Crypto Agility & AI Security Assessment

Demonstration Posture Report

Purpose: validate the assessment pipeline against a multi-account, multi-region synthetic enterprise at customer-scale volumes. Metrics represent the full generated population; interactive drill-down is intentionally capped for browser performance. No customer data or credentials were accessed.

Enterprise scope & evidence coverage

Scenario / customer scope
Technology / SaaS · Staging
Accounts / organizational units
40 / 25
Regions observed
5
Evidence model
Synthetic / provenance simulated

Full-population metrics are generated across the configured enterprise-scale scenario and environment. Interactive drill-down is capped at 20,000 records to keep the report responsive.

69
Moderate
Enterprise posture score / 100
10,000
Systems assessed
6,835
Security findings
18,670
Evidence & audit events
1,728
HNDL-exposed systems
39
Migrations blocked
6.1%
PQC-ready systems
10
Business units

Findings by severity

Critical 39
High 4999
Medium 1797

Cryptographic estate

ECC P-256 2043
RSA-2048 1613
AES-256 1290
ECC P-384 1207
RSA-3072 1155
AES-128 825

Top risk signals

Click a signal to filter the finding explorer below.

HNDL exposure1728
PQC migration required1728
Certificate expires <90d708
Certificate expires <30d671
Missing asset owner556
Key rotation overdue360
Missing evidence249
HSM capability gap215
SHA-1 usage194
Configuration drift186

Systems by business unit

Click a business unit to filter the finding explorer below.

Platform Engineering1034
Finance1032
Product Engineering1026
Corporate IT1014
Security1009
Customer Success992
Data & AI988
Developer Experience981

GenAI & Internal LLM Risk Assessments

AI risk by severity

Critical 64
High 984
Moderate 5044
Low 7959

AI risk profile

20,000
AI assessments
16
Critical
328
High

Combined GenAI exposure and internal LLM misuse. AI findings are included directly in the unified Finding Explorer.

Top AI risk signals

Click a signal to filter the unified Finding Explorer to AI Risk.

GenAI exposure: Sensitive data to model4992
Internal LLM misuse: Sensitive internal prompt2248
GenAI exposure: Unapproved external model1749
Internal LLM misuse: Unapproved model or endpoint1457
GenAI exposure: Shadow AI use1184
Internal LLM misuse: Excessive data access967
Internal LLM misuse: Policy bypass behavior835
GenAI exposure: Prompt exfiltration signal619

AI risk by business unit

Click a business unit to filter the unified Finding Explorer to AI Risk.

Platform Engineering1460
Data & AI1459
Finance1444
Security1434
Product Engineering1428
Developer Experience1402
Corporate IT1402
Customer Success1383
Cloud Infrastructure1350
Identity1289

C-level summary

Enterprise risk is concentrated where modernization constraints, business exposure, and control gaps intersect. The immediate priority is to reduce critical and high findings while removing the technology dependencies that can block migration — particularly legacy algorithms, HNDL exposure, HSM/PKI constraints, certificate and ownership gaps, and unsupported libraries. In parallel, AI risk requires governance over sensitive-data flows, unapproved models or endpoints, prompt-mediated exfiltration, excessive data access, and policy-bypass behavior. For the CEO, this frames the business exposure and investment priorities; for the CTO, it identifies engineering dependencies that can delay modernization; for the CISO, it identifies the control and evidence gaps requiring remediation. Use the unified Finding Explorer to move from an enterprise signal to the affected system, evidence, recommended action, and remediation status.

Finding Explorer

One investigation surface for cryptographic and AI risk findings. Use the scope toggle, filters, or any risk signal above to drill down.

DomainSeveritySignalSystemBusiness unitRecommended action
CryptographyHighCertificate expires <30dCustomer-Portal-00001Corporate ITRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dModel-Gateway-00004Developer ExperienceRotate certificate and validate dependent chains.
CryptographyMediumMissing evidenceCertificate-Authority-00006Developer ExperienceCollect and seal evidence snapshot.
CryptographyHighHNDL exposureKubernetes-Cluster-00007Corporate ITPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredKubernetes-Cluster-00007Corporate ITSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureModel-Gateway-00010Developer ExperiencePrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredModel-Gateway-00010Developer ExperienceSelect approved hybrid target and schedule migration.
CryptographyMediumMissing asset ownerKubernetes-Cluster-00011Data & AIAssign an owner and establish review cadence.
CryptographyMediumConfiguration driftKubernetes-Cluster-00011Data & AIReconcile configuration and reseal evidence.
CryptographyHighHNDL exposureSaaS-Control-Plane-00012Platform EngineeringPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredSaaS-Control-Plane-00012Platform EngineeringSelect approved hybrid target and schedule migration.
CryptographyHighKey rotation overdueCI/CD-Platform-00014Data & AIRotate key and capture evidence.
CryptographyMediumMissing asset ownerKubernetes-Cluster-00015FinanceAssign an owner and establish review cadence.
CryptographyMediumCertificate expires <90dKubernetes-Cluster-00015FinanceSchedule rotation.
CryptographyHighCertificate expires <30dDeveloper-Platform-00019FinanceRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dCertificate-Authority-00021FinanceRotate certificate and validate dependent chains.
CryptographyMediumCertificate expires <90dCustomer-Portal-00023Customer SuccessSchedule rotation.
CryptographyMediumMissing asset ownerData-Warehouse-00024Platform EngineeringAssign an owner and establish review cadence.
CryptographyHighKey rotation overdueSaaS-Control-Plane-00025Corporate ITRotate key and capture evidence.
CryptographyMediumConfiguration driftSaaS-Control-Plane-00025Corporate ITReconcile configuration and reseal evidence.
CryptographyHighHNDL exposurePublic-API-00029Data & AIPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredPublic-API-00029Data & AISelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureIdentity-Platform-00033SecurityPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredIdentity-Platform-00033SecuritySelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureSaaS-Control-Plane-00035Customer SuccessPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredSaaS-Control-Plane-00035Customer SuccessSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureAnalytics-Lake-00038Developer ExperiencePrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredAnalytics-Lake-00038Developer ExperienceSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureCustomer-Portal-00040Corporate ITPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredCustomer-Portal-00040Corporate ITSelect approved hybrid target and schedule migration.
CryptographyMediumMissing asset ownerCustomer-Portal-00040Corporate ITAssign an owner and establish review cadence.
CryptographyHighCertificate expires <30dCustomer-Portal-00040Corporate ITRotate certificate and validate dependent chains.
CryptographyHighHNDL exposureModel-Gateway-00041FinancePrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredModel-Gateway-00041FinanceSelect approved hybrid target and schedule migration.
CryptographyHighSHA-1 usageModel-Gateway-00045FinanceReplace primitive and validate dependent applications.
CryptographyMediumMissing asset ownerKubernetes-Cluster-00046Product EngineeringAssign an owner and establish review cadence.
CryptographyHighHNDL exposureSaaS-Control-Plane-00050Data & AIPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredSaaS-Control-Plane-00050Data & AISelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dCustomer-Portal-00053FinanceRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dCustomer-Portal-00054Developer ExperienceRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dSaaS-Control-Plane-00065Platform EngineeringRotate certificate and validate dependent chains.
CryptographyHighHNDL exposureKubernetes-Cluster-00066Platform EngineeringPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredKubernetes-Cluster-00066Platform EngineeringSelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dKubernetes-Cluster-00066Platform EngineeringRotate certificate and validate dependent chains.
CryptographyHighKey rotation overdueKubernetes-Cluster-00066Platform EngineeringRotate key and capture evidence.
CryptographyHighCertificate expires <30dDeveloper-Platform-00067Corporate ITRotate certificate and validate dependent chains.
CryptographyMediumMissing asset ownerData-Warehouse-00072Product EngineeringAssign an owner and establish review cadence.
CryptographyHighHNDL exposureIdentity-Platform-00074Data & AIPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredIdentity-Platform-00074Data & AISelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dIdentity-Platform-00077Developer ExperienceRotate certificate and validate dependent chains.

How to read this report

Executives can start with posture, concentration of critical/high findings, HNDL exposure and migration blockers. Executives can then click through the unified Finding Explorer — filter by domain, business unit, system, or signal, expand a row to see the remediation context and evidence, and export the filtered list as evidence-backed work items.

Evidence model

begin → collect → seal → consume
Synthetic evidence is generated deterministically across accounts, organizational units, regions, systems and AI/LLM signals. The same normalization and assessment logic is exercised; no live cloud mutations occur.

Enterprise Scale Validation · Synthetic only · Full-population metrics with capped interactive drill-down · Generated locally