Core Engines
Know your exposure.
Scans code, configs, certificates, dependency manifests and infrastructure across 8+ languages; detects RSA/ECDH/ECDSA/DH; produces a risk-prioritised CycloneDX CBOM. You cannot migrate what you cannot see.
Built for
Overview
A closer look at Discover.
Scans code, configs, certificates, dependency manifests and infrastructure across 8+ languages; detects RSA/ECDH/ECDSA/DH; produces a risk-prioritised CycloneDX CBOM. You cannot migrate what you cannot see.
Dhiti Discover lives in the Core Engines of the platform, whose job is simple: discover, orchestrate, prove. It ships as part of Dhiti Secure, software platform, the saas that funds the company, so it carries the same sovereignty posture as everything else Dhiti runs: region pinning, keys that stay inside the HSM, and an air gapped deployment for estates that need it.
Nothing here works in isolation. Every product on the platform reads and writes to one shared cryptographic asset graph, so what Discover produces becomes usable everywhere else: a finding here becomes a prioritised task there, and a change becomes a line of audit evidence a regulator will accept. You can adopt Discover on its own, fold it into an edition, or grow into it as your estate matures. It is built to sit above the tools you already bought rather than replace them.
At a glance
- Plane
- Core Engines
- Line
- Dhiti Secure
- Status
- LIVE
- Engine
- CryptoShift
- Capabilities
- 5
- Pricing
- Connect for pricing
Why it matters
The problem it solves.
Most teams cannot answer a basic question about their own cryptography: where is it, what algorithms are in use, and what breaks when one of them is deprecated. That gap is not a tooling failure so much as an ownership failure. The SIEM, the EDR, the scanner and the GRC spreadsheet each see a slice, and none of them owns the cryptographic picture.
Discover closes its part of that gap in a way you can measure. Instead of a point in time report that is stale the day it ships, you get a living view that updates as your estate changes, ranked by real risk rather than raw volume, and expressed in the language your auditors and your board already use.
Capabilities
What Discover does.
Multi-language scan
Python, Java, JS/TS, Go, C/C++, Rust, C#.
Algorithm detection
RSA, ECDH, ECDSA, DH, and weak legacy (MD5, SHA-1, 3DES, RC4).
CBOM output
Signed CycloneDX 1.6 CBOM, SPDX 3.0, JSON, GraphQL API.
Risk prioritiser
Mosca scoring and blast radius, not a flat list.
Source connectors
GitHub, GitLab, Bitbucket, Azure Repos.
Strengths
Why teams choose Discover.
Multi-language scan
Python, Java, JS/TS, Go, C/C++, Rust, C#.
Algorithm detection
RSA, ECDH, ECDSA, DH, and weak legacy (MD5, SHA-1, 3DES, RC4).
Runs on what you already own
It operates inside your existing Splunk, Sentinel, QRadar, CrowdStrike, cloud and CI/CD rather than asking you to rip anything out. Adoption is additive, not a migration in itself.
Sovereign by architecture
Data is region pinned to Mumbai, Singapore or Frankfurt at the schema level, keys are handled by reference and never leave the HSM, and a dedicated air gapped edition exists for critical infrastructure.
Honest about what ships
Every capability carries a status token. Nothing is dressed up as available today when it is on the roadmap, which is exactly what a compliance buyer needs to hear.
Priced to the Indian enterprise
The cost structure is built for regulated Indian buyers first, and pricing is quoted against your actual estate rather than a Western enterprise list price.
How it works
Four steps, one asset graph.
Connect
Discover wires into your sources, clouds and tools through the Dhiti connector fabric, read only wherever it can be, so it starts from the estate you actually run.
See
Multi-language scan: Python, Java, JS/TS, Go, C/C++, Rust, C#. Everything it finds flows into the shared cryptographic asset graph.
Act
Algorithm detection: RSA, ECDH, ECDSA, DH, and weak legacy (MD5, SHA-1, 3DES, RC4). Work is ranked by blast radius and confidentiality lifetime, not by raw count.
Prove
Posture rolls up to Dhiti Command and evidence to Dhiti Comply, region pinned and audit ready, so the work you do is the work you can show a regulator.
Sub-modules
Individually named, individually sold.
| NetSensor | TLS/SSH/IPsec/Kerberos via SPAN/TAP/eBPF, JA4 fingerprinting. No decryption. |
| ScanSensor | External + internal attack surface, cipher enumeration, downgrade testing. |
| CodeSensor | AST + dataflow across OpenSSL, BouncyCastle, JCA/JCE, PyCA, Go crypto, WebCrypto. |
| BinarySensor | Container images, ELF/PE/Mach-O, firmware blobs, no source access needed. |
| HostAgent | Java cacerts, Windows cert store, /etc/ssl, PKCS#11, TPM. Read-only. |
| CloudSensor | AWS KMS/ACM, Azure Key Vault, GCP KMS, TLS policies. Agentless. |
| PKISensor | AD CS, internal + external CAs, HSM fleet (Thales/Entrust/Utimaco). |
| LegacySensor | z/OS ICSF, AS/400, OT/ICS protocols, medical and industrial devices. |
| SiliconSensor | Crypto burned into boot ROMs, TPMs, secure elements. No competitor ships this. |
Works with
It compounds.
Discover finds it. Orchestrate fixes it. Comply proves it.
Where it applies
Built for the estates that carry the risk.
This one applies across every sector Dhiti serves. A few of the most common:
Banking
RBI Master Directions, CERT-In, payment HSM estate, 2030
Financial Services & Capital Markets
SEBI CSCRF, DORA-aligned, clearing/settlement long-lived records
Insurance
IRDAI cyber norms, 30-year policy confidentiality, DPDP
Insurtech
IRDAI, DPDP, rapid product teams shipping crypto they don't inventory
Fintech & Payments
PCI DSS 4.0 §12.3.3, a cryptographic inventory is already mandatory
IT & Software Services
You migrate your clients' estates, Dhiti as channel and as your own control
Integrations
Frameworks satisfied
What we measure
8+
languages scanned
40s
to first Q-Day grade
Frequently asked
Questions a buyer actually asks.
- Does Discover replace the tools we already have?
- No. It runs alongside your existing security stack and adds the cryptographic layer none of those tools cover. You keep your SIEM, EDR and scanners; Discover makes them part of one picture.
- Where does our data live, and who can see the keys?
- Data is pinned to your chosen region at the schema level, tenants are isolated row by row, and keys are handled by reference so they never leave the HSM. For government, defence and critical infrastructure there is an air gapped Sovereign deployment.
- Is Discover available today?
- Yes. Discover is shipping now, and you can see it on your own estate in a demo.
- What does it work with?
- It compounds with Orchestrate, Comply, Certus, Sentinel and the rest of the suite through the shared asset graph. Discover finds it, Orchestrate fixes it, Comply proves it.
- How is it priced?
- Pricing is quoted per estate rather than published as a list price. Tell us your sector and scale and we will put a number to it. Every edition includes cryptographic discovery, so even at the entry tier you leave with a CBOM.
Related reading
Quantum threat research
Harvest now, decrypt later, explained for people who own the risk
PQC standards & compliance
