KORTHEXDocumentation

Docs / TRUST & COMPLIANCE

TRUST & COMPLIANCE

Compliance

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex automatically maps findings to recognized compliance frameworks, helping organizations demonstrate adherence to cryptographic security standards.

NIST FIPS 203/204/205

FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) define the first NIST-standardized post-quantum cryptographic algorithms. Korthex evaluates your codebase against these standards: Each finding includes a compliance.nist field indicating which FIPS standards apply and the current compliance status.

StandardAlgorithmKorthex Check
FIPS 203ML-KEM (Kyber)Identifies key encapsulation mechanisms that need PQC upgrade.
FIPS 204ML-DSA (Dilithium)Flags digital signature schemes vulnerable to quantum attack.
FIPS 205SLH-DSA (SPHINCS+)Detects hash-based signature opportunities.

BSI IT-Grundschutz

For organizations operating under German/EU regulatory requirements, Korthex maps findings to BSI IT-Grundschutz controls: Findings include a compliance.bsi field with the relevant Grundschutz module references and requirement IDs.

BSI ModuleDescription
CON.1Crypto concept - algorithm selection and key management.
APP.3.6DNS security and DNSSEC cryptographic configuration.
NET.3.3VPN - IPsec and TLS tunnel cryptographic requirements.
OPS.1.2.4Patch and change management for crypto libraries.

Severity Model

Korthex uses a five-level severity model: Severity levels are automatically adjusted by the Context Engine. Taint analysis may promote or demote findings based on evidence about key sources and code context.

SeverityDescriptionExamples
CRITICALImmediate security risk. Exploitable without quantum computers.Hardcoded private keys, MD5 for passwords, DES in production
HIGHSignificant weakness. Vulnerable to near-term attacks or quantum.RSA-2048 for long-term secrets, SHA-1 certificates, ECB mode
MEDIUMSuboptimal cryptography that should be upgraded.AES-128 (vs 256), PKCS#1 v1.5 padding, 2048-bit DH
LOWMinor improvement opportunity.Non-PQC algorithms in non-sensitive contexts
INFOInformational finding for inventory purposes.Detected crypto usage with no identified weakness