| Assessment |
Deterministic evaluation of available scanner facts against metadata or policy. |
| CBOM |
Cryptography Bill of Materials interoperability report. |
| Crypto function |
One selected cryptographic API call after normalization and enrichment. |
| Detected expression |
Source expression observed at a crypto API parameter. |
| Evidence source |
How a parameter fact was obtained, such as direct capture, constant propagation, or intrafile data flow. |
| Finding |
Canonical scanner evidence. Findings can include crypto functions, anti-pattern signals, and parameter-flow evidence. |
| FIPS evidence |
Scanner assessment of available algorithm/property/provider/runtime facts; not product or deployment certification. |
| Flow path |
OpenGrep source-to-sink evidence supporting a parameter value. |
| Manual review |
Work required because static evidence is incomplete, unresolved, or requires application/deployment context. |
| OpenGrep |
The local source-analysis engine used by PostQ packaged rules. |
| Operation group |
Related crypto-function calls presented as one logical asset or lifecycle. |
| Origin |
Where a detected parameter expression appears to come from, such as source, configuration, environment, or external input. |
| PQC |
Post-quantum cryptography. |
| Quantum classification |
Scanner-owned category based on available algorithm and operation facts; one input to migration planning. |
| Resolution |
Whether deterministic static evidence supports a parameter value. |
| SARIF |
Static Analysis Results Interchange Format used by compatible security tools. |
| Scan session |
Identity and metadata shared by reports generated in one scanner run. |
| Schema version |
Version of a generated report contract. |
| Trial ledger |
Protected local state used to enforce offline trial repository limits and detect time rollback. |