System or domain
Name the public endpoint, API, application, VPN, identity service or signing workflow.
The CSV is intentionally simple enough to start today, but structured enough to become a migration backlog as supplier evidence and internal discovery improve.
Name the public endpoint, API, application, VPN, identity service or signing workflow.
Record the business owner, technical owner and supplier contact where relevant.
Separate TLS, mTLS, VPN, signing, key exchange, identity tokens, SSH and data-at-rest controls.
Capture RSA, ECDH, ECDSA, DH, DSA, curve, key size, certificate chain or library evidence.
Prioritise traffic, signatures or records that need confidentiality or authenticity for years.
Show whether a CDN, cloud, identity, HSM, SaaS or managed-service provider controls the dependency.
Track unknown, assessed, pilot-ready, blocked, planned, migrated or not applicable.
Assign the next evidence request, scan, supplier question, pilot or migration owner.
Create a free account if you want the inventory template to start with a saved, repeatable public scan. Add a domain during signup and the scanner opens directly.
The direct CSV remains free, but the account gives the spreadsheet an evidence URL and gives you a reason to return after TLS, CDN or provider changes.
Yes. You can download the CSV template directly. A free account is useful when you want to save the first public scan evidence and rerun it after changes.
No. It is a practical starting structure. Automated discovery tools, supplier evidence and internal review are still needed for a complete estate inventory.
Start with a public customer-facing website or API because it is easy to scan, easy to rescan and often exposes TLS, CDN and supplier decisions.
The account keeps a repeatable scan record tied to an email, so the spreadsheet row can point to evidence instead of becoming an unsupported assertion.