> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanoss.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cryptography

> How Earnie finds the cryptography in your code and its dependencies, judges it, and carries it into review, policies, and evidence.

Cryptography is one of the domains Earnie governs, alongside open source and AI provenance. It isn't a separate area of the product. Cryptographic findings appear in the same Review Workspace as every other finding. The same policies judge them, they gate the same pull requests, and Earnie exports them in the same SBOM snapshots.

This page explains what Earnie does with cryptography and links to the pages that cover each part in full.

<Note>
  **Cryptography is available where your organisation has it enabled.**
  Without it, Earnie hides the pages, filters, policy fields, and export options
  this page describes.
</Note>

## What Earnie finds

A cryptography scan looks for every place your code uses cryptography. It records one finding for each use of one of these assets:

| Asset | Example |
| - | - |
| **Algorithm** | AES in CBC mode, RSA, SHA-1, ECDSA on P-256 |
| **Protocol** | TLS 1.0, SSL 3.0 |
| **Certificate** | A certificate your code uses |
| **Key material** | A key your code uses with an algorithm |

Earnie looks in two places:

* **Your own code.** Detection rules find calls to cryptography APIs and libraries, and record the exact lines.
* **Your dependencies.** Earnie resolves the libraries your project depends on and finds the cryptography inside them. This catches a weak algorithm that a library uses on your behalf.

Each finding records what Earnie could resolve about the asset, such as its primitive, mode, padding, key size, or elliptic curve, and which library provides it.

Detection runs inside your own Earnie environment. See [Deployment & data flow](/en/latest/earnie/deployment).

### Running a cryptography scan

Cryptography runs as part of a normal scan whenever your organisation has it enabled. You can also choose it for each scan. Select **Cryptography** under **Scanners** on the **New scan** page, or pass `--scanners crypto` to the [Earnie CLI](/en/latest/earnie/using-earnie/earnie-cli#choosing-scanners). While it runs, the scan shows the **Detecting cryptography** stage.

## How Earnie judges it

Earnie gives every cryptographic finding three judgements:

* **Severity.** How weak the cryptography is. Earnie looks this up in curated tables of algorithm families, key sizes, modes, and protocol versions. MD5 is weak whatever you use it for. RSA with a 1024-bit key is weaker than RSA with a 3072-bit key.
* **Post-quantum status.** Whether a future quantum computer breaks it. The status is **Vulnerable**, **Safe**, **Not applicable**, or **Unassessed**. **Not applicable** covers hashes and symmetric ciphers, which have nothing for a quantum computer to attack.
* **Export-control signals.** Evidence for your own export-control self-classification. Earnie never states an export classification for you.

Earnie only judges what its tables cover. Earnie marks an algorithm it hasn't curated as **Unassessed** rather than guessing a severity.

### Crypto assessment rules

Earnie publishes the tables behind those judgements at **Settings → Crypto Assessment**. The page is read-only and the same for every organisation. It shows the rules Earnie applies, so you can check why a finding got its severity.

The page has one table, with one row per family. A **scope** switch moves between **Algorithms**, **Key material**, and **Protocols**. You can search for a family, an alternative name, or a protocol, and use **Show** to narrow the table to **High severity**, **Quantum-vulnerable**, or **Export-controlled** rows.

Each row gives the family's **Base severity**, its **Post-quantum** verdict (for algorithms), and its **Export threshold**. Select a row to open its details drawer, which shows:

* the base severity, and any key-size or mode variants that change it
* the post-quantum verdict and the reasoning behind it
* the export-control line the family falls under
* the published sources each value cites

**Export ruleset** downloads the whole published ruleset as JSON. See [Where the severity comes from](/en/latest/earnie/using-earnie/triaging-findings#where-the-severity-comes-from) for how a base severity becomes a finding's severity.

## Reachability

A weak algorithm your application never runs is less urgent than one on a code path that runs. Earnie traces calls through your code and its dependencies to tell them apart:

| Reachability | What it means |
| - | - |
| **Reachable** | Earnie traced a call path from an entry point of your application. |
| **Not reached** | Earnie looked and found no such path. |
| **Unknown** | The analysis couldn't decide, and Earnie says so rather than guess. |

When a finding is reachable, you can open its **Call trace**. It shows the path from the entry point to the cryptographic call, hop by hop, including the libraries it passes through. Earnie raises a reachable finding with an assessed severity by one level, and the finding explains why. An unassessed finding is never raised.

<Note>
  **Not reached is not the same as not used.** Reachability is static
  analysis. It can't follow code that runs only through reflection or
  configuration. Treat a reachable finding as more urgent, but never treat an
  unreached one as harmless.
</Note>

See [Reachability](/en/latest/earnie/using-earnie/triaging-findings#reachability) for path strength, dependency chains, and reading the call trace.

## Reviewing cryptographic findings

### In the Review Workspace

In the [Review Workspace](/en/latest/earnie/using-earnie/triaging-findings#cryptographic-findings), a cryptographic finding highlights the exact lines in the same source panel as any other finding. To see only cryptography, open **+ Filter** and choose the **Cryptography** evidence type, or use one of the preset views: **Weak crypto**, **Quantum vulnerable**, or **Reachable crypto**. Cryptography also has its own filters, such as algorithm, algorithm family, reachability, post-quantum status, and key size.

You can record one of three decisions on each finding:

| Decision | Use it when |
| - | - |
| **Confirm usage** | The cryptography is in use. |
| **False positive** | It isn't cryptography. |
| **Accepted risk** | The usage is real, and you accept the risk. |

There's no "Fixed" decision. You fix a weak algorithm by removing it, and the next scan reports it gone. See [Making a decision](/en/latest/earnie/using-earnie/triaging-findings#making-a-decision).

### On the Algorithms page

Each project's sidebar has an **Algorithms** page that lists every algorithm detected in the project, one row per algorithm. Each row shows its key size, quantum status, severity, how many assets and files use it, its open findings, and the libraries that provide it.

Use it to answer questions such as "where do we use RSA?" or "what here isn't quantum-safe?". Select a row to open the Review Workspace filtered to that algorithm. See [Starting from the Algorithms page](/en/latest/earnie/using-earnie/triaging-findings#starting-from-the-algorithms-page).

### On the Dashboard

The project [Dashboard](/en/latest/earnie/using-earnie/dashboard) has a **Cryptography** tab with cards for reachability, asset composition, post-quantum exposure, export readiness, and algorithm families. Trend lines for **Reachable weak crypto** and **PQC-vulnerable assets** track how your cryptography changes across scans.

## What changed between scans

A completed scan's page has a **Crypto changes** card. It compares the scan with the nearest earlier scan that measured the project's cryptography in full, and counts findings as **New**, **Resolved**, **Re-detected**, or **Still open**. **Resolved** means the finding is absent from this scan.

The card appears only when there's an earlier scan to compare against. Without one, Earnie hides the card rather than showing zeros. See [Crypto changes between scans](/en/latest/earnie/getting-started/first-scan#crypto-changes-between-scans).

## Policies for cryptography

The same [policies](/en/latest/earnie/using-earnie/setting-policies) govern cryptographic findings as every other finding. With cryptography enabled, the policy editor offers a **Crypto** field group and seven cryptography templates:

* **Block reachable weak cryptography**
* **Flag quantum-vulnerable cryptography**
* **Block weak finite-field key sizes**
* **Block weak elliptic curves**
* **Warn on legacy protocol versions**
* **Warn on confidentiality crypto over export threshold**
* **Warn on unresolved export evidence**

Regulatory template sets, such as PCI DSS 4.0 and the EU Cyber Resilience Act, select all the templates mapped to a clause in one action. See [Rules about cryptography](/en/latest/earnie/using-earnie/setting-policies#rules-about-cryptography) for every template and field.

A cryptography policy gates pull requests, the pre-commit hook, and coding agents the same way as any other policy. See [When the gate blocks a merge](/en/latest/earnie/using-earnie/merge-gate).

## Evidence: CBOM and export control

### CBOM

A **CBOM** (cryptography bill of materials) lists your cryptographic assets in a standard format. In Earnie, it's a CycloneDX 1.7 document generated from an SBOM snapshot.

On a project's **SBOMs** page, select **Generate snapshot** and choose the **CBOM** scope. To get one document holding everything, choose **xBOM**, or turn on **Cryptographic assets** alongside open-source components. Each asset carries its cryptographic properties, where it occurs in your code, its reachability, and its export-control signals. SPDX doesn't support cryptographic assets, so a CBOM is always CycloneDX.

From the command line, `earnie export --include crypto` writes the same document. See [Exporting SBOMs](/en/latest/earnie/evidence/exporting-sboms#cryptographic-asset-details).

### The export-control evidence report

A snapshot that includes cryptographic assets also produces an **export-control evidence report**. This is one HTML file with the evidence you need to classify your own product under export-control rules. It lists the detected assets, their export-control signals, what Earnie scanned, and which ruleset it used.

The report is evidence for your own self-classification. It isn't legal advice, and it states no export classification. Download it from the snapshot's row menu, or from the Dashboard's **Download** menu. See [The export-control evidence report](/en/latest/earnie/evidence/exporting-sboms#the-export-control-evidence-report).

## What's next

* [Triaging findings](/en/latest/earnie/using-earnie/triaging-findings#cryptographic-findings) explains how to work through cryptographic findings in the Review Workspace.
* [Setting policies](/en/latest/earnie/using-earnie/setting-policies#rules-about-cryptography) explains how to turn your cryptography standards into rules.
* [Exporting SBOMs](/en/latest/earnie/evidence/exporting-sboms) explains how to produce a CBOM for a customer or an auditor.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.