PRODUCT GUIDE
supported scope
Local software · limited supported scope
Supported scope for CryptoProof Early Access
Initial supported offer, 2026-10-08. This is the supported subset, not a claim that arbitrary questionnaires work.
Supported
| Area | Boundary |
|---|---|
| Local runtime | Windows 11 x64 and official independently installed CPython 3.13.16 with venv/pip; pinned openpyxl==3.1.5 and et-xmlfile==2.0.0 wheels are supplied. Other Python versions and operating systems are outside the initial supported offer. |
| CBOM | CycloneDX JSON 1.6 or 1.7, up to 10 MiB and 5,000 components. The tool uses selected supplied fields; it is not a full schema validator or scanner. |
| Questionnaire | .xlsx up to 10 MiB, with bounded decompressed size and worksheet dimensions. Recognizable question/answer/evidence headers on the first 25 rows, or explicit user mapping. Every nonempty unmapped sheet needs an explicit, content-bound ignore --confirm-no-questions acknowledgement after vendor inspection. Normalized CSV with question_id,question headers is accepted without original-template write-back. |
| XLSX write-back | A new output copy. Only empty, explicitly identified answer/evidence cells receive supported drafts. Sheet names, order, unrelated cells, and tested styles are preserved. Existing values are not overwritten. |
| Answers | Deterministic evidence-based technical statements where eligible; VERIFIED, PARTIAL, UNKNOWN, OWNER_INPUT_REQUIRED, and separately labeled vendor OWNER_APPROVED assertions from narrow answer templates. Unrecognized algorithm names are not treated as known cryptography. No negative answer is inferred from absence in a CBOM. |
| Final pack | A draft first; explicit per-question vendor review, unchanged public draft and unchanged local source inputs are required for finalize. The final ZIP includes bounded customer artifacts and an approval record, not the internal path map. |
Rejected or outside scope
- Macro-enabled workbooks, external workbook links, hidden sheets/rows/columns, protected question sheets, charts, pivots, drawings, embeddings, controls, signatures, and other OOXML parts that the writer may not preserve.
- Merged, formula, or data-validated answer/evidence target cells; ambiguous or missing answer/evidence columns; unacknowledged nonempty sheets; duplicate question IDs or XLSX ZIP members; known external workbook formulas. Preflight explains the reason and asks for a supported copy, explicit mapping or inspected-sheet acknowledgement. CryptoProof does not bypass protection or fix arbitrary customer templates.
- DOCX/PDF questionnaires, source-code scanning or upload, CBOM creation consulting, hosted processing, automatic legal/compliance certification, audit attestation, and complete questionnaire automation.
- Claims about all cryptography in a product or actual runtime deployment. A CBOM can be incomplete or inaccurate; the vendor must check its scope and the generated wording.
Preflight exposes question_count, ignored_sheets and acknowledged_ignored_sheets; compare them with the buyer's workbook. A nonempty unknown sheet stops compilation even if named Read me. An acknowledgement records that the vendor inspected a specific sheet content hash and found no questions; it is not an automatic proof. If the count is wrong, map the sheet or obtain a simpler workbook. High-confidence secret/path patterns cause a stop, but this is not a general DLP guarantee: visible free text, comments and existing answer cells still require vendor review.