery and post-quantum readiness: identifying where cryptography is used across an estate, what algorithms and key material are involved, what depends on them, and what a migration would actually have to touch.

It is organised around a lifecycle rather than a single scan, because the difficulty is rarely finding one weak algorithm — it is maintaining an accurate picture of cryptographic dependencies while systems keep changing.

  1. Discover — locate cryptographic usage across systems, code and configuration.
  2. Score — assess risk, including deprecated algorithms and quantum-vulnerable primitives.
  3. CBOM — produce a Cryptographic Bill of Materials describing usage and dependencies.
  4. Report — present the inventory and its risk posture in a form stakeholders can act on.
  5. Migrate — plan and sequence the transition towards crypto agility and post-quantum readiness.

The problem

Organisations cannot migrate cryptography they cannot identify. Cryptographic usage is spread across application code, libraries, protocol configuration, certificates, hardware modules and third-party services, and almost no organisation holds a complete inventory of it.

Post-quantum migration turns this from a hygiene concern into a planning problem with a deadline. Sequencing a migration requires knowing not only where an algorithm is used but what depends on that usage, and dependency structure is exactly what an inventory-free estate cannot supply.

Crypto agility — the ability to change cryptographic primitives without redesigning the systems that use them — is the property that makes future transitions tractable. It cannot be assessed without an inventory either.

Architecture

The architecture follows the lifecycle: discovery feeds an inventory, the inventory is scored for risk, the scored inventory is expressed as a Cryptographic Bill of Materials, and the CBOM drives reporting and migration planning.

Technical detail about how each stage works is maintained on the venture's own pages rather than duplicated here, so that there is a single description to keep accurate.

Security model

A cryptographic inventory is itself sensitive: a complete list of where weak or deprecated cryptography is used is a target list. Any deployment model has to treat the inventory and the CBOM as confidential assets rather than as reports.

Discovered inventory
Treated as sensitive by default. It describes weaknesses before they are remediated.
Scanned systems
Discovery must not alter the systems it examines, and must operate within the access granted to it rather than seeking additional reach.

The venture pages carry the detailed positioning. This page does not restate it.

Current status

Cryptagion is a KOR IT venture with its own brand and website. Current information about it is published at cryptagion.io and on the venture page at /ventures/cryptagion.

No further status is asserted here.

Limitations

One limitation of any discovery approach is coverage: cryptography embedded in third-party binaries, appliances or managed services is harder to observe than cryptography in source code, and an inventory that omits those is incomplete in a way that is easy to overlook.

A second is currency. An inventory is accurate at the moment it is produced, and estates change continuously, so a CBOM is a snapshot unless discovery is continuous.

Roadmap

  1. Read the venture page at /ventures/cryptagion for the full description.
  2. Visit cryptagion.io for current information about the venture.
  3. Follow KOR IT research on cryptographic security for the underlying technical work.

Detail

Topics

  • cryptography
  • cryptographic discovery
  • CBOM
  • crypto agility
  • post-quantum
  • migration planning