PRODUCT GUIDE
quick start
Local software · limited supported scope
CryptoProof Quick Start: Create a questionnaire draft
CryptoProof helps a software vendor draft answers to a customer's cryptography questionnaire. It reads an Excel questionnaire and a CBOM (an inventory of cryptographic assets in a product). It fills only bounded answers supported by the supplied evidence and leaves other questions unresolved. Your team reviews every row before creating a final Evidence Pack.
This is an Early Access candidate, not a published general-availability product. Read the supported scope before using a customer workbook. The steps below use only the synthetic files in the local review bundle.
Before you start
Follow local installation to install the wheel in a dedicated Python environment. Open PowerShell in the extracted review bundle folder, which contains sample/, docs/, and wheel/. Activate that environment or use its python.exe as $py:
$py = 'C:\path\to\your\venv\Scripts\python.exe'
& $py -m cryptoproof --version
If you are running from the source repository instead, use release-sample/ in place of sample/, set $env:PYTHONPATH = 'src', and point $py at a Python 3.10+ installation with the dependencies specified in pyproject.toml.
1. Check the questionnaire
Preflight reads the original Excel file and reports which columns it will use. It does not change the file.
& $py -m cryptoproof preflight `
--questionnaire sample/sample-questionnaire.xlsx `
--output preflight.json
This first check reports MAPPING_REQUIRED: the nonempty Read me sheet must be reviewed before it is ignored. The bundle includes sample/sample-mapping.json, an acknowledgement made for this exact synthetic sheet content. Rerun:
& $py -m cryptoproof preflight `
--questionnaire sample/sample-questionnaire.xlsx `
--mapping sample/sample-mapping.json `
--output mapped-preflight.json
The second check reports READY, 28 questions, and Read me under acknowledged_ignored_sheets. For a real workbook, inspect every sheet yourself. Use map for an unfamiliar question sheet or ignore --confirm-no-questions only after confirming a non-question sheet contains no questions. An acknowledgement stops working if that sheet's content changes.
2. Create a draft
& $py -m cryptoproof compile `
--cbom sample/sample-product.cdx.json `
--questionnaire sample/sample-questionnaire.xlsx `
--mapping sample/sample-mapping.json `
--output answered-sample.xlsx
The original sample XLSX is untouched. Open answered-sample.xlsx, a draft copy of the original template, and the sibling answered-sample-cryptoproof/ directory with the evidence, limitations, and review files. The synthetic example processes 28 questions and writes 11 draft answers. No submission ZIP is produced at this step.
| Status | Meaning | Your next action |
|---|---|---|
VERIFIED | A narrow fact is supported by the supplied CBOM | Check its evidence and product scope |
PARTIAL | Some evidence exists, but does not prove the full claim | Review the stated limitation |
UNKNOWN | There is not enough evidence | Find other evidence or leave unresolved |
OWNER_INPUT_REQUIRED | A company decision or policy answer is needed | Ask an authorized person in your organization |
OWNER_APPROVED | A previously approved company answer was reused | Recheck its wording, scope, and expiry |
Even VERIFIED refers only to the supplied CBOM. CryptoProof does not certify compliance or prove that every cryptographic asset was discovered.
3. Review before any submission
Read answered-sample-cryptoproof/review-required.json and the evidence manifest. A vendor reviewer must decide what to approve or leave unresolved for every question. The self-service guide explains column mapping, approved company answers, per-row review, and the separate finalize command that produces the final ZIP. Do not send the draft workbook or draft ZIP to a customer.