<?xml version="1.0" encoding="UTF-8"?>
<!-- Korthex - Deutsche Sitemap (korthex.de). Generiert - siehe scripts, die public/sitemap.xml pflegen; diese Datei folgt demselben Schema fuer die uebersetzte Teilmenge der Routen. -->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:xhtml="http://www.w3.org/1999/xhtml"
        xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">

  <url>
    <loc>https://korthex.de/</loc>
    <lastmod>2026-06-21T00:00:00+00:00</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/" />
    <image:image>
      <image:loc>https://korthex.de/og/de/home.jpg</image:loc>
      <image:title>Korthex - Kryptografie-Scanner mit Post-Quanten-Migration, von Flowence</image:title>
      <image:caption>Korthex ist der On-Premise-Kryptografie-Scanner von Flowence. Er analysiert Quellcode, Abhängigkeiten, Binärdateien, TLS-Zertifikate, Datenbanken und die Git-Historie auf schwache, gebrochene, veraltete und quantenanfällige Kryptografie - MD5, SHA-1, RC4, DES, 3DES, Blowfish, AES-CBC-Missbrauch, RSA, ECC, DH, hartkodierte Schlüssel und Secrets. Erstellt eine Cryptographic Bill of Materials (CBOM) und einen konkreten Migrationspfad zu NIST FIPS 140-3 / FIPS 203 / 204 / 205, BSI IT-Grundschutz, PCI-DSS und ISO 27001. 18 Sprachen. Ergebnisse in unter 2 Minuten.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/license</loc>
    <lastmod>2026-05-26T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/license" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/license" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/license" />
    <image:image>
      <image:loc>https://korthex.de/og/de/license.jpg</image:loc>
      <image:title>Preise und Lizenz - Korthex</image:title>
      <image:caption>Korthex-Tarife: Free (10 Scans/Monat), Extended (599 €/Jahr), Business (5.999 €/Jahr), Enterprise (49.999 €/Jahr). Alle Tarife laufen zu 100 % On-Premise - Quellcode verlässt niemals Ihre Infrastruktur.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/beta</loc>
    <lastmod>2026-08-01T00:00:00+00:00</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.5</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/beta" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/beta" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/beta" />
    <image:image>
      <image:loc>https://korthex.de/og/de/beta.jpg</image:loc>
      <image:title>Korthex Beta-Programm - Korthex</image:title>
      <image:caption>Korthex ist derzeit als öffentliche Beta für kryptografische Sicherheitsanalyse, Inventarverwaltung und Migrationsplanung verfügbar. Aktueller Beta-Umfang, Entwicklungs-Roadmap und Teilnahmebedingungen.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/changelog</loc>
    <lastmod>2026-07-29T00:00:00+00:00</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/changelog" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/changelog" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/changelog" />
    <image:image>
      <image:loc>https://korthex.de/og/de/changelog.jpg</image:loc>
      <image:title>Änderungsprotokoll - Korthex Entwicklungs-Build-Notizen</image:title>
      <image:caption>Das Korthex-Entwicklungs-Änderungsprotokoll: was in jedem Pre-Release-Build gelandet ist, neueste zuerst, über die Scanner-Engines, CBOM- und Migrationsausgabe, Compliance-Autoritätsabdeckung, das SDK und die CI/CD-Integration sowie die Dokumentation.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/terms</loc>
    <lastmod>2026-08-03T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/terms" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/terms" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/terms" />
    <image:image>
      <image:loc>https://korthex.de/og/de/terms.jpg</image:loc>
      <image:title>Nutzungsbedingungen - Korthex</image:title>
      <image:caption>Die Nutzungsbedingungen für Korthex, den On-Premise-Kryptografie-Scanner von Flowence.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/privacy</loc>
    <lastmod>2026-08-03T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/privacy" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/privacy" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/privacy" />
    <image:image>
      <image:loc>https://korthex.de/og/de/privacy.jpg</image:loc>
      <image:title>Datenschutzerklärung - Korthex</image:title>
      <image:caption>Die Korthex-Datenschutzerklärung erläutert, was erfasst wird, was niemals erfasst wird, und wie der On-Premise-Scanner Quellcode innerhalb Ihrer Infrastruktur hält.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/imprint</loc>
    <lastmod>2026-08-03T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.2</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/imprint" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/imprint" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/imprint" />
    <image:image>
      <image:loc>https://korthex.de/og/de/imprint.jpg</image:loc>
      <image:title>Impressum - Korthex von Flowence</image:title>
      <image:caption>Impressum für Korthex, ein Produkt von Flowence.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/sla</loc>
    <lastmod>2026-06-28T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/sla" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/sla" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/sla" />
    <image:image>
      <image:loc>https://korthex.de/og/de/sla.jpg</image:loc>
      <image:title>Service Level Agreement - Korthex</image:title>
      <image:caption>Das Korthex Service Level Agreement definiert Support-Stufen, Reaktionszeiten und Verfügbarkeitszusagen je Tarif.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/links</loc>
    <lastmod>2026-05-26T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.4</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/links" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/links" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/links" />
    <image:image>
      <image:loc>https://korthex.de/og/de/links.jpg</image:loc>
      <image:title>Weiterführende Links - Korthex</image:title>
      <image:caption>Kuratierte Ressourcen rund um Korthex und kryptografische Migration: Standarddokumente, Tools und weiterführende Literatur.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/cbom-generator</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/cbom-generator" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/cbom-generator" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/cbom-generator" />
    <image:image>
      <image:loc>https://korthex.de/og/de/cbom-generator.jpg</image:loc>
      <image:title>Generator für die Kryptografische Stückliste (CBOM)</image:title>
      <image:caption>Erstellen Sie mit Korthex eine kryptografische Stückliste (CBOM): jeder Algorithmus, Schlüssel, jedes Zertifikat und Protokoll in Ihrem Stack mit Datei:Zeile-Nachweis, Taint-Verdikt, PQC-Bereitschaft und Compliance-Zuordnung zu NIST FIPS 140-3, BSI, PCI-DSS und ISO 27001. Export als CycloneDX, SARIF, JSON, PDF. 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/crypto-agility</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/crypto-agility" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/crypto-agility" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/crypto-agility" />
    <image:image>
      <image:loc>https://korthex.de/og/de/crypto-agility.jpg</image:loc>
      <image:title>Crypto-Agility-Tool</image:title>
      <image:caption>Crypto Agility ist die Fähigkeit, kryptografische Algorithmen auszutauschen, ohne den Produktivbetrieb zu gefährden. Korthex macht das operativ nutzbar: ein laufend aktuelles kryptografisches Inventar (CBOM), Scoring von Schwachstellen und Quantenexposition, ein nach Abhängigkeiten geordneter Migrationsplan mit Auswirkungssimulation sowie ein CI/CD-Gate, das das Inventar aktuell hält. 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/crypto-vulnerability-scanner</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/crypto-vulnerability-scanner" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/crypto-vulnerability-scanner" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/crypto-vulnerability-scanner" />
    <image:image>
      <image:loc>https://korthex.de/og/de/crypto-vulnerability-scanner.jpg</image:loc>
      <image:title>Kryptografie-Schwachstellenscanner CLI</image:title>
      <image:caption>Korthex ist ein Crypto Vulnerability Scanner mit CLI-first-Workflow: Ein einziger Befehl durchsucht Quellcode, Abhängigkeiten, Binärdateien, TLS und Datenbanken nach schwacher, gebrochener und quantenverwundbarer Kryptografie, liefert einen gate-fähigen Exit-Code und exportiert ein CBOM. Unter zwei Minuten für 500.000 Zeilen, 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/pqc-scanner</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/pqc-scanner" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/pqc-scanner" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/pqc-scanner" />
    <image:image>
      <image:loc>https://korthex.de/og/de/pqc-scanner.jpg</image:loc>
      <image:title>Post-Quanten-Kryptografie-Scanner</image:title>
      <image:caption>Korthex ist ein On-Premise-Scanner für Post-Quanten-Kryptografie. Er findet quantenverwundbare RSA-, ECC-, Diffie-Hellman- und DSA-Implementierungen in Quellcode, Binärdateien, TLS-Zertifikaten und der Git-Historie, ordnet jeden Fund einer PQC-Bereitschaftskategorie zu und erstellt einen Migrationsplan zu ML-KEM (NIST FIPS 203), ML-DSA (FIPS 204) und SLH-DSA (FIPS 205).</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.85</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance.jpg</image:loc>
      <image:title>Anerkannte Behörden &amp; Frameworks</image:title>
      <image:caption>Korthex bewertet jeden kryptografischen Befund anhand kuratierter Baseline-Kanäle der anerkannten Behörden NIST, BSI, ANSSI, CISA, IETF und OWASP – ergänzt um länderspezifische Overlays für EU-Zahlungsverkehr, Deutschland, Frankreich, das Vereinigte Königreich, Australien und Kanada. Signierte 24-Stunden-Updates, Framework-Tags je Befund, auditfeste Nachweise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/anssi</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/anssi" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/anssi" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/anssi" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-anssi.jpg</image:loc>
      <image:title>ANSSI-Kryptografie-Compliance (RGS B1)</image:title>
      <image:caption>Der ANSSI-Baseline-Kanal von Korthex bewertet Befunde anhand von RGS Annexe B1 v2.0, dem kryptografischen Referenzdokument der französischen nationalen Cybersicherheitsbehörde: 9 Regeln, getaggt gegen ANSSI-RGS-B und NIS2. Das Frankreich-Overlay erweitert den Geltungsbereich um kritische Infrastrukturen (OIV). Signierte 24-Stunden-Updates.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/bsi</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/bsi" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/bsi" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/bsi" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-bsi.jpg</image:loc>
      <image:title>BSI-Kryptografie-Compliance (TR-02102)</image:title>
      <image:caption>Der BSI-Baseline-Kanal von Korthex bewertet Befunde anhand von BSI TR-02102-1: 16 Regeln zu Mindest-Schlüssellängen (RSA 3000 Bit, ECC 250 Bit), Anforderungen an Hash- und AEAD-Verfahren sowie Empfehlungen zu quantensicheren Hybridverfahren, getaggt gegen BSI TR-02102 und NIS2. Signierte 24-Stunden-Updates, air-gapped-fähig.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/cisa</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/cisa" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/cisa" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/cisa" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-cisa.jpg</image:loc>
      <image:title>CISA-Direktiven &amp; Post-Quanten-Initiative</image:title>
      <image:caption>Der CISA-Baseline-Kanal von Korthex bewertet Befunde anhand der Post-Quantum Cryptography Initiative der CISA und der Binding Operational Directive 18-01: 7 Regeln zur Entfernung schwacher Protokolle (RC4, 3DES, veraltetes SSL/TLS) und zur PQC-Readiness für US-Bundesbehörden, getaggt mit FIPS 140-3 und BOD 18-01.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/ietf</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/ietf" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/ietf" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/ietf" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-ietf.jpg</image:loc>
      <image:title>IETF-RFC-Deprecation-Track</image:title>
      <image:caption>Der IETF-Baseline-Kanal von Korthex verfolgt die RFC-Deprecation-Historie: RFC 8996 (TLS 1.0/1.1 abgekündigt), RFC 8429 (3DES und RC4 aus Kerberos entfernt), RFC 6151 (MD5) und RFC 6194 (SHA-1). 11 Regeln, die Befunde an dem messen, was die Standardisierungsorganisation des Internets selbst ausgemustert hat.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/nist</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/nist" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/nist" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/nist" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-nist.jpg</image:loc>
      <image:title>NIST-Kryptografie-Compliance</image:title>
      <image:caption>Der NIST-Baseline-Kanal von Korthex bewertet Befunde anhand von SP 800-131A Rev. 2, FIPS 180-4 und FIPS 197: 24 Regeln zu nicht mehr zulässigem 3DES, verbotenen SHA-1-Signaturen, Mindest-Schlüssellängen für RSA sowie den Post-Quanten-Nachfolgern FIPS 203 / 204 / 205 gemäß den Zeitplänen aus NIST IR 8547. Höchstpriorisierte Quelle, signierte 24-Stunden-Updates.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/owasp</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/owasp" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/owasp" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/owasp" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-owasp.jpg</image:loc>
      <image:title>OWASP-ASVS-Kryptografie-Verifizierung</image:title>
      <image:caption>Der OWASP-Kanal von Korthex ist eine Live-Baseline-Quelle: Er bezieht ASVS v5.x im 24-Stunden-Zyklus direkt aus dem offiziellen OWASP-Repository und überführt die Kapitel V11 (Cryptography) und V12 (Secure Communication) in 33 Verifizierungsregeln. Befunde tragen den Tag OWASP-ASVS-V5 mit file:line-Nachweis.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/bsi-it-grundschutz</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/bsi-it-grundschutz" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/bsi-it-grundschutz" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/bsi-it-grundschutz" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-bsi-it-grundschutz.jpg</image:loc>
      <image:title>BSI IT-Grundschutz Krypto-Scanner</image:title>
      <image:caption>Korthex ordnet kryptografische Funde dem BSI IT-Grundschutz zu (Baustein CON.1, Kryptokonzept) sowie den Algorithmen- und Schlüssellängen-Empfehlungen der BSI TR-02102: schwache Primitiven, kurze Schlüssel, veraltetes TLS und quantenverwundbare Kryptografie, jeweils mit File:Line-Nachweis. 100 % On-Premise und air-gap-fähig.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/fips-140-3</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/fips-140-3" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/fips-140-3" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/fips-140-3" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-fips-140-3.jpg</image:loc>
      <image:title>NIST FIPS 140-3 Scanner</image:title>
      <image:caption>Korthex durchsucht Quellcode, Binärdateien, TLS-Verbindungen und Datenbanken nach Kryptografie, die NIST FIPS 140-3 nicht erfüllt: nicht zugelassene Algorithmen (MD5, SHA-1-Signaturen, DES, 3DES, RC4), schwache Schlüssellängen und riskante Modi – jeweils gegen die zugelassenen Algorithmenlisten abgeglichen, inklusive File:Line-Nachweis. 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/iso-27001</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/iso-27001" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/iso-27001" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/iso-27001" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-iso-27001.jpg</image:loc>
      <image:title>ISO 27001 Kryptografie-Audit-Tool</image:title>
      <image:caption>Korthex ist ein ISO-27001-Kryptografie-Audit-Tool: Es inventarisiert jede tatsächlich eingesetzte kryptografische Kontrolle in Code, TLS und Datenbanken, markiert schwache und unverwaltete Kryptografie und exportiert auditfertige Nachweise für Annex-A-Control 8.24 mit File:Line-Detail. 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/pci-dss</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/pci-dss" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/pci-dss" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/pci-dss" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-pci-dss.jpg</image:loc>
      <image:title>PCI-DSS Kryptografie-Scanner</image:title>
      <image:caption>Korthex findet Kryptografie, die PCI DSS 4.0 verletzt: schwaches Hashing gespeicherter Daten, veraltetes TLS auf Karteninhaberdaten-Flows, fest codierte Schlüssel und undokumentierte Cipher Suites. Erstellt das dokumentierte kryptografische Inventar, das Anforderung 12.3.3 verlangt, inklusive File:Line-Nachweis. 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/australia</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/australia" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/australia" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/australia" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-australia.jpg</image:loc>
      <image:title>Australien: ASD Information Security Manual</image:title>
      <image:caption>Das Korthex-Overlay für die Jurisdiktion Australien bewertet Kryptografie gegen das ASD Information Security Manual: 4 Regeln mit Fokus auf OFFICIAL-eingestufte Daten für australische Regierungsstellen und deren Zulieferer, getaggt ASD-ISM mit Datei:Zeile-Nachweis.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/canada</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/canada" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/canada" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/canada" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-canada.jpg</image:loc>
      <image:title>Kanada: CCCS ITSP.40.111</image:title>
      <image:caption>Das Korthex-Overlay für die Jurisdiktion Kanada bewertet Kryptografie gegen CCCS ITSP.40.111, die vom Canadian Centre for Cyber Security zugelassenen Algorithmen für UNCLASSIFIED- und PROTECTED-Informationen: 4 Regeln auf Basis der NIST-Baseline, getaggt ITSP-40.111.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/eu-cra</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/eu-cra" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/eu-cra" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/eu-cra" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-eu-cra.jpg</image:loc>
      <image:title>EU Cyber Resilience Act: Kryptografie-Bereitschaft</image:title>
      <image:caption>Wie Korthex die Vorbereitung auf den EU Cyber Resilience Act unterstützt: das kryptografische Inventar (CBOM) als Kryptografie-Baustein Ihrer CRA-technischen Dokumentation, NIS2-getaggte EU-Baselines als Maßstab für den Stand der Technik und ein CI-Gate, das die Nachweise aktuell hält. Die Hauptpflichten der CRA gelten ab Dezember 2027.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/eu-payments</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/eu-payments" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/eu-payments" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/eu-payments" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-eu-payments.jpg</image:loc>
      <image:title>Kryptografie im EU-Zahlungsverkehr (PSD2, DORA, PCI DSS)</image:title>
      <image:caption>Das Korthex-Overlay für die Jurisdiktion EU-Zahlungsverkehr ergänzt die Behörden-Baselines um Kryptografie-Regeln für Zahlungsinfrastrukturen: PSD2-, DORA- und PCI-DSS-4.0-Tags für EU-Zahlungsdienstleister und FinTechs, mit Datei:Zeile-Nachweis je Fund für Prüfer und Aufsichtsbehörden.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/france</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/france" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/france" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/france" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-france.jpg</image:loc>
      <image:title>Frankreich: ANSSI RGS und OIV-Geltungsbereich</image:title>
      <image:caption>Das Korthex-Overlay für die Jurisdiktion Frankreich ergänzt die ANSSI-RGS-B1-Baseline um den Geltungsbereich kritischer Infrastrukturen (OIV): 4 Jurisdiktionsregeln, getaggt ANSSI-RGS-B, für französische Verwaltungen, Betreiber wesentlicher Bedeutung (opérateurs d'importance vitale) und deren Zulieferer.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/germany</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/germany" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/germany" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/germany" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-germany.jpg</image:loc>
      <image:title>Deutschland: BSI, NIS2 und Grundschutz</image:title>
      <image:caption>Wie deutsche Organisationen Korthex einsetzen: der BSI-TR-02102-Kanal als Algorithmen-Baseline, NIS2-Tags für kritische Infrastrukturen und IT-Grundschutz-Nachweise (CON.1 Kryptokonzept) aus der CBOM. Entwickelt in Deutschland, 100% on-premise und air-gapped-fähig.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/compliance/united-kingdom</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/compliance/united-kingdom" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/compliance/united-kingdom" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/compliance/united-kingdom" />
    <image:image>
      <image:loc>https://korthex.de/og/de/compliance-united-kingdom.jpg</image:loc>
      <image:title>Vereinigtes Königreich: NCSC Foundation Profile</image:title>
      <image:caption>Das Korthex-Overlay für die Jurisdiktion Vereinigtes Königreich bewertet TLS und Kryptografie gegen das NCSC Foundation Profile: 4 Regeln für britische Unternehmen und Zulieferer des öffentlichen Sektors, aufgesetzt auf die Behörden-Baseline NIST.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/hardcoded-secrets-scanner</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/hardcoded-secrets-scanner" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/hardcoded-secrets-scanner" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/hardcoded-secrets-scanner" />
    <image:image>
      <image:loc>https://korthex.de/og/de/hardcoded-secrets-scanner.jpg</image:loc>
      <image:title>Hardcoded Keys and Secrets Scanner (SAST)</image:title>
      <image:caption>Korthex findet hardcodierte Keys, Credentials, API-Tokens und private Schlüssel in Quellcode, Konfiguration und der vollständigen Git-Historie – mit taint-klassifizierter Schlüsselherkunft und Dataflow-Analyse über 16 Import-Hops zur Reduktion von False Positives. SAST-artige Analyse, 18 Sprachen, 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/integrations/ci-cd</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/integrations/ci-cd" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/integrations/ci-cd" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/integrations/ci-cd" />
    <image:image>
      <image:loc>https://korthex.de/og/de/integrations-ci-cd.jpg</image:loc>
      <image:title>CI/CD Cryptography Scanning</image:title>
      <image:caption>Jede CI/CD-Pipeline auf kryptografische Findings gaten: Korthex liefert einen GitHub-Actions-Schritt, eine GitLab-CI-Vorlage, ein Jenkins-Snippet und einen generischen CLI-Exit-Code für Azure DevOps, CircleCI, Bitbucket, Drone und Buildkite. Konfigurierbarer Risiko-Schwellenwert, SARIF-Output, unter zwei Minuten pro Scan, 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/integrations/github-actions</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/integrations/github-actions" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/integrations/github-actions" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/integrations/github-actions" />
    <image:image>
      <image:loc>https://korthex.de/og/de/integrations-github-actions.jpg</image:loc>
      <image:title>Korthex GitHub Actions Integration</image:title>
      <image:caption>Korthex-Kryptografie-Scans in GitHub Actions ausführen: Ein Pipeline-Schritt scannt jeden Pull Request auf schwache, gebrochene und quantenanfällige Kryptografie, lässt den Build oberhalb eines konfigurierbaren Risiko-Schwellenwerts fehlschlagen und postet Findings inline via SARIF und GitHub Code Scanning. Funktioniert auf Self-Hosted-Runnern, vollständig On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/md5-sha1-scanner</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/md5-sha1-scanner" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/md5-sha1-scanner" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/md5-sha1-scanner" />
    <image:image>
      <image:loc>https://korthex.de/og/de/md5-sha1-scanner.jpg</image:loc>
      <image:title>MD5- und SHA-1-Scanner für Quellcode</image:title>
      <image:caption>Findet jede MD5- und SHA-1-Verwendung in Quellcode, Dependencies, Binärdateien, Zertifikaten und der Git-Historie. Korthex trennt sicherheitskritische Verwendung von unkritischen Prüfsummen mittels taint-basiertem Urteil, mappt Funde auf FIPS, BSI und PCI-DSS und plant die Migration zu SHA-256 / SHA-3. 18 Sprachen, 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/tls-certificate-audit</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/tls-certificate-audit" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/tls-certificate-audit" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/tls-certificate-audit" />
    <image:image>
      <image:loc>https://korthex.de/og/de/tls-certificate-audit.jpg</image:loc>
      <image:title>TLS Certificate Audit Tool, On-Premise</image:title>
      <image:caption>TLS-Zertifikate und Cipher Suites prüfen, ohne etwas an einen Cloud-Dienst zu senden: Korthex untersucht Zertifikate, Schlüssel und TLS-Konfigurationen in Repositories, Containern und interner Infrastruktur auf SHA-1-/MD5-Signaturen, RSA unter 2048 Bit, ECC unter 256 Bit, Ablauf und unsichere Konfiguration. Air-Gap-fähig.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/weak-cipher-detection</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/weak-cipher-detection" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/weak-cipher-detection" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/weak-cipher-detection" />
    <image:image>
      <image:loc>https://korthex.de/og/de/weak-cipher-detection.jpg</image:loc>
      <image:title>Weak Cipher Detection Tool</image:title>
      <image:caption>Korthex erkennt schwache und gebrochene Chiffren in 18 Sprachen, Binärdateien, TLS-Konfigurationen und Datenbanken: DES, 3DES (Sweet32), RC4, Blowfish, AES-ECB und CBC ohne Integritätsschutz – mit Dataflow-Analyse und NIST-KAT-Emulation als Nachweis statt reinem Pattern-Matching. 100 % On-Premise.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/vs-snyk</loc>
    <lastmod>2026-06-28T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/vs-snyk" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/vs-snyk" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/vs-snyk" />
    <image:image>
      <image:loc>https://korthex.de/og/de/vs-snyk.jpg</image:loc>
      <image:title>Korthex vs. Snyk - Kryptografie-spezialisiertes Scanning vs. generisches SAST</image:title>
      <image:caption>Snyk ist ein generischer SAST- und Dependency-Scanner für Schwachstellen in der Code-Logik. Korthex ist auf Kryptografie spezialisiert: Es inventarisiert jede kryptografische Primitive, bewertet die Post-Quanten-Exposition, erstellt eine CBOM und einen Migrationsplan und verifiziert schwache Kryptografie offensiv per Emulation. Der ehrliche Vergleich.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/vs-sonarqube</loc>
    <lastmod>2026-06-28T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/vs-sonarqube" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/vs-sonarqube" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/vs-sonarqube" />
    <image:image>
      <image:loc>https://korthex.de/og/de/vs-sonarqube.jpg</image:loc>
      <image:title>Korthex vs. SonarQube - Krypto-Inventar und PQC-Migration vs. Code-Qualitäts-SAST</image:title>
      <image:caption>SonarQube ist eine generische Plattform für Codequalität und SAST, die Bugs, Code Smells und sicherheitsrelevante Hotspots in der Code-Logik abdeckt. Korthex ist auf Kryptografie spezialisiert: Cross-Engine Attack-Paths, CBOM mit Post-Quanten-Bereitschaft, Migrationsplan und offensive Verifikation per Emulation. Der ehrliche Vergleich bei Kryptografie.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/vs-semgrep</loc>
    <lastmod>2026-06-28T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/vs-semgrep" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/vs-semgrep" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/vs-semgrep" />
    <image:image>
      <image:loc>https://korthex.de/og/de/vs-semgrep.jpg</image:loc>
      <image:title>Korthex vs. Semgrep - Kryptografische Erreichbarkeit vs. Pattern-Regeln</image:title>
      <image:caption>Semgrep ist ein schnelles, anpassbares, musterbasiertes SAST. Korthex ist auf Kryptografie spezialisiert: Es verfolgt Werte über Import-Hops hinweg, baut Cross-Engine Attack-Paths, exportiert eine CBOM mit Post-Quanten-Bereitschaft, erstellt einen Migrationsplan und beweist schwache Kryptografie per Emulation gegen NIST-KAT. Der ehrliche Vergleich bei Kryptografie.</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://korthex.de/vs-sandboxaq</loc>
    <lastmod>2026-07-10T00:00:00+00:00</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
    <xhtml:link rel="alternate" hreflang="en" href="https://korthex.io/vs-sandboxaq" />
    <xhtml:link rel="alternate" hreflang="de" href="https://korthex.de/vs-sandboxaq" />
    <xhtml:link rel="alternate" hreflang="x-default" href="https://korthex.io/vs-sandboxaq" />
    <image:image>
      <image:loc>https://korthex.de/og/de/vs-sandboxaq.jpg</image:loc>
      <image:title>Korthex vs. SandboxAQ AQtive Guard - Source-Level-Scanning vs. Runtime-Discovery</image:title>
      <image:caption>Korthex ist ein quellcodebasierter Krypto-Scanner: statische Analyse in 18 Sprachen mit Datei:Zeile-Nachweis, Beweisführung per NIST-KAT-Emulation und einem abhängigkeitsgeordneten Migrationsplan, vollständig on-premise, selbstbedient. AQtive Guard ist SandboxAQs Plattform für Kryptografie-Management im Unternehmen: Runtime-, Netzwerk- und Dateisystem-Discovery mit KI-gestützter Risikopriorisierung, vertriebsgeführt für Enterprise-Kunden. Der ehrliche, achsenweise Vergleich zweier unterschiedlicher Blickwinkel.</image:caption>
    </image:image>
  </url>

</urlset>
