Generated by Codex with GPT 5.6 Sol High
Cryptographic migrations begin with an inventory problem: organizations must find not just algorithm names, but the runtime purpose, dependencies, and upgrade path of each use. A text search for RSA may count dead tests while missing a TLS default selected in another repository. Cloudflare built CryptoLabe to turn that ambiguous code archaeology into structured migration work, using agents to trace evidence across source, configuration, documentation, and internal systems.
The official Cloudflare Blog published “Using AI to chart a course for our post-quantum migration” on September 29, 2026. The post describes an internal system for mapping classical and post-quantum cryptography across Cloudflare’s repositories before a company-wide 2029 migration deadline. Its most useful contribution is not a claim that an agent can replace security review. It is an architecture for producing reviewable evidence at scale while explicitly representing uncertainty and ecosystem blockers.
Search for behavior, not strings
The core difficulty is that the same primitive can demand different migrations depending on context. An ECDSA signature might authenticate a JWT, a TLS connection, an IPsec tunnel, or an SSH session. Some cryptography is selected by configuration or a dependency’s default rather than by code in the repository being scanned. Other matches are unused, test-only, or already scheduled for removal. A useful inventory therefore has to answer how an operation participates in a running system, not merely whether a symbol appears in a file.
CryptoLabe splits that analysis into two stages. Discovery first maps a repository and searches source files, manifests, lockfiles, scripts, tests, documentation, and configuration for raw observations about key agreement, signatures, public-key infrastructure, tokens, credentials, and hardware security modules. Deep analysis then rechecks each observation against the code, investigates runtime behavior and dependencies, consults related repositories when necessary, and searches its own conclusion for conflicting evidence such as overrides or test-only paths.
The result is classified as classical encryption, classical signature, classical token, post-quantum-ready hybrid key exchange, or another post-quantum-ready use. When evidence is insufficient, the system can say “more evidence needed,” “external dependency,” or “unknown” instead of inventing certainty. That design choice matters because a security inventory is dangerous when a polished answer conceals missing context. The output must support both program-level migration metrics and the repository owner who will validate and act on a finding.
Isolate the agent and make the workflow durable
CryptoLabe separates the scanning path from the inventory interface. A scanner Worker runs analyses, while an inventory Worker serves the dashboard and API and stores results in D1. Service Bindings connect the two. Each repository receives a persistent coordinator backed by a Durable Object, with a bounded queue limiting concurrent scans. The coordinator handles progress, cancellation, retry, and recovery, while Cloudflare Workflows persist the four processing stages: discovery, deep analysis, merging duplicate findings, and publishing results.
The agent never works against a mutable checkout. At the beginning of a scan, CryptoLabe downloads one exact commit and stores the snapshot in R2. Each analysis restores that snapshot into a fresh short-lived Cloudflare Sandbox, where the model receives a small set of read-only tools. This provides repeatability and contains mistakes: the evidence cannot shift midway through a run, and an analysis task cannot alter the repository it is inspecting.
Scale introduced a separate distributed-systems problem. Many repositories produced bursts of model calls, HTTP 429 responses, and independent retries that amplified the overload. Cloudflare added one global Durable Object to pace requests across every scan. When a rate limit occurs, all scans share the cooldown instead of competing through retry storms. Model requests pass through AI Gateway to open-weight models on Workers AI, which keeps model choice replaceable and exposes costs. The lesson is that an agent fleet needs centralized capacity control even when its units of work are otherwise isolated.
Turn findings into a dependency map
Finding classical cryptography does not mean one product team can replace it immediately. A post-quantum JWT migration may be blocked by a token issuer or a validation library; another protocol may lack an agreed standard. CryptoLabe groups findings by these prerequisites so the migration program can distinguish local engineering work from shared ecosystem dependencies.
Cloudflare also runs a broader, simpler prompt for “hard cases”: custom protocols, keys embedded in size-constrained fields, hardware-bound cryptography, specialized constructions, or integrations with parties that lack post-quantum support. Running that prompt across repositories with ticketing and documentation context worked better than asking each repository scan to find every anomaly. One example was a certificate transported in an HTTP header, where larger post-quantum signatures could violate assumptions in the application or an intermediary. The system still cannot decide whether that path matters long term; an owner must measure the limits and determine whether the code should survive.
That limitation is central to the design. Cloudflare says it does not yet have a ground-truth corpus for reproducibly comparing prompt versions and does not claim complete coverage. It improves prompts by reviewing findings with repository owners, investigating misses, and rerunning the process. Different scans expose different classes of evidence, and every result remains subject to human validation.
The broader engineering takeaway is to use agents as evidence-building infrastructure rather than as autonomous migration authorities. Freeze the input, constrain the tools, persist every stage, coordinate shared capacity, preserve unknowns, and route findings to the people who understand the system. An exhaustive inventory is not required before action: teams can prioritize critical systems, validate their cryptographic dependencies, apply compensating controls, and resolve shared blockers in impact order. CryptoLabe makes that work measurable without pretending that code search alone can explain a production security boundary.