Tensor Cryptographic Behavioural Audit
TCBA
Audit Your AI Models for Cryptographic Risk.
TCBA is the first audit primitive for the cryptographic content of machine learning model parameters, built for the regulatory perimeter created by the EU AI Act, DORA, and the Cyber Resilience Act. Detect cryptographic primitives embedded in tensor weights, score them against the post-quantum threat horizon, and emit a CycloneDX 1.6 bill of materials your auditors, regulators, and customers can verify.
Instant access · No minimum term · Cancel anytime
Move your cursor to steer the scan beam across the model layers
What TCBA produces
One Upload. Every Primitive. CycloneDX-Grade Evidence.
TCBA scans your model artefact across four detection layers and produces a single CycloneDX 1.6 cryptographic bill of materials. Every detected primitive is identified, located in the tensor, scored for quantum vulnerability, and mapped to a recommended post-quantum replacement.
Every scan generates a timestamped, optionally signed attestation in the proposed MBOM-PQC schema extension to OWASP CycloneDX. Attach it to conformity submissions, supply-chain registries, board reports, or regulator filings with confidence.
Cryptographic Bill of Materials
TCBA v0.1.0 · CycloneDX 1.6
Verdict
QUANTUM-WEAKENED
45 / 100 model score
below post-quantum threshold (Grover-affected primitives present)
Findings
encoder_layer_1.weight · L0
encoder_layer_2.bias · L0
The Cryptography You Cannot See
Every CISO has a software bill of materials. Every CISO can list the cryptographic libraries the code depends on. Almost no CISO can answer a different question: what cryptographic primitives live inside the weights of the AI models we run?
Embedded cryptography in model parameters is not theoretical. It arises by intentional placement, by incidental learning from training data that contained cryptographic constants, and by adversarial insertion during fine-tuning or quantisation. Every existing audit tool ignores this surface.
TCBA changes that.
Four-Layer Detection Cascade
Each layer is more expensive than the last. Earlier layers narrow the search space for later layers, making deep cryptanalysis tractable on full-size production models.
Layer 0: Constant Pattern Matching
Identifies known cryptographic constants within raw tensor bytes and within integer projections of floating-point values at numerical scales of 255, 256, and identity. Catches primitives embedded as scaled floats, not only as direct byte patterns.
Layer 1: Structural Analysis
Singular value decomposition of weight matrices, two-dimensional FFT, bit-plane decomposition of quantised tensors, and graph-theoretic matching against substitution-permutation, Feistel, sponge, and Merkle-Damgård templates.
Layer 2: Behavioural Cryptanalysis
Treats the model as a callable function and applies avalanche tests against the strict avalanche criterion, differential probing, linear approximation search, and algebraic degree estimation. Available on Enterprise tier.
Layer 3: Candidate Key Recovery
Authorisation-gated. Recovers candidate cryptographic key material corresponding to detected primitives using primitive-specific procedures for AES key schedules, RSA exponents, and elliptic curve scalars. Defence and Forensics tier only.
Built For Anyone Asking: What Cryptography Lives Inside Our Models?
TCBA is designed for the audit surface that SBOM, CBOM, and existing model security scanners do not cover.
How TCBA Works
From model artefact to signed bill of materials in minutes
01
Upload your artefact
safetensors, ONNX, PyTorch state dict, or GGUF. Streaming uploads to two gigabytes on the Pro tier; on-premises appliance for larger or restricted artefacts.
02
Scan across four layers
Constant pattern matching with integer projection runs first, then structural analysis, then behavioural cryptanalysis, then optional authorisation-gated key recovery.
03
Score for quantum vulnerability
Each primitive is classified as quantum-vulnerable, quantum-weakened, or quantum-resilient against your chosen threat horizon, with a recommended PQC replacement.
04
Download your CBOM
A timestamped, optionally signed CycloneDX 1.6 bill of materials in the proposed MBOM-PQC schema extension, ready for conformity submissions, board packs, or supply-chain registries.
See How TCBA Works
Watch a narrated journey through the portal, from model artefact to signed audit report and comparative scan.
Watch how TCBA worksPricing for Every Stage of AI Cryptographic Maturity
Professional
For AI platform teams, security consultants, and individual researchers
- Per-scan or annual licence options
- Models up to 2 GB per artefact
- Layer 0 and Layer 1 detection
- CycloneDX 1.6 CBOM download
- safetensors, PyTorch, and ONNX formats
- 90-day scan history
- Single user account
- Email support (48-hour SLA)
Enterprise
For large organisations, AI security teams, and regulated AI deployment
- Everything in Professional
- Layer 2 behavioural cryptanalysis
- Comparative scans (PQC migration verification)
- CI/CD plugins (Sagemaker, Vertex, Azure ML, Databricks, MLflow, GitHub Actions, GitLab CI, Jenkins, Azure DevOps)
- Digitally-signed CBOMs
- GGUF and TensorFlow SavedModel support
- Unlimited users with SSO/SAML
- Compliance mapping (EU AI Act, FDA, NIST SP 800-218A)
- Priority support (24-hour SLA)
Defence & Forensics
For government, defence, critical infrastructure, and incident response
- Everything in Enterprise
- Layer 3 authorisation-gated key recovery
- On-premises appliance (air-gapped, classified-ready)
- Chain-of-custody forensic reports
- Court-ready evidence packs
- Custom integrations (SIEM, GRC)
- Dedicated account manager
- Custom SLA (4-hour critical response)
Frequently Asked Questions
Enquire About TCBA
Tell us about your AI estate and audit requirements. We will be in touch within one business day.
MBOM-PQC Schema · Patent Pending · physivitis.tech