C5 / 10.53% of index

Correctness

Is detection accuracy measured against named ground truth?

What is correctness?

Correctness measures whether the discovery system finds real cryptographic assets while controlling false negatives, false positives and partial matches.

An inventory can look comprehensive while silently missing assets. Named corpora, independent ground truth and reproducible evaluators make accuracy claims auditable.

Questions to ask a vendor

  1. What corpus was used?
  2. Who constructed and labeled the ground truth?
  3. Are precision, recall and partial-match rules published per detector?

What this edition actually supports

Weight 2 of 19. How many findings are right, and what did the scanner miss?

A useful accuracy study fixes a corpus and independently adjudicated labels before detection, then reports false positives and false negatives by surface. QScout scores 6 in edition 2026.7. Its published 1,368-case corpus is vendor labelled, with detector-shaped vocabulary and a precision construction artifact; it does not prove market-leading field accuracy. Missing peer metrics are unknown, not automatic product failure.

How to investigate this criterion

Look for a frozen denominator, label provenance, replayable cases and confidence intervals; compare peers on the same cases only.

The 2026.7 cells below are public-evidence scores. A vendor page documents a claim; an artifact check tests only its stated scope. Missing product execution and inaccessible sources remain explicit unknowns. The score snapshot has not been recomputed from later pages.

Correctness scores in edition 2026.7

Equal scores share the same criterion position; the next position skips the tied places. The highest value in this column is a published rubric cell, not a measured product winner. A partial or unverified source anchor remains visible even when its numeric score is high.

Position on criterionProductCorrectness scoreOverall scoreInternal 1 October source reviewEvidence
1QScout Pulse GoldQtonic Quantum Corp68.00Partial or qualified supportPublic corpus arithmetic recomputes but labels are partly detector-derived, legacy, and narrow; it is not an independently adjudicated product miss rate.Exact cell and citationsS27S28S29S30
2CBOM SecureEncryption Consulting47.47Partial or qualified supportVendor says false positives are eliminated but gives no method or precision/recall metric; anchor is only a documented claim.Exact cell and citationsS04S05S06
2Keyfactor AgileSec + CommandKeyfactor46.53Narrow feature documentedVendor records false-positive correction for secure key exchange, without published precision/recall.Exact cell and citationsS08S25
2QCecuring CBOMQCecuring46.53Partial or qualified supportParsing limitations describe potential misses, not a measured false-positive rate; score four remains a rubric judgment.Exact cell and citationsS19
2AppViewX Quantum Trust HubAppViewX46.37Claim not verified from accessible evidenceZero reflects no documented metric in a 403-constrained search, not evidence of no accuracy work.Exact cell and citationsS07S24
2SandboxAQ AQtive GuardSandboxAQ46.21Partial or qualified supportVendor says false positives reduced but provides no method or metric in cited source.Exact cell and citationsS12
2DigiCert Quantum CentralDigiCert45.37Narrow feature documentedVendor documents manual handling for false positives, without a published accuracy metric.Exact cell and citationsS18
8Fortanix Key Insight / PQC CentralFortanix05.74Claim not verified from accessible evidenceZero reflects no metric in bounded accessible docs, not an observed correctness result.Exact cell and citationsS15
8IBM Guardium + Quantum SafeIBM05.58Partial or qualified supportFinal zero correctly excludes a CBOMkit benchmark not tied to Guardium/Quantum Safe; absence of IBM-specific metric is bounded.Exact cell and citationsS09S10S26
8O3 SecurityO3 Security05.47Claim not verified from accessible evidenceZero is a bounded no-metric finding; docs portal access limits prevent complete correctness review.Exact cell and citationsS17
8ISARA AdvanceISARA05.42Claim not verified from accessible evidenceZero is a bounded lack of public accuracy metric; source marketing claim is not a benchmark.Exact cell and citationsS14
8QuSecure QuProtect R3QuSecure05.21Claim not verified from accessible evidenceVendor says always accurate but provides no benchmark; zero means not documented under rubric, not measured inaccuracy.Exact cell and citationsS13
8TYCHON Quantum CommandTYCHON05.16Claim not verified from accessible evidenceVendor pages returned 403; zero is bounded no metric, not a product accuracy result.Exact cell and citationsS11
8CryptoNext COMPASSCryptoNext04.68Claim not verified from accessible evidenceZero is a bounded absence of published accuracy evidence, not measured error rate; archived no-hit search was not reproduced.Exact cell and citationsS16