Engagements · Programme
Three reviews. One programme.
The catalogue's three layer reviews — Transport & PKI, Signing & Identity, and Key Management — cover the three places where an estate's cryptography meets the world. Run separately, each stands on its own. Run together, they share one engagement letter, one delivery window and one combined register, and they end in a single Posture Attestation that covers all three layers. This page states exactly what combining them changes, and what it does not.
The programme
Three layer reviews, one piece of work
Each card below is the same engagement it is in the catalogue, with the same scope, the same artefacts and the same stated limits. Combining them adds nothing to any single review — what it removes is the duplication between them.
Transport & PKI Review
A review of X.509 chains, issuance and expiry, TLS terminators, cipher suites and key exchange, mutual TLS, and the internal certificate authorities behind them.
Read the engagementREVIEWSigning & Identity Review
A review of code signing and artefact provenance, token and assertion signing, document signing, and SSH host and user keys across the estate.
Read the engagementREVIEWKey Management Review
A review of KMS and HSM key inventory, rotation and custody boundaries, secrets stores, key lifecycle and escrow, and algorithm agility at the key layer.
Read the engagementOne engagement letter
A single scope covering all three layers, agreed once, amended in writing or not at all.
One delivery window
All three reviews read the same estate snapshot, so no finding is stale relative to another.
One combined register
Findings from every layer in a single severity order, scored by the same published method.
One Posture Attestation
A single verifiable attestation covering transport, signing and key management together.
Run separately
Three letters, three windows, three registers. The boundaries between layers — where a certificate chain meets a signing key, or a signing key meets its custodian — are reviewed twice, or fall between scopes and are reviewed by nobody.
Run as one programme
One letter, one window, one register. Every boundary is assigned to exactly one reviewer, every finding is scored against the same snapshot, and the attestation at the end covers the perimeter rather than a third of it.
01 · One review
Full depth on the layer that concerns you most. Nothing about running one alone is diminished.
02 · Any two
The boundary the two layers share — where a certificate meets a signing key, or a key meets its custodian — is reviewed once, in one register, instead of twice or not at all.
03 · All three
The estate's full cryptographic perimeter in one window, ending in one attestation an auditor can verify.
Also in the catalogue
Before the reviews, and after them
The reviews assume you know which layers matter. The inventory is how you find out; engineering and the briefing are what a scored register is for. Each can be scoped on its own or alongside the programme.
Estate Inventory
Discovery of cryptographic use across source trees, dependency manifests, build chains, configuration and certificates, delivered as a CBOM and a scored register.
Read the engagementENGINEERINGMigration Engineering
Sequencing, hybrid deployment, rollback preservation and measured performance proof, so a post-quantum change ships with evidence rather than optimism.
Read the engagementBRIEFINGExecutive Briefing
A working session that turns an exposure position into a board-legible decision: what expires when, what deferring changes, and what the next cycle of work buys.
Read the engagementToolScope Builder
Tick the surfaces your estate actually has and read back which engagements touch them — assembled from the catalogue, without a price.
Open the builderBetween engagements
A review ends. The estate keeps changing.
An engagement reads a snapshot, and a snapshot ages the day it is taken. Two surfaces on this site keep moving between engagements, and neither is a subscription — both are public.
Sector Pulse
What is publicly known about cryptographic failure, sector by sector.
- Ten sectors, one public advisory pool
- Grouped by how the cryptography actually failed
- Refreshed on a schedule from named public sources
- Every inclusion rule published on the page itself
- Public — no account and no charge
Compatibility Reference
Post-quantum support in the libraries and protocols your estate actually links against.
- Public libraries, protocols and toolchains in one table
- Six support states, one meaning each
- ML-KEM, ML-DSA and SLH-DSA support, version by version
- Each cell cites the project's own documentation
- A dated as-of line on every revision
Engagements and coverage, together
The Enterprise Program pairs continuous platform coverage with engagement work.
Everything in Platform, multi-estate · Compliance-mapped reporting · Vendor-roadmap tracking · Named engineering contact — as stated on the pricing page, which owns that list.
Signed · Verifiable
Every engagement in the catalogue ends with a Posture Attestation you can verify.
A programme ends with one attestation covering all three layers. Anyone holding its code can check it on this site.