VAJRA RECON scans source code and lockfiles you provide (zip export) for pattern-matched weak cryptography — MD5, SHA-1, weak TLS, RSA references, and more. Findings require engineering validation; this is not a full HSM, network, or regulatory sign-off.
Honest scope: static analysis only. No live GitHub/AWS connector on this page. CI/CD webhooks and admin assessment are available for enterprise deployments.
What you receive (enterprise pilot)
Executive summary is drafted after your engineer validates findings — not from raw scanner grades.
For banks & fintech
Production CBOM engine — scoped export, static scan, engineer validation, then executive readout.
Client exports repository source + lockfiles. Exclude .env, keys, node_modules, and secrets.
Pattern + dependency audit with false-positive policy. Optional AST/taint when tree-sitter is available in the deployment image.
Full bundle (JSON, MD, HTML, SARIF, PDF + manifest) delivered after pilot kickoff. Your team validates findings before any audit claim.
Full report bundle + PQC migration path on VajraShield. We respond to verified corporate email.