Product Features¶
PostQ discovers cryptography in source code and explains what the available evidence means for security review and post-quantum migration. Start with discovery and coverage, then explore the five assessment dimensions.
Core capabilities¶
| Capability | What it helps you understand |
|---|---|
| Cryptographic Discovery and Inventory | Identify cryptography, trace its settings, recognize API defaults, and group multi-step operations into logical assets for assessment. |
| Languages and Libraries Supported | Which source languages and library families are covered, and where additional review can be needed. |
| Assessment Dimensions | The five review questions PostQ addresses, with a short explanation of their scope and limits. |
| Quantum Exposure | Which uses need quantum migration or effective-strength review. |
| Crypto Weaknesses | Which supported cryptographic weaknesses are identified and what their CWE identifiers mean. |
| FIPS Source Assessment | Which supported FIPS-related source issues or evidence gaps need investigation. |
| Crypto Agility | Which source indicators warrant review before changing cryptography. |
| Risk Signals | What context observations, anti-patterns, and parameter concerns mean. |
Operational capabilities¶
| Capability | What you can accomplish |
|---|---|
| Running Scans | Select source and generate results through the CLI, an IDE, a container, or a build pipeline. |
| Reviewing Results | Investigate evidence, focus a review, navigate source, and compare completed scans. |
| Sharing Reports | Exchange inventories through CBOM, share findings through SARIF, and export review selections. |
| Administration and Support | Prepare environments, manage activation and retention, and resolve operational issues. |
Discovery and supported assessments run as part of a normal scan; you do not enable each dimension separately. Available evidence and coverage determine the conclusions that can be reached.
For practical review sequences, use Everyday Security Workflows. For instructions on opening results, understanding report counts, or using report files, use Reports and Data. Installation and activation are covered in Getting Started.