Automated cryptographic security auditing for applications
5.0/5 (1 review)We have used the Cryptosense analyzer to assess the strength of our cryptography which we use in the product
Pros
- Very accurate findings
- The recommendations are straightforward and cannot be misinterpreted. In some cases they are very useful to evaluate the real impact on the software
- This type of scanning allows to catch all types of cryptography calls in JVM, not only the one that originate directly from the application, but also that are triggered indirectly by a middleware
- Low ration of false positives
Cons
- The size of the traces for products that do a lot of cryptography calls can be problematic, it can be too big for producing the report (this was however quickly resolved by excellent support)
- There was no direct support for Cloud vendors solutions around key management (e.g. AWS KMS), however some of the Cloud services uses standard Java Cryptography API and hence we would able to identified some findings and the Cryptosense team is working to add this type of support
Rating breakdown
Likelihood to recommend: 8/10
14-day trial available.
Standard = $595 per month, per app ($795 per month if paid annually)
Preimium = $1195 per month, per app ($1595 per month if paid annually)
Premium+ = $1495 per month, per app ($1949 per month if paid annually)
Enterprise = Quote available on request