Vanta proves your processes. ProofByte proves your bytes.
ProofByte is a technical-evidence engine for the 2027–2028 regulatory wave: it scans your actual code, containers and runtime, and produces machine-verifiable, auditor-ready artifacts — not questionnaires.
| Pack | Status | Regulatory driver |
|---|---|---|
| pqc-radar — cryptographic inventory (CBOM) + post-quantum migration plan | 🚧 v0 | US EO 14412, CNSA 2.0 (2027), UK NCSC (2028), EU PQC transition (from 2026) |
| agent-trace — AI-agent inventory + tamper-evident action-log verification | 🚧 v0 | EU AI Act Art. 12 (high-risk deadline 2027-12-02), Kazakhstan AI Law 230-VIII |
npx @proofbyte/pqc-radar scan ./my-repo --cbom cbom.json --report report.md --sarif findings.sarifagent-trace inventories the agents a codebase declares (MCP server configs,
agent-framework imports, workflow files) and independently verifies a
hash-chained action log — the evidence an auditor asks for when the question is
"what did the agent actually do":
npx proofbyte-agent-trace scan ./my-repo --out agents.json
npx proofbyte-agent-trace verify ./journal.jsonl
npx proofbyte-agent-trace evidence --inventory agents.json --journal journal.jsonl --report evidence.mdThe verifier is deliberately a separate implementation from the writer: proof that only its own author can check is not proof. The package's test suite verifies a journal produced by a Python writer.
pqc-radar walks your repository, detects quantum-vulnerable cryptography
(RSA, ECC/ECDSA/ECDH, DH, DSA, Curve25519, legacy hashes, weak TLS configs) and emits:
cbom.json— a CycloneDX 1.6 Cryptographic Bill of Materials, the artifact regulators and auditors ask for;report.md— a human-readable findings report with a prioritized migration plan (ML-KEM / FIPS 203, ML-DSA / FIPS 204, hybrid TLS);findings.sarif— a SARIF 2.1.0 log for GitHub code scanning or any SARIF viewer.
Fast: hashicorp/vault (4 827 files) scans in ~9 s, node-forge in ~0.7 s — see real-world corpus results, regenerated weekly in CI, and the honest benchmark vs PQCA CBOMkit (spoiler: they're complementary — CBOMkit goes deeper on Java/Python, pqc-radar covers the whole polyglot estate).
Language coverage (v0): Java/Kotlin/Scala, Python, JavaScript/TypeScript, Go, C#, Rust, Ruby, PHP, C/C++, plus nginx/Apache TLS configs and certificate/keystore file discovery.
npx @proofbyte/pqc-radar scan-tls your-api.example.com github.com:443One handshake per host (no data sent) reports the negotiated protocol, cipher, key-exchange group and certificate key — and whether the endpoint already speaks hybrid post-quantum key exchange (X25519+ML-KEM-768) or is still harvest-now-decrypt-later exposed. Unknown groups are reported as inconclusive, never as findings.
- uses: oleg-vdv/proofbyte@v1
with:
fail-on-findings: 'true'Or with plain npx:
- run: npx @proofbyte/pqc-radar scan . --sarif findings.sarif --fail-on-findings
- uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: findings.sarifAdd the badge to show your repo is scanned:
[](https://github.com/oleg-vdv/proofbyte)The code scanner is fully offline (no network calls), has zero runtime dependencies,
never modifies scanned code, skips symlinks, and only writes the output files you name.
scan-tls is the one network feature: it connects only to endpoints you explicitly list
and sends no payload beyond the TLS handshake. See SECURITY.md.
v0 uses fast line-pattern detection. Absence of findings is not proof of absence. Planned: PQCA CBOMkit engine integration for deep AST analysis, container/TLS endpoint collectors, signed artifacts.
npm install
npm run build
npm testGolden-fixture tests live in packages/pqc-radar/test/fixtures — small repos with
deliberately planted crypto; every scanner change is verified against them. CI also
dogfoods: the repo scans itself on every push.
- The post-quantum deadlines are closer than your roadmap thinks — so I built a CBOM scanner (dev.to)
- Benchmark vs PQCA CBOMkit · Real-world corpus
MIT