| Algorithm |
The cryptographic method used by an operation, such as AES or RSA |
| Anti-pattern |
A detected cryptographic coding or configuration choice that warrants review |
| Assessment |
Evaluation of the available evidence for security or migration review |
| CBOM |
Cryptography bill of materials: an inventory for exchanging cryptographic asset information |
| Confidence |
How strongly the available evidence supports a reported conclusion |
| Crypto agility |
The ability to change cryptographic algorithms and implementations as requirements evolve; PostQ supplies source evidence for this review, not a per-asset agility score |
| Crypto function |
A reported cryptographic API call in source code |
| Cryptographic asset |
Cryptographic functionality or material relevant to an application; PostQ describes assets detected through supported source-code use, not every deployed key or certificate |
| Cryptographic inventory |
A record of detected cryptographic use, including available algorithms, libraries, operations, settings, and source locations; its scope is the source included in a scan |
| CWE |
Common Weakness Enumeration: an identifier for a type of software weakness |
| Effective parameter |
A security setting used in assessment, with its value, evidence, and resolution status |
| Evidence |
Source locations, code, and settings that support a finding |
| Finding |
A detected item or supporting signal reported by the scanner |
| Flow path |
Locations showing where a parameter value was found and used |
| FIPS |
Federal Information Processing Standards; PostQ reports supported source-level issues relevant to a FIPS review |
| FIPS source assessment |
Review of supported source evidence for FIPS-related issues; it does not certify a deployment |
| IV |
Initialization vector: an input used by certain cryptographic operations |
| KDF |
Key derivation function: a method for deriving key material, including from passwords |
| MAC |
Message authentication code: a keyed value used to check message integrity and authenticity |
| Manual review |
Investigation needed when evidence is incomplete, conflicting, or requires application context |
| Nonce |
A value whose required uniqueness or freshness depends on the cryptographic operation |
| OpenGrep |
The local source-analysis tool required by PostQ scans |
| Operation group |
Related cryptographic calls presented together as a logical operation |
| PQC |
Post-quantum cryptography |
| Quantum classification |
An assessment of quantum exposure based on available algorithm and operation information |
| Remediation |
A change to address a reported weakness or configuration issue, followed by source review, rescanning, and application testing |
| Resolution |
Whether the scanner can establish a parameter's value from the available evidence |
| SARIF |
Static Analysis Results Interchange Format, used by compatible security tools |
| Scan session |
The identifier shared by reports from one scan |
| Schema version |
The version of a report's data format |
| Trial ledger |
Protected local records used to maintain offline activation and usage limits |