Support starts here
Most of what people ask is answered on this page. What is not reaches a person — no account, no portal, no login. Your request carries a reference so both of us can find the thread, and you never have to look it up or quote it back at us.
Before you send us anything
Do not send your inventory, host names, configuration files, credentials or keys. We do not need any of it to help, and we ask for none of it. If you need to show us what happened, run the support bundle described below — it is built to strip the estate out and is tested on every release to prove that it does.
The fastest route to an answer
- Search the answers below. They are written from the cases that actually come up, not from a template.
- If it concerns a specific finding, reproduce it first. Every finding cites a certificate number that links to NIST. Opening that link settles a surprising share of questions in under a minute, because the record either says what we said it says or it does not.
- Still stuck? Open a request from this page. The form below collects the four things we would otherwise have to write back and ask for, which is usually the difference between an answer today and an answer on Thursday.
Answers
PowerShell refuses to run the collector — execution policy, AppLocker, or constrained language mode
This is a real limitation and we would rather say so than pretend otherwise. A hardened Windows estate can block the collectors outright, and the block is doing its job.
You do not need our collector. It is a convenience, not
the product. The assessment reads an inventory export you almost certainly
already produce — from ServiceNow, Intune, SCCM, Tanium, Jamf, or
rpm -qa and dpkg -l on Linux. Send that instead
and nothing is lost.
If you would rather make the collector run, open a request: the answer depends on which control is stopping it, and we would rather look than guess.
The tool says “this inventory cannot answer the question”
Almost always a source-level SBOM — a list of one application’s own libraries rather than the operating system underneath it. The cryptography that matters for a certificate-standing question lives in the OS packages, so a manifest of an app’s dependencies genuinely cannot answer it.
This is usually a five-minute fix rather than a problem: open a request saying what produced the file and we will tell you exactly what to send instead. The tool stopping is the tool working. It is built to refuse rather than return a clean-looking result that means nothing.
The report came back nearly empty
Two common causes. A Windows inventory taken from HKLM only misses per-user installations — the current collector handles both. Or a container image with no OS layer, which has the same shape of problem as the SBOM answer above.
Tell us what produced the export and we will identify which it is.
Every row says “unknown”
Usually an export the tool could not match, or components newer than the snapshot dated in your bundle. Open a request with your license reference and what produced the export, and we will tell you which it is.
What input formats do you accept?
CSV or TSV from any CMDB or spreadsheet — comma, semicolon, tab or pipe, detected automatically. CycloneDX JSON, SPDX 2.x JSON, and SPDX 3.x JSON-LD. Column headings do not have to match ours; we accept the headings real exports actually use.
If your export is not read correctly, that is our defect and not your problem. Send us the header row — the column names only, no data — and fixing it is included.
Your report says a module is not covered, but our vendor says they are FIPS validated
Both statements are often true at once, and the gap between them is the whole point of the report. A vendor saying “we are FIPS validated” and a certificate naming the exact version you run are different facts. The second is the one an assessor cites.
The question worth putting to them in writing is narrow: does an active certificate name the exact version we are running? Your report writes that letter for you, per vendor.
If you believe the finding is simply wrong, say so — see the next answer, because we treat that seriously.
I think a finding is wrong
Tell us, and we will reproduce it before replying. We do not answer “the tool is right” without checking, because occasionally it is not.
A defect that makes a report wrong is handled as a security defect here, not as a routine question: we fix it, re-issue your report at no charge, and tell you exactly what changed and why. There is no tier that buys you this faster — it is the first thing we do.
What does “a similar module exists” mean?
The vendor holds an active certificate whose name strictly contains, or is contained by, the one that is retiring. That cannot be settled from a name in either direction. “Kernel Mode Cryptographic Primitives Library” contains every word of “Cryptographic Primitives Library” and is a different module — while a renamed product looks identical.
So we do not decide it, and we will not guess for you on a call either. Ask the vendor which one covers you; the report drafts that question.
What does “nothing found at the snapshot date” mean?
Read it as a question, not a verdict. It means no successor certificate and no queue entry matched in a snapshot taken on a stated date. A certificate may have issued since, or been filed under a company name our matching did not join to the retiring one — corporate mergers make this genuinely hard.
It is not a finding about the vendor and we do not publish it as one. The honest action is to ask them in writing whether a submission exists for the product you own. That written answer is itself evidence, and worth more to an assessor than anything we could infer.
You found no validated cryptography at all. Is that a failed assessment?
No — it is a real finding, and frequently the most important one in the report. It means the question “which validated module protects this data” currently has no answer on that system, which is a present-tense gap rather than a future one.
It is not grounds for a refund, and our terms say so plainly rather than leaving it to be discovered later.
Can you just tell me whether we are compliant?
No, and be wary of anyone who says yes. That determination belongs to your assessor or contracting officer. We are not a C3PAO and do not want to be — an organization that assessed you could not also sell you the preparation.
What we produce is evidence you bring to that conversation, early enough to act on. Who decides what sets out the boundary in full.
Can I run it on more machines?
On a twelve-month license, yes — your whole estate, unlimited runs, as often as you like. Nothing expires, phones home, or counts you.
The $100 trial covers one machine and one report. If you have already run it and want the rest, the $100 comes off the $5,000.
The tool says my license file is not readable as issued
The license carries a signature, and the tool declines to act on one it cannot verify rather than guessing. Usually the file was edited, re-saved by something that rewrote it, or copied incompletely.
Open a request with your license reference — the line at the top of the file — and we will re-issue it. Reformatting alone does not break it: indentation and key order are handled deliberately, so an editor that tidies JSON on save will not lock you out.
What is your refund policy?
If we cannot produce a report at all from what you send, you get your money back. That one is not a judgment call.
The trial is refundable on request within thirty days, without argument.
A finding you dislike is not a refund — including “no validated cryptography found”, which is a real result. Anything else, talk to us; we look at those individually and settle quickly.
I want to report a security vulnerability
Not this page. Email security@agilicrypt.com and see our security policy for the acknowledgement and response windows.
What support covers
The line that matters is not how big your estate is. It is whether the question is “does this work” or “what should we do about it”.
| Question | Included |
|---|---|
| Getting the tool running, on any supported platform | Unlimited |
| An export format we read incorrectly, or do not read at all | Unlimited |
| A finding you believe is wrong | Unlimited |
| What a term, label or column in your report means | Unlimited |
| Interpreting your findings for a specific assessment | Advisory |
| Drafting POA&M wording for your situation | Advisory |
| Joining a call with your assessor or contracting officer | Advisory |
| Reviewing vendor replies and advising what to do next | Advisory |
Why the line sits there. Everything on the first list is either our defect or our documentation being unclear, and charging you to work around our own gaps would be indefensible. Everything on the second is real consulting work on your specific contract position, and it is unbounded by nature — pricing it honestly is better for both of us than pretending it fits inside a license fee. How advisory works, and what it costs.
Response times
| Included | Premium — $1,000/year | |
|---|---|---|
| The tool will not run, or cannot produce a report | Same working day, if it reaches us before noon | Same working day, if it reaches us before noon |
| A finding you believe is wrong | Same working day, if it reaches us before noon | Same working day, if it reaches us before noon |
| Everything else | Within two working days | Next working day |
| Who answers | Us — there is no tier-one queue to get past | A named person who has seen your estate before |
| A new profile for your export format | Included, in the next release | Included, ahead of the queue |
| A working session on your findings | By arrangement, when we can | Scheduled within five working days, twice a year |
Requests are answered during business hours. Working days are Monday to Friday, US Eastern, excluding US federal holidays; noon means 12:00 Eastern. These are target times to a first response, not to a fix, and we use reasonable efforts to meet them. We set them at what we expect to hit rather than what would look best here. In practice most replies are faster, and we would rather beat a stated time than explain a missed one.
Phone: (814) 737-0555, for every paying customer, trial included — Monday to Friday, US Eastern business hours, excluding US federal holidays. We do not offer 24×7 cover. If your contract requires round-the-clock support, tell us before you buy — that is a fair reason to choose something else, and we would rather say so now than take your money and disappoint you.
Note what is not on the Premium list: the two things that matter most are the same on both. A tool that will not run and a finding that may be wrong are treated as urgent for every customer, because they are our problem rather than yours. Premium buys attention on everything else, and a person who already knows your estate.
Premium runs alongside a twelve-month license and for the same term. It does not renew by itself, any more than the license does.
Already partway through your twelve months? Email us rather than using that button and we will invoice the remaining months pro-rata. The button charges a full year whenever it is clicked, which is the wrong answer if you have four months left.
Most estates should not buy this. If your export reads cleanly and your findings make sense, the included support is the whole of what you need and we would rather tell you that than take $1,000. It earns its price when you are working to an assessment date, or when your inventory comes out of something unusual and you would rather have a named person than a queue.
Open a request
Requests start here rather than in an inbox, because the four things below are what we would otherwise write back and ask for. Filling them in usually saves a full day.
Have these ready
- Your license reference — the line at the top of
LICENCE.json. Not needed if you have not bought yet. - What you were doing, and what happened instead.
- What produced your inventory — the tool or system, not the file.
- The support bundle, if the tool ran at all. On
Windows:
collectors\collect-support.ps1. It records what happened without recording your estate: no machine names, no account names, no file paths, no package names. Read it before you send it — it is plain text, and we would rather you did.
Your reference is . It goes into the subject line for you. Keep it if you like — you will never be asked to quote it, and we can always find your thread by your email address alone.
That button opens your own mail client with the headings filled in. Nothing on this page is sent anywhere, and this site sets no cookies and runs no analytics — see our privacy policy. Prefer to write it yourself? support@agilicrypt.com reaches the same place, and a request without a reference is not treated any differently.