Purpose: validate the assessment pipeline against a multi-account, multi-region synthetic enterprise at customer-scale volumes. Metrics represent the full generated population; interactive drill-down is intentionally capped for browser performance. No customer data or credentials were accessed.
Full-population metrics are generated across the configured enterprise-scale scenario and environment. Interactive drill-down is capped at 20,000 records to keep the report responsive.
Click a signal to filter the finding explorer below.
Click a business unit to filter the finding explorer below.
Combined GenAI exposure and internal LLM misuse. AI findings are included directly in the unified Finding Explorer.
Click a signal to filter the unified Finding Explorer to AI Risk.
Click a business unit to filter the unified Finding Explorer to AI Risk.
Enterprise risk is concentrated where modernization constraints, business exposure, and control gaps intersect. The immediate priority is to reduce critical and high findings while removing the technology dependencies that can block migration — particularly legacy algorithms, HNDL exposure, HSM/PKI constraints, certificate and ownership gaps, and unsupported libraries. In parallel, AI risk requires governance over sensitive-data flows, unapproved models or endpoints, prompt-mediated exfiltration, excessive data access, and policy-bypass behavior. For the CEO, this frames the business exposure and investment priorities; for the CTO, it identifies engineering dependencies that can delay modernization; for the CISO, it identifies the control and evidence gaps requiring remediation. Use the unified Finding Explorer to move from an enterprise signal to the affected system, evidence, recommended action, and remediation status.
One investigation surface for cryptographic and AI risk findings. Use the scope toggle, filters, or any risk signal above to drill down.
| Domain | Severity | Signal | System | Business unit | Recommended action |
|---|---|---|---|---|---|
| Cryptography | High | Certificate expires <30d | Customer-Portal-00001 | Corporate IT | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | Model-Gateway-00004 | Developer Experience | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Missing evidence | Certificate-Authority-00006 | Developer Experience | Collect and seal evidence snapshot. |
| Cryptography | High | HNDL exposure | Kubernetes-Cluster-00007 | Corporate IT | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Kubernetes-Cluster-00007 | Corporate IT | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Model-Gateway-00010 | Developer Experience | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Model-Gateway-00010 | Developer Experience | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Missing asset owner | Kubernetes-Cluster-00011 | Data & AI | Assign an owner and establish review cadence. |
| Cryptography | Medium | Configuration drift | Kubernetes-Cluster-00011 | Data & AI | Reconcile configuration and reseal evidence. |
| Cryptography | High | HNDL exposure | SaaS-Control-Plane-00012 | Platform Engineering | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | SaaS-Control-Plane-00012 | Platform Engineering | Select approved hybrid target and schedule migration. |
| Cryptography | High | Key rotation overdue | CI/CD-Platform-00014 | Data & AI | Rotate key and capture evidence. |
| Cryptography | Medium | Missing asset owner | Kubernetes-Cluster-00015 | Finance | Assign an owner and establish review cadence. |
| Cryptography | Medium | Certificate expires <90d | Kubernetes-Cluster-00015 | Finance | Schedule rotation. |
| Cryptography | High | Certificate expires <30d | Developer-Platform-00019 | Finance | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | Certificate-Authority-00021 | Finance | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Certificate expires <90d | Customer-Portal-00023 | Customer Success | Schedule rotation. |
| Cryptography | Medium | Missing asset owner | Data-Warehouse-00024 | Platform Engineering | Assign an owner and establish review cadence. |
| Cryptography | High | Key rotation overdue | SaaS-Control-Plane-00025 | Corporate IT | Rotate key and capture evidence. |
| Cryptography | Medium | Configuration drift | SaaS-Control-Plane-00025 | Corporate IT | Reconcile configuration and reseal evidence. |
| Cryptography | High | HNDL exposure | Public-API-00029 | Data & AI | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Public-API-00029 | Data & AI | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Identity-Platform-00033 | Security | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Identity-Platform-00033 | Security | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | SaaS-Control-Plane-00035 | Customer Success | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | SaaS-Control-Plane-00035 | Customer Success | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Analytics-Lake-00038 | Developer Experience | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Analytics-Lake-00038 | Developer Experience | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Customer-Portal-00040 | Corporate IT | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Customer-Portal-00040 | Corporate IT | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Missing asset owner | Customer-Portal-00040 | Corporate IT | Assign an owner and establish review cadence. |
| Cryptography | High | Certificate expires <30d | Customer-Portal-00040 | Corporate IT | Rotate certificate and validate dependent chains. |
| Cryptography | High | HNDL exposure | Model-Gateway-00041 | Finance | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Model-Gateway-00041 | Finance | Select approved hybrid target and schedule migration. |
| Cryptography | High | SHA-1 usage | Model-Gateway-00045 | Finance | Replace primitive and validate dependent applications. |
| Cryptography | Medium | Missing asset owner | Kubernetes-Cluster-00046 | Product Engineering | Assign an owner and establish review cadence. |
| Cryptography | High | HNDL exposure | SaaS-Control-Plane-00050 | Data & AI | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | SaaS-Control-Plane-00050 | Data & AI | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Customer-Portal-00053 | Finance | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | Customer-Portal-00054 | Developer Experience | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | SaaS-Control-Plane-00065 | Platform Engineering | Rotate certificate and validate dependent chains. |
| Cryptography | High | HNDL exposure | Kubernetes-Cluster-00066 | Platform Engineering | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Kubernetes-Cluster-00066 | Platform Engineering | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Kubernetes-Cluster-00066 | Platform Engineering | Rotate certificate and validate dependent chains. |
| Cryptography | High | Key rotation overdue | Kubernetes-Cluster-00066 | Platform Engineering | Rotate key and capture evidence. |
| Cryptography | High | Certificate expires <30d | Developer-Platform-00067 | Corporate IT | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Missing asset owner | Data-Warehouse-00072 | Product Engineering | Assign an owner and establish review cadence. |
| Cryptography | High | HNDL exposure | Identity-Platform-00074 | Data & AI | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Identity-Platform-00074 | Data & AI | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Identity-Platform-00077 | Developer Experience | Rotate certificate and validate dependent chains. |
Executives can start with posture, concentration of critical/high findings, HNDL exposure and migration blockers. Executives can then click through the unified Finding Explorer — filter by domain, business unit, system, or signal, expand a row to see the remediation context and evidence, and export the filtered list as evidence-backed work items.
begin → collect → seal → consume
Synthetic evidence is generated deterministically across accounts, organizational units, regions, systems and AI/LLM signals. The same normalization and assessment logic is exercised; no live cloud mutations occur.
Enterprise Scale Validation · Synthetic only · Full-population metrics with capped interactive drill-down · Generated locally