A separate measurement track

A protocol for comparable product tests

The capability index reads public product evidence. A hands-on benchmark requires every included product to be tested against the same independently labeled cases before any comparative performance claim is made.

What QScout's public artifacts show

These vendor-hosted artifact responses were fetched on 30 September 2026. Counts below were recomputed from the fetched bytes. The dated input manifest preserves exact vendor responses, original URLs and SHA-256 digests. They are not a common-product test, a fresh detector run or independent verification of the deployed source build.

Dated QScout vendor evidence and its boundaries
ArtifactWhat the public bytes showWhat remains unproved
Signed CBOM sample · verification record · public key
Archived inputs: sample · verification · key
A 13-component CycloneDX 1.7 sample for Qtonic Quantum Corp's own API. Its ML-DSA-65 signature verifies under the published key, and a one-byte change fails verification.It is not an inventory from a customer-estate scan or a peer comparison.
Accuracy corpus · metrics
Archived inputs: corpus · metrics
The 15 August 2026 corpus has 1,368 cases: 550 true positives, 171 false negatives, 647 true negatives and zero false positives under its labels. It covers only TLS surface and certificate expiry; labels were partly shaped by the detector and lacked independent dual annotation.The vendor labels the resulting precision a construction artifact, not a field precision result. The 171 constructed-corpus disagreements are not a current production miss rate.
Pulse change export
Archived inputs: changes · scope summary
The fetched 500 events span about 44.7 days on Qtonic Quantum Corp's own estate. Their prior-state fields are null, and the record includes dogfood ticks.This does not demonstrate third-party estate coverage, real-time discovery or per-asset cryptographic diffs.
Remediation harness · workflow
Archived inputs: harness · workflow
The public sequence is a recorded fixture with live_tenant=false; outbound connectors are dry-run in the published evidence.It does not establish a completed live ticket, verified customer rescan or algorithm transition.

What the dated public-evidence scores say

These are all 14 assessed products and their published C1 discovery and C6 remediation-loop cells from edition 2026.7, scored on public evidence on 26 September 2026. They are documentation and artifact assessments, not measured side-by-side detection or transition outcomes. The full seven-cell matrix and each product's archived sources remain available.

QScout does not have the highest C1 or C6 score in this rubric. The table covers every assessed product; higher public-evidence cells do not establish which product would find more real assets or complete a safer migration in a common environment.

Remediation is narrower than crypto agility

C6 asks whether a finding can move through ownership, action and verified closure. NIST CSWP 39-upd1 describes crypto agility more broadly: adapting or replacing algorithms across protocols, applications, software, hardware, firmware and infrastructure while keeping systems secure and operating. This edition did not execute cross-product algorithm transitions, compatibility checks or rollback tests.

Protocol before results

The first comparable outcome is a complete, attributable audit workflow: native discovery → asset-linked finding → scan-bound export → assigned action → controlled change → rescan-confirmed closure → reopen on regression. Planning, harness-supplied state and product actuation are recorded separately. No peer product has completed this common protocol in this publication.

  1. Freeze and publish corpus construction, exclusions, labels, source hashes, product builds and a versioned manifest before scoring products. Record license, configuration, unsupported inputs and failed runs for every participant.
  2. Include independently labeled positive and negative cases across code, dependencies, binaries, certificates, TLS and SSH services, cloud key stores and configuration where products claim coverage. Count true and false positives and negatives by surface; publish recall, precision and denominators rather than a single headline percentage.
  3. Generate an inventory from a real scan of the same fixtures. Trace each finding to an asset and observation time; export it, verify its schema and cryptographic integrity independently, and show that a one-bit edit fails verification. Keep a vendor-signed sample for the vendor's own API distinct from a customer-estate scan.
  4. Inject a known addition, removal and downgrade. Measure observation-to-report latency, diff completeness and attribution, then check that the evidence history detects edited bytes. Do not substitute write-pipeline latency for discovery latency.
  5. In an approved lab tenant, create and assign a remediation task, change the affected policy or algorithm, verify closure by rescan, reopen on regression and exercise an idempotent retry. A mock connector or dry run is recorded as such.
  6. Transition a named client/server pair from classical to hybrid to post-quantum cryptography. Record negotiated algorithms, compatibility, downtime, downgrade refusal and a safe rollback, using the same pass conditions for each accessible product.
  7. Release raw machine-readable outcomes, evaluator code and uncertainty intervals after sensitive-data checks. Re-run material disputes under the same corpus version and log changes.

A product that has not completed this protocol is not tested, not last. Company size, sales, funding and market reach have no benchmark weight.

Challenge the protocol or a result

Submit a reproducible case, a label correction or an output-matching dispute through the public challenge process. The editor will publish the disposition, including changes that lower QScout's position.