Purpose: validate the assessment pipeline against a multi-account, multi-region synthetic enterprise at customer-scale volumes. Metrics represent the full generated population; interactive drill-down is intentionally capped for browser performance. No customer data or credentials were accessed.
Full-population metrics are generated across the configured enterprise-scale scenario and environment. Interactive drill-down is capped at 20,000 records to keep the report responsive.
Click a signal to filter the finding explorer below.
Click a business unit to filter the finding explorer below.
Combined GenAI exposure and internal LLM misuse. AI findings are included directly in the unified Finding Explorer.
Click a signal to filter the unified Finding Explorer to AI Risk.
Click a business unit to filter the unified Finding Explorer to AI Risk.
Enterprise risk is concentrated where modernization constraints, business exposure, and control gaps intersect. The immediate priority is to reduce critical and high findings while removing the technology dependencies that can block migration — particularly legacy algorithms, HNDL exposure, HSM/PKI constraints, certificate and ownership gaps, and unsupported libraries. In parallel, AI risk requires governance over sensitive-data flows, unapproved models or endpoints, prompt-mediated exfiltration, excessive data access, and policy-bypass behavior. For the CEO, this frames the business exposure and investment priorities; for the CTO, it identifies engineering dependencies that can delay modernization; for the CISO, it identifies the control and evidence gaps requiring remediation. Use the unified Finding Explorer to move from an enterprise signal to the affected system, evidence, recommended action, and remediation status.
One investigation surface for cryptographic and AI risk findings. Use the scope toggle, filters, or any risk signal above to drill down.
| Domain | Severity | Signal | System | Business unit | Recommended action |
|---|---|---|---|---|---|
| Cryptography | Medium | Weak RSA key | Vendor-Integration-00001 | Supply Chain | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | High | Certificate expires <30d | Internal-Service-00004 | Data & Analytics | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | Internal-Service-00005 | Corporate IT | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Certificate expires <90d | CI/CD-Platform-00008 | Cloud Platform | Schedule rotation. |
| Cryptography | High | Certificate expires <30d | Database-00009 | Supply Chain | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Weak RSA key | Vendor-Integration-00010 | Finance | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | High | Certificate expires <30d | Vendor-Integration-00010 | Finance | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Third-party dependency | Certificate-Service-00016 | Customer Operations | Obtain vendor roadmap and migration compatibility statement. |
| Cryptography | Critical | HNDL exposure | Kubernetes-Platform-00017 | Engineering | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Kubernetes-Platform-00017 | Engineering | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Certificate expires <90d | Kubernetes-Platform-00017 | Engineering | Schedule rotation. |
| Cryptography | High | HNDL exposure | Kubernetes-Platform-00019 | Data & Analytics | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Kubernetes-Platform-00019 | Data & Analytics | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Missing asset owner | Certificate-Service-00020 | Engineering | Assign an owner and establish review cadence. |
| Cryptography | Medium | Weak RSA key | Kubernetes-Platform-00022 | Engineering | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | Medium | Third-party dependency | Analytics-Lake-00024 | Cloud Platform | Obtain vendor roadmap and migration compatibility statement. |
| Cryptography | Medium | Certificate expires <90d | CI/CD-Platform-00027 | Digital Products | Schedule rotation. |
| Cryptography | High | HNDL exposure | Customer-Portal-00031 | Data & Analytics | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Customer-Portal-00031 | Data & Analytics | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Backup-Platform-00033 | Corporate IT | Rotate certificate and validate dependent chains. |
| Cryptography | High | HNDL exposure | Data-Platform-00038 | Finance | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Data-Platform-00038 | Finance | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Certificate-Service-00039 | Finance | Rotate certificate and validate dependent chains. |
| Cryptography | High | HNDL exposure | Analytics-Lake-00041 | Shared Services | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Analytics-Lake-00041 | Shared Services | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Analytics-Lake-00041 | Shared Services | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Certificate expires <90d | API-Platform-00043 | Cloud Platform | Schedule rotation. |
| Cryptography | High | Key rotation overdue | API-Platform-00043 | Cloud Platform | Rotate key and capture evidence. |
| Cryptography | Medium | Missing asset owner | Customer-Portal-00045 | Finance | Assign an owner and establish review cadence. |
| Cryptography | High | SHA-1 usage | Data-Platform-00046 | Digital Products | Replace primitive and validate dependent applications. |
| Cryptography | High | Key rotation overdue | CI/CD-Platform-00047 | Security | Rotate key and capture evidence. |
| Cryptography | Critical | HNDL exposure | Database-00049 | Digital Products | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Database-00049 | Digital Products | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Kubernetes-Platform-00052 | Shared Services | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Kubernetes-Platform-00052 | Shared Services | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Certificate expires <90d | Kubernetes-Platform-00055 | Customer Operations | Schedule rotation. |
| Cryptography | Medium | Weak RSA key | Identity-Service-00060 | Engineering | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | Medium | Missing evidence | CI/CD-Platform-00062 | Shared Services | Collect and seal evidence snapshot. |
| Cryptography | High | HNDL exposure | Kubernetes-Platform-00065 | Data & Analytics | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Kubernetes-Platform-00065 | Data & Analytics | Select approved hybrid target and schedule migration. |
| Cryptography | High | Certificate expires <30d | Customer-Portal-00066 | Digital Products | Rotate certificate and validate dependent chains. |
| Cryptography | Critical | HNDL exposure | Kubernetes-Platform-00067 | Digital Products | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Kubernetes-Platform-00067 | Digital Products | Select approved hybrid target and schedule migration. |
| Cryptography | Medium | Weak RSA key | Kubernetes-Platform-00067 | Digital Products | Move to approved stronger or hybrid profile during lifecycle work. |
| Cryptography | High | Certificate expires <30d | Kubernetes-Platform-00067 | Digital Products | Rotate certificate and validate dependent chains. |
| Cryptography | High | Certificate expires <30d | Identity-Service-00068 | Supply Chain | Rotate certificate and validate dependent chains. |
| Cryptography | Medium | Missing asset owner | Database-00073 | Customer Operations | Assign an owner and establish review cadence. |
| Cryptography | High | HNDL exposure | Data-Platform-00075 | Corporate IT | Prioritize hybrid/PQC migration and protect retained ciphertext. |
| Cryptography | High | PQC migration required | Data-Platform-00075 | Corporate IT | Select approved hybrid target and schedule migration. |
| Cryptography | High | HNDL exposure | Certificate-Service-00081 | Shared Services | Prioritize hybrid/PQC migration and protect retained ciphertext. |
Executives can start with posture, concentration of critical/high findings, HNDL exposure and migration blockers. Executives can then click through the unified Finding Explorer — filter by domain, business unit, system, or signal, expand a row to see the remediation context and evidence, and export the filtered list as evidence-backed work items.
begin → collect → seal → consume
Synthetic evidence is generated deterministically across accounts, organizational units, regions, systems and AI/LLM signals. The same normalization and assessment logic is exercised; no live cloud mutations occur.
Enterprise Scale Validation · Synthetic only · Full-population metrics with capped interactive drill-down · Generated locally