Comparison
Korthex vs SandboxAQ AQtive Guard: Source vs Runtime
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex reads the source of truth before deployment: static analysis across 18 languages with file:line evidence, weakness proven by emulation against NIST Known-Answer Tests, and a dependency-ordered migration plan, entirely on-premise and self-serve. SandboxAQ's AQtive Guard attacks the same problem, unmanaged cryptography, from the opposite vantage point: it discovers cryptography already running in the estate, network traffic, runtime library calls, filesystems, keys and certificates, at organizational scale.
Axis by axis: KAT emulation proof vs policy-based identification against FIPS/PCI-DSS; a topologically-ordered migration plan with impact simulation vs AI-assisted prioritization; five CBOM export formats with a per-finding post-quantum bucket vs CBOM generation aligned with CNSA 2.0; self-serve CLI with a free tier vs enterprise sales-led engagement (30-day trial on request); on-premise / air-gapped by default vs an integrated enterprise platform; pre-deploy source truth vs running-estate discovery; file:line dataflow evidence vs asset-level owner mapping. The two vantage points are complementary; some organizations run both.
How Korthex and SandboxAQ AQtive Guard differ, axis by axis
| Axis | Korthex | SandboxAQ AQtive Guard |
|---|---|---|
| Weakness verification | Extracted cryptography is proven weak or broken by emulation against NIST Known-Answer Tests, with a side-channel timing verdict on top | Policy-based identification against FIPS, PCI DSS and quantum-readiness policies |
| Migration output | Topologically-ordered migration plan: per item file:line, replacement algorithm, effort estimate, dependency order, impact simulation | AI-assisted risk prioritization and remediation guidance |
| CBOM export | Five export formats (CycloneDX, SARIF, JSON, PDF, .kxr), every finding carrying its own post-quantum readiness bucket | CBOM generation aligned with CNSA 2.0 and NIST mandates |
| Getting started | Self-serve CLI with a free tier (10 scans/month), transparent pricing | Enterprise, sales-led engagement; 30-day trial on request for non-production use |
| Deployment model | 100% on-premise or air-gapped by default; source code never leaves your infrastructure | Enterprise platform with integrations across cloud providers, CMDBs and repositories |
| Primary vantage point | Pre-deploy source truth: static analysis of source code in 18 languages, dependencies, binaries and git history | Running estate: network-traffic, application-runtime and filesystem analyzers discover cryptography in operation |
| Finding evidence | File and line per finding, dataflow across 16 import hops, taint-based verdicts | Asset-level inventory mapping keys, certificates and algorithms to owners and dependencies |