LatticeScan

Evidence

Cryptographic threat monitoring, as evidence

Regulated crypto firms are now asked to show that they monitor cryptanalytic threats, quantum included, and can change their cryptography as those threats develop. The tools that sell evidence for this look at enterprise PKI and TLS. None of them looks at the on-chain signing keys that actually hold a crypto firm’s assets. This pack measures both surfaces from public data, maps each fact to the clause it evidences, says plainly where the result is a gap, and signs the whole thing with ML-DSA-65 so a supervisor or auditor can confirm it is unaltered.

Generate signed evidence pack (PDF)View signed JSONA first-time domain scan takes up to a minute.

Nothing leaves the public record: the domain scan uses public certificate logs and a TLS handshake; the addresses are read from public chain data. No key material is ever requested.

What the pack maps to

Each clause below is quoted from, and linked to, the primary text. The pack also maps to NIST CSWP 48 (post-quantum cryptography in CSF 2.0 terms).

How to read a status

Evidence: the measurement supports the clause as written.

Partial: it supports part of the clause; the pack names what is missing.

Gap: the measurement shows the clause is not yet met, or cannot be met with current standards. On-chain signatures are one such gap for every firm today: no production post-quantum signature exists for them, so the pack records that honestly rather than pretending otherwise.

Need the pack on a schedule, under NDA, or for addresses that are not public? The method is the same; only the address set and the cadence change.

Talk to us

Related: on-chain exposure, reserve attestations, how reports are signed and verified.