Purpose: validate the assessment pipeline against a multi-account, multi-region synthetic enterprise at customer-scale volumes. Metrics represent the full generated population; interactive drill-down is intentionally capped for browser performance. No customer data or credentials were accessed.
Full-population metrics are generated across the configured enterprise-scale scenario and environment. Interactive drill-down is capped at 20,000 records to keep the report responsive.
Click a signal to filter the finding explorer below.
Click a business unit to filter the finding explorer below.
Combined GenAI exposure and internal LLM misuse. AI findings are included directly in the unified Finding Explorer.
Click a signal to filter the unified Finding Explorer to AI Risk.
Click a business unit to filter the unified Finding Explorer to AI Risk.
Enterprise risk is concentrated where modernization constraints, business exposure, and control gaps intersect. The immediate priority is to reduce critical and high findings while removing the technology dependencies that can block migration — particularly legacy algorithms, HNDL exposure, HSM/PKI constraints, certificate and ownership gaps, and unsupported libraries. In parallel, AI risk requires governance over sensitive-data flows, unapproved models or endpoints, prompt-mediated exfiltration, excessive data access, and policy-bypass behavior. For the CEO, this frames the business exposure and investment priorities; for the CTO, it identifies engineering dependencies that can delay modernization; for the CISO, it identifies the control and evidence gaps requiring remediation. Use the unified Finding Explorer to move from an enterprise signal to the affected system, evidence, recommended action, and remediation status.
One investigation surface for cryptographic and AI risk findings. Use the scope toggle, filters, or any risk signal above to drill down.
| Domain | Severity | Signal | System | Business unit | Recommended action |
|---|---|---|---|---|---|
| Cryptography | Medium | Certificate expires <90d | Fleet-Platform-00001 | Corporate IT | Schedule rotation. |
| Cryptography | High | HNDL exposure | Dispatch-Platform-00004 | Payments | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Dispatch-Platform-00004 | Payments | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Reservation-API-00005 | Security | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Reservation-API-00005 | Security | Select approved hybrid target and schedule migration. |
| Cryptography | High | Key rotation overdue | Reservation-API-00005 | Security | Rotate key and capture evidence. |
| Cryptography | Medium | Missing evidence | Reservation-API-00006 | Data & Analytics | Collect and seal evidence snapshot. |
| Cryptography | High | Certificate expires <30d | Customer-Portal-00007 | Reservations | Rotate certificate and validate dependent chains. |
| Cryptography | Critical | HNDL exposure | Vehicle-Telematics-00009 | Supply Chain | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Vehicle-Telematics-00009 | Supply Chain | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Weak RSA key | Vehicle-Telematics-00009 | Supply Chain | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | High | SHA-1 usage | Vehicle-Telematics-00013 | Digital Products | Replace primitive and validate dependent applications. |
| Cryptography | Medium | Missing asset owner | Payment-Service-00015 | Corporate IT | Assign an owner and establish review cadence. |
| Cryptography | High | SHA-1 usage | Dispatch-Platform-00016 | Data & Analytics | Replace primitive and validate dependent applications. |
| Cryptography | Medium | Certificate expires <90d | Dispatch-Platform-00016 | Data & Analytics | Schedule rotation. |
| Cryptography | High | Key rotation overdue | Identity-Platform-00017 | Fleet Operations | Rotate key and capture evidence. |
| Cryptography | High | HNDL exposure | Mobile-Backend-00018 | Payments | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Mobile-Backend-00018 | Payments | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Mobile-Backend-00018 | Payments | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Certificate expires <90d | Dispatch-Platform-00020 | Supply Chain | Schedule rotation. |
| Cryptography | Medium | Weak RSA key | Mobile-Backend-00021 | Customer Experience | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | Medium | Third-party dependency | Analytics-Lake-00023 | Payments | Obtain vendor roadmap and migration compatibility statement. |
| Cryptography | High | SHA-1 usage | Data-Warehouse-00024 | Reservations | Replace primitive and validate dependent applications. |
| Cryptography | High | HNDL exposure | Identity-Platform-00026 | Data & Analytics | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Identity-Platform-00026 | Data & Analytics | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Certificate expires <90d | Identity-Platform-00026 | Data & Analytics | Schedule rotation. |
| Cryptography | High | Certificate expires <30d | Dispatch-Platform-00027 | Fleet Operations | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | Vehicle-Telematics-00032 | Data & Analytics | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Missing evidence | Certificate-Authority-00034 | Customer Experience | Collect and seal evidence snapshot. |
| Cryptography | High | Certificate expires <30d | Mobile-Backend-00037 | Telematics | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | Fleet-Platform-00042 | Telematics | Rotate certificate and validate dependent chains. |
| Cryptography | High | HNDL exposure | Vehicle-Telematics-00043 | Data & Analytics | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Vehicle-Telematics-00043 | Data & Analytics | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Certificate-Authority-00052 | Supply Chain | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Certificate-Authority-00052 | Supply Chain | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Dispatch-Platform-00053 | Supply Chain | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Dispatch-Platform-00053 | Supply Chain | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Missing asset owner | Vehicle-Telematics-00054 | Customer Experience | Assign an owner and establish review cadence. |
| Cryptography | High | Key rotation overdue | Vehicle-Telematics-00054 | Customer Experience | Rotate key and capture evidence. |
| Cryptography | High | HNDL exposure | Reservation-API-00057 | Digital Products | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Reservation-API-00057 | Digital Products | Select approved hybrid target and schedule migration. |
| Cryptography | High | HSM capability gap | Certificate-Authority-00060 | Corporate IT | Upgrade/configure HSM before migration. |
| Cryptography | Medium | Certificate expires <90d | Analytics-Lake-00061 | Data & Analytics | Schedule rotation. |
| Cryptography | High | Certificate expires <30d | Fleet-Platform-00064 | Fleet Operations | Rotate certificate and validate dependent chains. |
| Cryptography | Critical | HNDL exposure | Mobile-Backend-00065 | Fleet Operations | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Mobile-Backend-00065 | Fleet Operations | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Weak RSA key | Mobile-Backend-00065 | Fleet Operations | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | High | Certificate expires <30d | Mobile-Backend-00065 | Fleet Operations | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Weak RSA key | Certificate-Authority-00067 | Customer Experience | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | High | HNDL exposure | Analytics-Lake-00073 | Data & Analytics | Prioritize hybrid/PQC migration and protect retained ciphertext. |
Executives can start with posture, concentration of critical/high findings, HNDL exposure and migration blockers. Executives can then click through the unified Finding Explorer — filter by domain, business unit, system, or signal, expand a row to see the remediation context and evidence, and export the filtered list as evidence-backed work items.
begin → collect → seal → consume
Synthetic evidence is generated deterministically across accounts, organizational units, regions, systems and AI/LLM signals. The same normalization and assessment logic is exercised; no live cloud mutations occur.
Enterprise Scale Validation · Synthetic only · Full-population metrics with capped interactive drill-down · Generated locally