MigrationOS assessment

Build a bounded cryptographic exposure baseline in 10 business days.

A fixed-scope, read-only crypto discovery assessment for regulated teams that need an inspectable CBOM, a risk-ranked report, and reproducible run evidence before they can plan post-quantum remediation.

The first offer

Founder-led, customer-controlled delivery.

Duration

10 days

Access

Read-only

Output

3 files + readout

Goal

Decision signal

The assessment produces a bounded decision record. It does not include migration execution, continuous monitoring, a hosted account, or an uptime SLA.

What you get

  • cbom.cyclonedx.json — cryptographic bill of materials for the agreed scope
  • risk-ranked-report.md — prioritized findings and remediation decision support
  • run-manifest.json — reproducibility and execution evidence
  • 60-minute engineering readout with security and technology stakeholders

Data boundaries

  • Read-only by default
  • No raw private keys required
  • No production write access
  • Finding snippets redacted in customer outputs by default
  • Customer-controlled execution can be isolated from network egress
  • NDA and data-handling addendum before real customer data
  • Assessment artifacts deleted on the agreed retention schedule
  • No FIPS module-certification claim

Timeline

A fixed scope, not an open-ended pilot.

The goal is to produce enough evidence for a buyer to decide whether a deeper paid pilot is justified.

Day 0

Scope

Pick repositories, sample environments, certificate stores, or config paths. We confirm data boundaries before any scan.

Days 1-3

Read-only discovery

MigrationOS scans the agreed scope without moving key material or requiring production write access.

Days 4-7

CBOM and prioritization

We normalize findings into a CycloneDX CBOM and rank supported findings by migration urgency.

Days 8-10

Readout

You receive three reviewable artifacts and a 60-minute engineering readout. Follow-on remediation is scoped separately.

Founder-led this week

Request a 30-minute scoping call.

Bring one environment, one compliance driver, and one owner. We will confirm whether the 10-day assessment is a fit before asking for anything else.

Email Latticis
10-day crypto exposure assessment | Latticis