Core
D2C, Retail & E-commerce
PCI DSS 4.0 §12.3.3, the mandatory cryptographic inventory, already in force
PCI DSS 4.0 already requires a cryptographic inventory. Most teams do it by hand once a year, we do it continuously.
What's exposed in a d2c, estate
Checkout TLS + third-party script sprawl
The Magecart problem, a payment page loading eleven external scripts.
Loyalty & gift-card cryptography
Which is money.
Fake storefronts & brand impersonation
AI-accelerated brand abuse at machine speed.
Your product set
Every product that applies here.
3 shipping now · 23 total
Open & Free
Dhiti Q-Day Scanner
Scan a domain, free.
Public, no-signup. Enter a domain and in ~40 seconds see every TLS endpoint, its cipher suites, key-exchange groups, certificate health, whether it offers hybrid PQC, and a Mosca countdown of the confidentiality you're losing today.
Dhiti CBOM CLI
cbom scan ./repo
Open-source CLI and GitHub Action. Apache-2.0, CycloneDX 1.6 output. Lives in the developer workflow long before sales ever calls.
Control Plane
Dhiti Command
One pane of quantum-safe control.
Executive posture dashboard and migration program tracking across repos, teams and business units, with RBAC and multi-tenant isolation plus region pinning at the schema level.
Dhiti Prajna
Your migration analyst, on tap.
Natural-language queries over your CBOM and findings, prioritised remediation, auto-drafted migration PRs, and generated compliance narratives, the model runs in-region.
Core Engines
Dhiti Discover
Know your exposure.
Scans code, configs, certificates, dependency manifests and infrastructure across 8+ languages; detects RSA/ECDH/ECDSA/DH; produces a risk-prioritised CycloneDX CBOM. You cannot migrate what you cannot see.
Dhiti Comply
Prove it to the regulator.
Maps inventory and key usage to NIST IR 8547, CNSA 2.0, RBI, CERT-In, DPDP 2023, NIS2 and more; produces audit-ready evidence packs. The GRC module covers ISO, SOC 2, PCI and DPDP alongside the post-quantum frameworks.
Trust Layer
Dhiti Sentinel
Catch exposure the moment it ships.
CI/CD and GitHub Actions guardrails that block quantum-vulnerable code, detect crypto drift across releases, and export real-time alerts to your SIEM/SOAR.
Dhiti Certus
Every certificate, accounted for.
Certificate lifecycle management and PKI modernisation, discover every cert, alert on expiry and weak algorithms, automate renewal via ACME/CA, and prepare PQ-hybrid certificate readiness.
Dhiti Connect
Every system you run, aware.
The connector fabric, source, cloud, SIEM/SOAR, ITSM, key sources and PQC libraries all wired into one platform without rip-and-replace.
Enforcement
Dhiti Aegis
Quantum-safe on the wire.
Policy-enforced PQ-hybrid TLS termination and inline crypto policy for north-south and east-west traffic, plus PQ-VPN for branch, remote and partner links, without re-architecting applications.
Dhiti Halo
PQ sessions, everywhere people work.
Browser, endpoint and mobile PQ-hybrid session protection for apps that can't be changed, a PQC channel for legacy estates, delivered without touching the application.
Exposure & Cloud
Dhiti Horizon
Crypto posture for every cloud.
Agentless posture management for cryptography across AWS/Azure/GCP: KMS key inventory, TLS/cert drift, storage and DB encryption modes, and IaC scanning for weak crypto before merge.
Dhiti Perimeter
See what the attacker sees.
Continuous external discovery of internet-facing cryptography, TLS versions, cipher suites, cert chains, quantum-vulnerable endpoints, plus a classical mode covering the full external attack surface. No agents, starts from a domain.
Dhiti Respond
A crypto incident has a playbook.
Crypto-incident response: algorithm-break and key-compromise playbooks, blast-radius mapping from the CBOM, emergency rotation through Orchestrate + Vault, and DFIR for all incidents.
Cyber Resilience
Dhiti SOC
MDR on the tools you own.
AI-assisted managed detection and response on the tooling you already bought, Splunk, Sentinel, QRadar, CrowdStrike, SentinelOne, Defender. 24×7 from an India-based SOC. No rip-and-replace.
Dhiti Intel
A directive is a task, not a PDF.
Operational threat intelligence: brand monitoring and takedown, dark-web and credential-leak monitoring, sector-specific feeds, and standards/mandate tracking so a new CERT-In or RBI directive reaches you as a task.
Dhiti TPRM
Is my vendor PQC-ready?
Third-party and supply-chain risk: vendor questionnaires, continuous external posture scoring of your vendors, contract-clause tracking, and, uniquely, vendor cryptographic posture as a field, not a phone call.
Dhiti Quantify
Risk, in money.
Cyber risk quantification: FAIR-style loss modelling for classical risk, plus HNDL quantification, for each data class, the confidentiality years being lost today and the modelled cost. This is the screen that gets budget approved.
Dhiti Aware
Meet the attack in training first.
Workforce risk: phishing simulation with LLM-generated, sector-specific lures, role-based training paths, and executive briefings. Extends Dhiti Academy from skills to behaviour.
Intelligence & Services
Dhiti Labs
Know the threat before the mandate.
Quantum-threat intelligence: standards tracking (NIST/BSI/CNSA/RBI/CERT-In), advisories on algorithm and library weaknesses, the Dhiti Quantum Threat Index, and research notes that feed the blog.
Dhiti Assure
An assessment for the board.
Post-quantum readiness assessment, cryptographic architecture review, crypto-focused VAPT, and DAST/SAST/SCA, red/blue/purple teaming, board-ready findings and a costed migration plan.
Dhiti Managed
Run the migration with us.
Managed migration programme and co-managed crypto assurance: dedicated migration engineers, monthly posture reviews, drift triage, evidence-pack production, and a virtual crypto-CISO retainer.
Dhiti Academy
Teach the estate, not the tool.
Role-based training and certification: PQC fundamentals for engineers, crypto-agile design patterns, compliance workshops, executive briefings, and a public Dhiti Certified Quantum-Safe Engineer track.
Frameworks for this sector
Recommended edition
Professional
Connect for PricingRegulated mid-market, multi-repo, SSO/SAML
Migration sequence
- 01First 90 days90 daysdiscovercomply
- 02First year12 monthscertusperimeterintel
- 03Multi-yearmulti-yearaegishorizon
Sector FAQ
- Where do we start in retail?
- Every engagement starts with Discover, a crypto inventory and CBOM. You cannot migrate what you cannot see, and even at stage one you leave with a CBOM.
- Do you replace our existing tools?
- No. Dhiti runs on the SIEM, EDR and scanners you already own, and adds the cryptographic layer none of them cover.
