Support starts here

Most of what people ask is answered on this page. What is not reaches a person — no account, no portal, no login. Your request carries a reference so both of us can find the thread, and you never have to look it up or quote it back at us.

Before you send us anything

Do not send your inventory, host names, configuration files, credentials or keys. We do not need any of it to help, and we ask for none of it. If you need to show us what happened, run the support bundle described below — it is built to strip the estate out and is tested on every release to prove that it does.

The fastest route to an answer

  1. Search the answers below. They are written from the cases that actually come up, not from a template.
  2. If it concerns a specific finding, reproduce it first. Every finding cites a certificate number that links to NIST. Opening that link settles a surprising share of questions in under a minute, because the record either says what we said it says or it does not.
  3. Still stuck? Open a request from this page. The form below collects the four things we would otherwise have to write back and ask for, which is usually the difference between an answer today and an answer on Thursday.

Answers

Running the tool
PowerShell refuses to run the collector — execution policy, AppLocker, or constrained language mode

This is a real limitation and we would rather say so than pretend otherwise. A hardened Windows estate can block the collectors outright, and the block is doing its job.

You do not need our collector. It is a convenience, not the product. The assessment reads an inventory export you almost certainly already produce — from ServiceNow, Intune, SCCM, Tanium, Jamf, or rpm -qa and dpkg -l on Linux. Send that instead and nothing is lost.

If you would rather make the collector run, open a request: the answer depends on which control is stopping it, and we would rather look than guess.

The tool says “this inventory cannot answer the question”

Almost always a source-level SBOM — a list of one application’s own libraries rather than the operating system underneath it. The cryptography that matters for a certificate-standing question lives in the OS packages, so a manifest of an app’s dependencies genuinely cannot answer it.

This is usually a five-minute fix rather than a problem: open a request saying what produced the file and we will tell you exactly what to send instead. The tool stopping is the tool working. It is built to refuse rather than return a clean-looking result that means nothing.

The report came back nearly empty

Two common causes. A Windows inventory taken from HKLM only misses per-user installations — the current collector handles both. Or a container image with no OS layer, which has the same shape of problem as the SBOM answer above.

Tell us what produced the export and we will identify which it is.

Every row says “unknown”

Usually an export the tool could not match, or components newer than the snapshot dated in your bundle. Open a request with your license reference and what produced the export, and we will tell you which it is.

What input formats do you accept?

CSV or TSV from any CMDB or spreadsheet — comma, semicolon, tab or pipe, detected automatically. CycloneDX JSON, SPDX 2.x JSON, and SPDX 3.x JSON-LD. Column headings do not have to match ours; we accept the headings real exports actually use.

If your export is not read correctly, that is our defect and not your problem. Send us the header row — the column names only, no data — and fixing it is included.

Reading your report
Your report says a module is not covered, but our vendor says they are FIPS validated

Both statements are often true at once, and the gap between them is the whole point of the report. A vendor saying “we are FIPS validated” and a certificate naming the exact version you run are different facts. The second is the one an assessor cites.

The question worth putting to them in writing is narrow: does an active certificate name the exact version we are running? Your report writes that letter for you, per vendor.

If you believe the finding is simply wrong, say so — see the next answer, because we treat that seriously.

I think a finding is wrong

Tell us, and we will reproduce it before replying. We do not answer “the tool is right” without checking, because occasionally it is not.

A defect that makes a report wrong is handled as a security defect here, not as a routine question: we fix it, re-issue your report at no charge, and tell you exactly what changed and why. There is no tier that buys you this faster — it is the first thing we do.

What does “a similar module exists” mean?

The vendor holds an active certificate whose name strictly contains, or is contained by, the one that is retiring. That cannot be settled from a name in either direction. “Kernel Mode Cryptographic Primitives Library” contains every word of “Cryptographic Primitives Library” and is a different module — while a renamed product looks identical.

So we do not decide it, and we will not guess for you on a call either. Ask the vendor which one covers you; the report drafts that question.

What does “nothing found at the snapshot date” mean?

Read it as a question, not a verdict. It means no successor certificate and no queue entry matched in a snapshot taken on a stated date. A certificate may have issued since, or been filed under a company name our matching did not join to the retiring one — corporate mergers make this genuinely hard.

It is not a finding about the vendor and we do not publish it as one. The honest action is to ask them in writing whether a submission exists for the product you own. That written answer is itself evidence, and worth more to an assessor than anything we could infer.

You found no validated cryptography at all. Is that a failed assessment?

No — it is a real finding, and frequently the most important one in the report. It means the question “which validated module protects this data” currently has no answer on that system, which is a present-tense gap rather than a future one.

It is not grounds for a refund, and our terms say so plainly rather than leaving it to be discovered later.

Can you just tell me whether we are compliant?

No, and be wary of anyone who says yes. That determination belongs to your assessor or contracting officer. We are not a C3PAO and do not want to be — an organization that assessed you could not also sell you the preparation.

What we produce is evidence you bring to that conversation, early enough to act on. Who decides what sets out the boundary in full.

License, billing and refunds
Can I run it on more machines?

On a twelve-month license, yes — your whole estate, unlimited runs, as often as you like. Nothing expires, phones home, or counts you.

The $100 trial covers one machine and one report. If you have already run it and want the rest, the $100 comes off the $5,000.

The tool says my license file is not readable as issued

The license carries a signature, and the tool declines to act on one it cannot verify rather than guessing. Usually the file was edited, re-saved by something that rewrote it, or copied incompletely.

Open a request with your license reference — the line at the top of the file — and we will re-issue it. Reformatting alone does not break it: indentation and key order are handled deliberately, so an editor that tidies JSON on save will not lock you out.

What is your refund policy?

If we cannot produce a report at all from what you send, you get your money back. That one is not a judgment call.

The trial is refundable on request within thirty days, without argument.

A finding you dislike is not a refund — including “no validated cryptography found”, which is a real result. Anything else, talk to us; we look at those individually and settle quickly.

I want to report a security vulnerability

Not this page. Email security@agilicrypt.com and see our security policy for the acknowledgement and response windows.

What support covers

The line that matters is not how big your estate is. It is whether the question is “does this work” or “what should we do about it”.

QuestionIncluded
Getting the tool running, on any supported platformUnlimited
An export format we read incorrectly, or do not read at allUnlimited
A finding you believe is wrongUnlimited
What a term, label or column in your report meansUnlimited
Interpreting your findings for a specific assessmentAdvisory
Drafting POA&M wording for your situationAdvisory
Joining a call with your assessor or contracting officerAdvisory
Reviewing vendor replies and advising what to do nextAdvisory

Why the line sits there. Everything on the first list is either our defect or our documentation being unclear, and charging you to work around our own gaps would be indefensible. Everything on the second is real consulting work on your specific contract position, and it is unbounded by nature — pricing it honestly is better for both of us than pretending it fits inside a license fee. How advisory works, and what it costs.

Response times

IncludedPremium — $1,000/year
The tool will not run, or cannot produce a reportSame working day, if it reaches us before noonSame working day, if it reaches us before noon
A finding you believe is wrongSame working day, if it reaches us before noonSame working day, if it reaches us before noon
Everything elseWithin two working daysNext working day
Who answersUs — there is no tier-one queue to get pastA named person who has seen your estate before
A new profile for your export formatIncluded, in the next releaseIncluded, ahead of the queue
A working session on your findingsBy arrangement, when we canScheduled within five working days, twice a year

Requests are answered during business hours. Working days are Monday to Friday, US Eastern, excluding US federal holidays; noon means 12:00 Eastern. These are target times to a first response, not to a fix, and we use reasonable efforts to meet them. We set them at what we expect to hit rather than what would look best here. In practice most replies are faster, and we would rather beat a stated time than explain a missed one.

Phone: (814) 737-0555, for every paying customer, trial included — Monday to Friday, US Eastern business hours, excluding US federal holidays. We do not offer 24×7 cover. If your contract requires round-the-clock support, tell us before you buy — that is a fair reason to choose something else, and we would rather say so now than take your money and disappoint you.

Note what is not on the Premium list: the two things that matter most are the same on both. A tool that will not run and a finding that may be wrong are treated as urgent for every customer, because they are our problem rather than yours. Premium buys attention on everything else, and a person who already knows your estate.

Premium runs alongside a twelve-month license and for the same term. It does not renew by itself, any more than the license does.

Add premium support — $1,000

Already partway through your twelve months? Email us rather than using that button and we will invoice the remaining months pro-rata. The button charges a full year whenever it is clicked, which is the wrong answer if you have four months left.

Most estates should not buy this. If your export reads cleanly and your findings make sense, the included support is the whole of what you need and we would rather tell you that than take $1,000. It earns its price when you are working to an assessment date, or when your inventory comes out of something unusual and you would rather have a named person than a queue.

Open a request

Requests start here rather than in an inbox, because the four things below are what we would otherwise write back and ask for. Filling them in usually saves a full day.

Have these ready

Open a support request What we can and cannot answer

That button opens your own mail client with the headings filled in. Nothing on this page is sent anywhere, and this site sets no cookies and runs no analytics — see our privacy policy. Prefer to write it yourself? support@agilicrypt.com reaches the same place, and a request without a reference is not treated any differently.