QORONEX
CryptoBOM

Post-quantum readiness for firmware teams

Know which classical crypto is in the binary — without uploading the binary.

CryptoBOM produces a Cryptographic Bill of Materials from ECU and embedded images on your own machine. Evidence for supplier challenge, audit, and migration planning. License and updates only leave the host.

What you get

Local-first analysis

Firmware stays on the build PC or air-gapped lab host. The remote plane validates entitlement and delivers signed rule updates.

PQC-focused inventory

Detects quantum-vulnerable classical cryptography commonly found in automotive and embedded stacks, with NIST replacement guidance.

Weak classical hygiene

Optional pack for deprecated algorithms (MD5, SHA-1, DES family, RC4) for compliance clean-up beyond pure PQC inventory.

Audit-ready reports

Export PDF, HTML, JSON, CycloneDX CBOM, SARIF, and CSV for auditors and CI pipelines.

Migration urgency language

Findings include Mosca-style urgency framing so programmes can prioritise Harvest Now, Decrypt Later exposure.

CI fail-closed gates

Jenkins and GitLab integrations can block release when CRITICAL quantum-vulnerable crypto is still present.

Privacy by design

Built for

OEM and Tier-1 supplier-quality, PSIRT, and AppSec teams that receive HEX, S-record, ELF, or raw images and must show crypto inventory under UNECE R155 / ISO 21434 programmes — without a cloud SCA upload.

Request a trial or commercial quote

Tell us about your programme. We will respond with seat options (single or multi) and a time-boxed trial token when approved.