Import approved source data
Versioned algorithm and key inventory
CBOM · GOVERNANCE PRODUCT / PLATFORM MODULE
Maintain a versioned cryptographic bill of materials for systems, applications and suppliers.
CUSTOMER PROBLEM
Cryptographic assets change across releases and suppliers; a one-time spreadsheet cannot support lifecycle governance, audit or migration waves.
PRODUCT-SPECIFIC IMPLEMENTATION FLOW
CSV/JSON import, assessment workflow and project-specific connectors. Versioned CBOM, ownership records, review history and exportable audit package.
Versioned algorithm and key inventory
Certificate, OID and profile registry
Software, firmware and supplier dependency mapping
Ownership, review and exception workflow
CSV/JSON import and controlled export
Change history for audit and procurement
NAMED COMPONENTS AND RESPONSIBILITIES
The descriptions below state concrete technical behaviour rather than generic support language.
Stores algorithm, key type, key length, purpose, location and lifecycle state as versioned records rather than unstructured assessment notes.
Maintains certificate profiles, OIDs, issuance hierarchy, validity rules and relying-party dependencies alongside the systems that consume them.
Connects software packages, firmware builds, devices and suppliers so that a library or vendor change can be traced to affected services.
Routes additions, corrections and exceptions through named owners, reviewers and approval states with a complete change history.
Accepts controlled CSV or JSON imports with schema validation and produces filtered exports for engineering, audit and procurement audiences.
Preserves who changed each record, why it changed, what evidence supported it and which inventory version was used for a decision.
CSV/JSON import, assessment workflow and project-specific connectors.
Collectors run against approved sources; findings are reviewed before entering the governed inventory.
Scheduled collectors and connectors feed the inventory, risk and policy workflows under customer control.
Mobile-ID facilitates refresh, review and reporting while the customer retains ownership and approval authority.
PRODUCT-SPECIFIC BOUNDARIES
These points come from the product profile, not from a shared disclaimer.
NEXT STEP
Review the exact operating model, interfaces and evidence needed for deployment.