KORTHEXDocumentation

Docs / ANALYSIS ENGINES

ANALYSIS ENGINES

Inventory Engine

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

The Inventory Engine builds an authoritative inventory of every cryptographic asset in your project - every algorithm use, every certificate, every TLS endpoint, every key in code or config - and writes it as an encrypted .kxi snapshot alongside the scan report. This is the engine that answers "what cryptography are we actually using, in which files, at what strength?" The inventory is a Dashboard surface, not a CLI verb . The CLI's job is to produce the snapshot - korthex scan . writes it - and the Dashboard's job is to read it. Both clients carry the same Inventory screen with four views: Desktop app: Inventory in the sidebar. Web Dashboard: Inventory (the separate CBOM page shows the same asset list in bill-of-materials shape).

ViewWhat it shows
FilesPer-file rollup: which algorithms and keys appear in which file.
CensusOne row per distinct algorithm: family, strength, occurrence count, NIST status, PQC flag. Filter by family, search by name.
PQC ReadinessThe PQC-safe share of the inventory, plus the ready list and the at-risk list.
Snapshot DiffCompare the loaded snapshot against an earlier one.

What It Inventories

CategoryExamples captured
AlgorithmsEvery distinct algorithm + mode + key-length combination, with usage counts.
CertificatesX.509 certs in code, config, and TLS endpoints. Validity, signing chain, key type.
TLS endpointsHostnames, ports, cipher suites, protocol versions, cert pinning state.
Top crypto filesFiles containing the highest density of crypto operations (audit hotspots).
Binary findingsAlgorithms discovered in shipped artifacts (.dll, .so, .jar, .wasm).
Git historyAlgorithms introduced or removed across commits.
Runtime processesLive algorithm choice from a Runtime-Agent session.

PQC Readiness Score

The PQC Readiness view scores the snapshot: what share of the inventoried algorithms is already post-quantum safe. It shows the percentage as a bar, then two lists - the algorithms that are already PQC-safe, and the quantum-vulnerable ones still in use. Two things are worth knowing before you quote the number: It is a ratio over distinct algorithms, not over call sites. Ten RSA call sites and one RSA algorithm count once. When you need the call-site weight, read the occurrence column in the Census view. Hashes are excluded from the at-risk list - they still count in the denominator, but a hash function is not a quantum-migration item the way a key-exchange or signature primitive is. An empty inventory has no ratio, and Korthex says so rather than reporting 0%. "Not measured" and "measured, and it is zero" are different answers and are rendered differently.

CBOM / SBOM Export

The Inventory engine emits the snapshot in two standard bill-of-materials formats. What a client hands you today is a third thing - be precise about which one you need. Today: open the Inventory screen and use Export CBOM . Name the target .json for the JSON rows or .csv for the spreadsheet form; the export is permission-gated on findings.read . Planned: the CycloneDX and SPDX emitters get a CLI surface. The commands below are the interface they will carry - they are not available yet, and the CLI will reject them until they are. # Planned - not yet available. Use Export CBOM in the Dashboard today. korthex inventory export latest --format cyclonedx --output cbom.cdx.json korthex inventory export latest --format spdx --output sbom.spdx.json

FormatStandardStatus
CycloneDX 1.5 JSONOWASP Crypto-BOM profileEmitted by the engine. Not yet reachable from the CLI or the Dashboard - the CLI surface is being built.
SPDX 2.3 JSONSPDX 2.3 with package extensionsEmitted by the engine. Not yet reachable from a client.
Korthex JSON / CSVNative per-usage rowsWhat Export CBOM writes today. One row per usage: algorithm, type, file, line, language, deprecated, PQC-safe, NIST status, severity, key size, mode.

Snapshot Diffs

Inventory snapshots compare cleanly across scans. Open the Inventory screen, pick Snapshot Diff , and choose the earlier .kxi . The comparison is per algorithm and reports five things: .kxi snapshots are encrypted. The Desktop app decrypts them with the workspace master key, so it diffs a snapshot straight from disk - without a master key loaded, the Diff action tells you so instead of failing quietly. The Web Dashboard currently needs an already-decrypted snapshot and rejects an encrypted payload with an inline error.

SectionMeaning
AddedAlgorithms present now that the earlier snapshot did not have.
RemovedAlgorithms the earlier snapshot had and this one does not.
UnchangedHow many algorithms carried over untouched (a count, not a list).
Newly deprecatedAlgorithms that were fine before and are flagged deprecated now.
Newly PQC-safeAlgorithms that crossed over to a post-quantum primitive.