Crypto Agility & AI Security Assessment

Demonstration Posture Report

Purpose: validate the assessment pipeline against a multi-account, multi-region synthetic enterprise at customer-scale volumes. Metrics represent the full generated population; interactive drill-down is intentionally capped for browser performance. No customer data or credentials were accessed.

Enterprise scope & evidence coverage

Scenario / customer scope
Rental Car · Production
Accounts / organizational units
100 / 25
Regions observed
4
Evidence model
Synthetic / provenance simulated

Full-population metrics are generated across the configured enterprise-scale scenario and environment. Interactive drill-down is capped at 20,000 records to keep the report responsive.

62
Elevated
Enterprise posture score / 100
25,000
Systems assessed
18,762
Security findings
50,024
Evidence & audit events
4,283
HNDL-exposed systems
188
Migrations blocked
6.1%
PQC-ready systems
10
Business units

Findings by severity

Critical 1180
High 11898
Medium 5684

Cryptographic estate

ECC P-256 4979
RSA-2048 4011
AES-256 3206
RSA-3072 3055
ECC P-384 2944
AES-128 2051

Top risk signals

Click a signal to filter the finding explorer below.

HNDL exposure4283
PQC migration required4283
Certificate expires <90d1949
Certificate expires <30d1613
Missing asset owner1401
HSM capability gap1146
Weak RSA key980
Key rotation overdue820
Missing evidence611
SHA-1 usage507

Systems by business unit

Click a business unit to filter the finding explorer below.

Payments2592
Digital Products2571
Fleet Operations2555
Telematics2517
Supply Chain2493
Corporate IT2485
Data & Analytics2479
Security2455

GenAI & Internal LLM Risk Assessments

AI risk by severity

Critical 168
High 2448
Moderate 12536
Low 20329

AI risk profile

50,000
AI assessments
42
Critical
816
High

Combined GenAI exposure and internal LLM misuse. AI findings are included directly in the unified Finding Explorer.

Top AI risk signals

Click a signal to filter the unified Finding Explorer to AI Risk.

GenAI exposure: Sensitive data to model12559
Internal LLM misuse: Sensitive internal prompt5624
GenAI exposure: Unapproved external model4547
Internal LLM misuse: Unapproved model or endpoint3614
GenAI exposure: Shadow AI use3011
Internal LLM misuse: Excessive data access2537
Internal LLM misuse: Policy bypass behavior2112
GenAI exposure: Prompt exfiltration signal1477

AI risk by business unit

Click a business unit to filter the unified Finding Explorer to AI Risk.

Payments3726
Digital Products3717
Fleet Operations3627
Telematics3558
Corporate IT3553
Security3491
Supply Chain3490
Data & Analytics3481
Reservations3481
Customer Experience3357

C-level summary

Enterprise risk is concentrated where modernization constraints, business exposure, and control gaps intersect. The immediate priority is to reduce critical and high findings while removing the technology dependencies that can block migration — particularly legacy algorithms, HNDL exposure, HSM/PKI constraints, certificate and ownership gaps, and unsupported libraries. In parallel, AI risk requires governance over sensitive-data flows, unapproved models or endpoints, prompt-mediated exfiltration, excessive data access, and policy-bypass behavior. For the CEO, this frames the business exposure and investment priorities; for the CTO, it identifies engineering dependencies that can delay modernization; for the CISO, it identifies the control and evidence gaps requiring remediation. Use the unified Finding Explorer to move from an enterprise signal to the affected system, evidence, recommended action, and remediation status.

Finding Explorer

One investigation surface for cryptographic and AI risk findings. Use the scope toggle, filters, or any risk signal above to drill down.

DomainSeveritySignalSystemBusiness unitRecommended action
CryptographyMediumCertificate expires <90dFleet-Platform-00001Corporate ITSchedule rotation.
CryptographyHighHNDL exposureDispatch-Platform-00004PaymentsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredDispatch-Platform-00004PaymentsSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureReservation-API-00005SecurityPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredReservation-API-00005SecuritySelect approved hybrid target and schedule migration.
CryptographyHighKey rotation overdueReservation-API-00005SecurityRotate key and capture evidence.
CryptographyMediumMissing evidenceReservation-API-00006Data & AnalyticsCollect and seal evidence snapshot.
CryptographyHighCertificate expires <30dCustomer-Portal-00007ReservationsRotate certificate and validate dependent chains.
CryptographyCriticalHNDL exposureVehicle-Telematics-00009Supply ChainPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredVehicle-Telematics-00009Supply ChainSelect approved hybrid target and schedule migration.
CryptographyMediumWeak RSA keyVehicle-Telematics-00009Supply ChainMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighSHA-1 usageVehicle-Telematics-00013Digital ProductsReplace primitive and validate dependent applications.
CryptographyMediumMissing asset ownerPayment-Service-00015Corporate ITAssign an owner and establish review cadence.
CryptographyHighSHA-1 usageDispatch-Platform-00016Data & AnalyticsReplace primitive and validate dependent applications.
CryptographyMediumCertificate expires <90dDispatch-Platform-00016Data & AnalyticsSchedule rotation.
CryptographyHighKey rotation overdueIdentity-Platform-00017Fleet OperationsRotate key and capture evidence.
CryptographyHighHNDL exposureMobile-Backend-00018PaymentsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredMobile-Backend-00018PaymentsSelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dMobile-Backend-00018PaymentsRotate certificate and validate dependent chains.
CryptographyMediumCertificate expires <90dDispatch-Platform-00020Supply ChainSchedule rotation.
CryptographyMediumWeak RSA keyMobile-Backend-00021Customer ExperienceMove to approved stronger or hybrid profile during lifecycle work.
CryptographyMediumThird-party dependencyAnalytics-Lake-00023PaymentsObtain vendor roadmap and migration compatibility statement.
CryptographyHighSHA-1 usageData-Warehouse-00024ReservationsReplace primitive and validate dependent applications.
CryptographyHighHNDL exposureIdentity-Platform-00026Data & AnalyticsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredIdentity-Platform-00026Data & AnalyticsSelect approved hybrid target and schedule migration.
CryptographyMediumCertificate expires <90dIdentity-Platform-00026Data & AnalyticsSchedule rotation.
CryptographyHighCertificate expires <30dDispatch-Platform-00027Fleet OperationsRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dVehicle-Telematics-00032Data & AnalyticsRotate certificate and validate dependent chains.
CryptographyMediumMissing evidenceCertificate-Authority-00034Customer ExperienceCollect and seal evidence snapshot.
CryptographyHighCertificate expires <30dMobile-Backend-00037TelematicsRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dFleet-Platform-00042TelematicsRotate certificate and validate dependent chains.
CryptographyHighHNDL exposureVehicle-Telematics-00043Data & AnalyticsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredVehicle-Telematics-00043Data & AnalyticsSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureCertificate-Authority-00052Supply ChainPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredCertificate-Authority-00052Supply ChainSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureDispatch-Platform-00053Supply ChainPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredDispatch-Platform-00053Supply ChainSelect approved hybrid target and schedule migration.
CryptographyMediumMissing asset ownerVehicle-Telematics-00054Customer ExperienceAssign an owner and establish review cadence.
CryptographyHighKey rotation overdueVehicle-Telematics-00054Customer ExperienceRotate key and capture evidence.
CryptographyHighHNDL exposureReservation-API-00057Digital ProductsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredReservation-API-00057Digital ProductsSelect approved hybrid target and schedule migration.
CryptographyHighHSM capability gapCertificate-Authority-00060Corporate ITUpgrade/configure HSM before migration.
CryptographyMediumCertificate expires <90dAnalytics-Lake-00061Data & AnalyticsSchedule rotation.
CryptographyHighCertificate expires <30dFleet-Platform-00064Fleet OperationsRotate certificate and validate dependent chains.
CryptographyCriticalHNDL exposureMobile-Backend-00065Fleet OperationsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredMobile-Backend-00065Fleet OperationsSelect approved hybrid target and schedule migration.
CryptographyMediumWeak RSA keyMobile-Backend-00065Fleet OperationsMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighCertificate expires <30dMobile-Backend-00065Fleet OperationsRotate certificate and validate dependent chains.
CryptographyMediumWeak RSA keyCertificate-Authority-00067Customer ExperienceMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighHNDL exposureAnalytics-Lake-00073Data & AnalyticsPrioritize hybrid/PQC migration and protect retained ciphertext.

How to read this report

Executives can start with posture, concentration of critical/high findings, HNDL exposure and migration blockers. Executives can then click through the unified Finding Explorer — filter by domain, business unit, system, or signal, expand a row to see the remediation context and evidence, and export the filtered list as evidence-backed work items.

Evidence model

begin → collect → seal → consume
Synthetic evidence is generated deterministically across accounts, organizational units, regions, systems and AI/LLM signals. The same normalization and assessment logic is exercised; no live cloud mutations occur.

Enterprise Scale Validation · Synthetic only · Full-population metrics with capped interactive drill-down · Generated locally