Cryptography is available where your organisation has it enabled.
Without it, Earnie hides the pages, filters, policy fields, and export options
this page describes.
What Earnie finds
A cryptography scan looks for every place your code uses cryptography. It records one finding for each use of one of these assets:
Earnie looks in two places:
- Your own code. Detection rules find calls to cryptography APIs and libraries, and record the exact lines.
- Your dependencies. Earnie resolves the libraries your project depends on and finds the cryptography inside them. This catches a weak algorithm that a library uses on your behalf.
Running a cryptography scan
Cryptography runs as part of a normal scan whenever your organisation has it enabled. You can also choose it for each scan. Select Cryptography under Scanners on the New scan page, or pass--scanners crypto to the Earnie CLI. While it runs, the scan shows the Detecting cryptography stage.
How Earnie judges it
Earnie gives every cryptographic finding three judgements:- Severity. How weak the cryptography is. Earnie looks this up in curated tables of algorithm families, key sizes, modes, and protocol versions. MD5 is weak whatever you use it for. RSA with a 1024-bit key is weaker than RSA with a 3072-bit key.
- Post-quantum status. Whether a future quantum computer breaks it. The status is Vulnerable, Safe, Not applicable, or Unassessed. Not applicable covers hashes and symmetric ciphers, which have nothing for a quantum computer to attack.
- Export-control signals. Evidence for your own export-control self-classification. Earnie never states an export classification for you.
Crypto assessment rules
Earnie publishes the tables behind those judgements at Settings → Crypto Assessment. The page is read-only and the same for every organisation. It shows the rules Earnie applies, so you can check why a finding got its severity. The page has one table, with one row per family. A scope switch moves between Algorithms, Key material, and Protocols. You can search for a family, an alternative name, or a protocol, and use Show to narrow the table to High severity, Quantum-vulnerable, or Export-controlled rows. Each row gives the family’s Base severity, its Post-quantum verdict (for algorithms), and its Export threshold. Select a row to open its details drawer, which shows:- the base severity, and any key-size or mode variants that change it
- the post-quantum verdict and the reasoning behind it
- the export-control line the family falls under
- the published sources each value cites
Reachability
A weak algorithm your application never runs is less urgent than one on a code path that runs. Earnie traces calls through your code and its dependencies to tell them apart:
When a finding is reachable, you can open its Call trace. It shows the path from the entry point to the cryptographic call, hop by hop, including the libraries it passes through. Earnie raises a reachable finding with an assessed severity by one level, and the finding explains why. An unassessed finding is never raised.
Not reached is not the same as not used. Reachability is static
analysis. It can’t follow code that runs only through reflection or
configuration. Treat a reachable finding as more urgent, but never treat an
unreached one as harmless.
Reviewing cryptographic findings
In the Review Workspace
In the Review Workspace, a cryptographic finding highlights the exact lines in the same source panel as any other finding. To see only cryptography, open + Filter and choose the Cryptography evidence type, or use one of the preset views: Weak crypto, Quantum vulnerable, or Reachable crypto. Cryptography also has its own filters, such as algorithm, algorithm family, reachability, post-quantum status, and key size. You can record one of three decisions on each finding:
There’s no “Fixed” decision. You fix a weak algorithm by removing it, and the next scan reports it gone. See Making a decision.
On the Algorithms page
Each project’s sidebar has an Algorithms page that lists every algorithm detected in the project, one row per algorithm. Each row shows its key size, quantum status, severity, how many assets and files use it, its open findings, and the libraries that provide it. Use it to answer questions such as “where do we use RSA?” or “what here isn’t quantum-safe?”. Select a row to open the Review Workspace filtered to that algorithm. See Starting from the Algorithms page.On the Dashboard
The project Dashboard has a Cryptography tab with cards for reachability, asset composition, post-quantum exposure, export readiness, and algorithm families. Trend lines for Reachable weak crypto and PQC-vulnerable assets track how your cryptography changes across scans.What changed between scans
A completed scan’s page has a Crypto changes card. It compares the scan with the nearest earlier scan that measured the project’s cryptography in full, and counts findings as New, Resolved, Re-detected, or Still open. Resolved means the finding is absent from this scan. The card appears only when there’s an earlier scan to compare against. Without one, Earnie hides the card rather than showing zeros. See Crypto changes between scans.Policies for cryptography
The same policies govern cryptographic findings as every other finding. With cryptography enabled, the policy editor offers a Crypto field group and seven cryptography templates:- Block reachable weak cryptography
- Flag quantum-vulnerable cryptography
- Block weak finite-field key sizes
- Block weak elliptic curves
- Warn on legacy protocol versions
- Warn on confidentiality crypto over export threshold
- Warn on unresolved export evidence
Evidence: CBOM and export control
CBOM
A CBOM (cryptography bill of materials) lists your cryptographic assets in a standard format. In Earnie, it’s a CycloneDX 1.7 document generated from an SBOM snapshot. On a project’s SBOMs page, select Generate snapshot and choose the CBOM scope. To get one document holding everything, choose xBOM, or turn on Cryptographic assets alongside open-source components. Each asset carries its cryptographic properties, where it occurs in your code, its reachability, and its export-control signals. SPDX doesn’t support cryptographic assets, so a CBOM is always CycloneDX. From the command line,earnie export --include crypto writes the same document. See Exporting SBOMs.
The export-control evidence report
A snapshot that includes cryptographic assets also produces an export-control evidence report. This is one HTML file with the evidence you need to classify your own product under export-control rules. It lists the detected assets, their export-control signals, what Earnie scanned, and which ruleset it used. The report is evidence for your own self-classification. It isn’t legal advice, and it states no export classification. Download it from the snapshot’s row menu, or from the Dashboard’s Download menu. See The export-control evidence report.What’s next
- Triaging findings explains how to work through cryptographic findings in the Review Workspace.
- Setting policies explains how to turn your cryptography standards into rules.
- Exporting SBOMs explains how to produce a CBOM for a customer or an auditor.