Patent Pending · NOW AVAILABLE · MBOM-PQC Schema

Tensor Cryptographic Behavioural Audit

TCBA

Audit Your AI Models for Cryptographic Risk.

TCBA is the first audit primitive for the cryptographic content of machine learning model parameters, built for the regulatory perimeter created by the EU AI Act, DORA, and the Cyber Resilience Act. Detect cryptographic primitives embedded in tensor weights, score them against the post-quantum threat horizon, and emit a CycloneDX 1.6 bill of materials your auditors, regulators, and customers can verify.

Instant access · No minimum term · Cancel anytime

Move your cursor to steer the scan beam across the model layers

What TCBA produces

One Upload. Every Primitive. CycloneDX-Grade Evidence.

TCBA scans your model artefact across four detection layers and produces a single CycloneDX 1.6 cryptographic bill of materials. Every detected primitive is identified, located in the tensor, scored for quantum vulnerability, and mapped to a recommended post-quantum replacement.

Every scan generates a timestamped, optionally signed attestation in the proposed MBOM-PQC schema extension to OWASP CycloneDX. Attach it to conformity submissions, supply-chain registries, board reports, or regulator filings with confidence.

Cryptographic Bill of Materials

TCBA v0.1.0 · CycloneDX 1.6

Verdict

QUANTUM-WEAKENED

45 / 100 model score

below post-quantum threshold (Grover-affected primitives present)

Findings

AES S-box (forward)WEAKENED

encoder_layer_1.weight · L0

SHA-256 K constantsWEAKENED

encoder_layer_2.bias · L0

Signed · tech.physivitis.tcba

The Cryptography You Cannot See

Every CISO has a software bill of materials. Every CISO can list the cryptographic libraries the code depends on. Almost no CISO can answer a different question: what cryptographic primitives live inside the weights of the AI models we run?

Embedded cryptography in model parameters is not theoretical. It arises by intentional placement, by incidental learning from training data that contained cryptographic constants, and by adversarial insertion during fine-tuning or quantisation. Every existing audit tool ignores this surface.

TCBA changes that.

Four-Layer Detection Cascade

Each layer is more expensive than the last. Earlier layers narrow the search space for later layers, making deep cryptanalysis tractable on full-size production models.

Layer 0: Constant Pattern Matching

Identifies known cryptographic constants within raw tensor bytes and within integer projections of floating-point values at numerical scales of 255, 256, and identity. Catches primitives embedded as scaled floats, not only as direct byte patterns.

Layer 1: Structural Analysis

Singular value decomposition of weight matrices, two-dimensional FFT, bit-plane decomposition of quantised tensors, and graph-theoretic matching against substitution-permutation, Feistel, sponge, and Merkle-Damgård templates.

Layer 2: Behavioural Cryptanalysis

Treats the model as a callable function and applies avalanche tests against the strict avalanche criterion, differential probing, linear approximation search, and algebraic degree estimation. Available on Enterprise tier.

Layer 3: Candidate Key Recovery

Authorisation-gated. Recovers candidate cryptographic key material corresponding to detected primitives using primitive-specific procedures for AES key schedules, RSA exponents, and elliptic curve scalars. Defence and Forensics tier only.

Built For Anyone Asking: What Cryptography Lives Inside Our Models?

TCBA is designed for the audit surface that SBOM, CBOM, and existing model security scanners do not cover.

Financial services AI risk teams under DORA, MiCA, and the EU AI Act
Defence and government AI procurement evaluating supplier models
AI platform teams enforcing pre-deployment cryptographic policy in CI/CD
Conformity assessors and Notified Bodies under EU AI Act Article 15
Open-source model maintainers and marketplaces attesting supply chain integrity
M&A teams diligencing AI assets in acquisition targets
Forensic and incident response investigators of compromised AI systems
Auditors extending PQC migration plans to cover the AI estate

How TCBA Works

From model artefact to signed bill of materials in minutes

01

Upload your artefact

safetensors, ONNX, PyTorch state dict, or GGUF. Streaming uploads to two gigabytes on the Pro tier; on-premises appliance for larger or restricted artefacts.

02

Scan across four layers

Constant pattern matching with integer projection runs first, then structural analysis, then behavioural cryptanalysis, then optional authorisation-gated key recovery.

03

Score for quantum vulnerability

Each primitive is classified as quantum-vulnerable, quantum-weakened, or quantum-resilient against your chosen threat horizon, with a recommended PQC replacement.

04

Download your CBOM

A timestamped, optionally signed CycloneDX 1.6 bill of materials in the proposed MBOM-PQC schema extension, ready for conformity submissions, board packs, or supply-chain registries.

See How TCBA Works

Watch a narrated journey through the portal, from model artefact to signed audit report and comparative scan.

Watch how TCBA works

Pricing for Every Stage of AI Cryptographic Maturity

Most Popular

Professional

Contact for pricing

For AI platform teams, security consultants, and individual researchers

  • Per-scan or annual licence options
  • Models up to 2 GB per artefact
  • Layer 0 and Layer 1 detection
  • CycloneDX 1.6 CBOM download
  • safetensors, PyTorch, and ONNX formats
  • 90-day scan history
  • Single user account
  • Email support (48-hour SLA)
Contact Us

Enterprise

Contact for pricing

For large organisations, AI security teams, and regulated AI deployment

  • Everything in Professional
  • Layer 2 behavioural cryptanalysis
  • Comparative scans (PQC migration verification)
  • CI/CD plugins (Sagemaker, Vertex, Azure ML, Databricks, MLflow, GitHub Actions, GitLab CI, Jenkins, Azure DevOps)
  • Digitally-signed CBOMs
  • GGUF and TensorFlow SavedModel support
  • Unlimited users with SSO/SAML
  • Compliance mapping (EU AI Act, FDA, NIST SP 800-218A)
  • Priority support (24-hour SLA)
Contact Sales

Defence & Forensics

Contact for pricing

For government, defence, critical infrastructure, and incident response

  • Everything in Enterprise
  • Layer 3 authorisation-gated key recovery
  • On-premises appliance (air-gapped, classified-ready)
  • Chain-of-custody forensic reports
  • Court-ready evidence packs
  • Custom integrations (SIEM, GRC)
  • Dedicated account manager
  • Custom SLA (4-hour critical response)
Request Quote

Frequently Asked Questions

Enquire About TCBA

Tell us about your AI estate and audit requirements. We will be in touch within one business day.

Your information is used solely to respond to your enquiry. It is not shared with third parties. Privacy Policy.

MBOM-PQC Schema · Patent Pending · physivitis.tech