Skip to main content

Vault

Applies to:
Securosys HSMAWS KMSAzure Key VaultAlgorithm Assessment
Tip

The Vault source is the preferred way to inventory key-management keys. It supersedes the legacy Cloud source.

Overview​

The Vault source inventories the keys held in a vault that is already registered in the Cockpit. Because the vault connection is configured centrally, the scan reuses that registration to enumerate keys and assess each key's algorithm for quantum vulnerability. Supported vault types include Securosys HSM, AWS KMS, and Azure Key Vault.

What It Scans​

ItemDetails
Vault typesSecurosys HSM, AWS KMS, Azure Key Vault
KeysKeys enumerated from the registered vault
AlgorithmsAlgorithm and key parameters for each key
Quantum riskPer-key quantum vulnerability assessment

When to Use​

🔒

Managed Key Inventory

Assess the keys held in your HSM or cloud key-management service

✅

Preferred Over Cloud

Use this source instead of the legacy Cloud source for key-management inventory

How to Run​

Run a Vault scan from the Cockpit scan wizard:

1

Register the vault

Ensure the vault is already registered in the Cockpit.

2

Open Run a Scan

In the Cockpit, go to Run a Scan.

3

Select the source

In Step 1 (Source), choose Vault, pick the registered vault, then start the scan and review the findings.