C2 / 15.79% of index
Evidence artifact
Does it produce a portable, verifiable record of what was found?
What is evidence artifact?
An evidence artifact is a portable record of discovery results, such as a CycloneDX cryptographic bill of materials, that can be validated and reused outside the product interface.
A dashboard assertion is not the same as durable evidence. Schema validation, hashes, signatures and public verification procedures determine whether another party can prove the artifact is complete and unaltered.
Questions to ask a vendor
- Can the complete artifact be downloaded?
- Does it validate against a named schema?
- Can an unaffiliated third party verify integrity without contacting the vendor?
What this edition actually supports
Weight 3 of 19. Can a reviewer carry the finding away and verify its structure and custody?
A CBOM or equivalent export is useful when it identifies the product/build, records findings, states its source and can be checked against a public format. The QScout 9 in the frozen edition includes a signed sample from its own API; that sample is not a customer-estate Gold scan. A separately published owned one-file lab packet shows what its local, unreleased export repair produced, including an incomplete after inventory.
How to investigate this criterion
Inspect the actual artifact, schema, signature scope, verifier and the difference between sample, lab and production output.
Primary and original inputs: api.qtonicquantum.com · cyclonedx.org · pqc-index.org. Review all dated cell source checks and the 1 October per-cell limits.
The 2026.7 cells below are public-evidence scores. A vendor page documents a claim; an artifact check tests only its stated scope. Missing product execution and inaccessible sources remain explicit unknowns. The score snapshot has not been recomputed from later pages.
Evidence artifact scores in edition 2026.7
Equal scores share the same criterion position; the next position skips the tied places. The highest value in this column is a published rubric cell, not a measured product winner. A partial or unverified source anchor remains visible even when its numeric score is high.
| Position on criterion | Product | Evidence artifact score | Overall score | Internal 1 October source review | Evidence |
|---|---|---|---|---|---|
| 1 | QScout Pulse GoldQtonic Quantum Corp | 9 | 8.00 | Narrow public artifact checkedSeparate public 13-component own-API CBOM sample was schema/signature/tamper checked; this is not an estate Gold native scan.Exact cell and citations | S27S28S29S30 |
| 2 | CBOM SecureEncryption Consulting | 7 | 7.47 | Narrow feature documentedAccessible vendor page documents CycloneDX 1.6/1.7 export; it does not document a signature on the exported CBOM.Exact cell and citations | S04S05S06 |
| 3 | Keyfactor AgileSec + CommandKeyfactor | 6 | 6.53 | Narrow feature documentedVendor explicitly documents CycloneDX CBOM 1.6 export per source, without export signature.Exact cell and citations | S08S25 |
| 3 | QCecuring CBOMQCecuring | 6 | 6.53 | Narrow feature documentedPublic documentation explicitly specifies CycloneDX 1.6 JSON output; no integrity mechanism cited.Exact cell and citations | S19 |
| 3 | AppViewX Quantum Trust HubAppViewX | 6 | 6.37 | Claim not verified from accessible evidenceVendor blog/docs/datasheet returned 403; CycloneDX/CSV export claim remains unverified here.Exact cell and citations | S07S24 |
| 3 | Fortanix Key Insight / PQC CentralFortanix | 6 | 5.74 | Narrow feature documentedVendor explicitly documents CycloneDX CBOM JSON export across named environments; no signed-export mechanism.Exact cell and citations | S15 |
| 3 | IBM Guardium + Quantum SafeIBM | 6 | 5.58 | Narrow feature documentedIBM documentation describes CBOM/CSV/Findings.JSON output; no signature/integrity method cited.Exact cell and citations | S09S10S26 |
| 3 | O3 SecurityO3 Security | 6 | 5.47 | Claim not verified from accessible evidenceArchived generic industry-format quote does not name CycloneDX; exact standard-schema export support unverified.Exact cell and citations | S17 |
| 3 | QuSecure QuProtect R3QuSecure | 6 | 5.21 | Narrow feature documentedVendor documents CycloneDX 1.6 CBOM export from live inventory; exported bytes were not tested.Exact cell and citations | S13 |
| 3 | CryptoNext COMPASSCryptoNext | 6 | 4.68 | Narrow feature documentedPrimary Network Probe PDF states CBOM files based on OWASP CycloneDX; PDF text extraction splits the standard name.Exact cell and citations | S16 |
| 11 | SandboxAQ AQtive GuardSandboxAQ | 4 | 6.21 | Narrow feature documentedCSV export is documented; marketed CBOM mechanism lacks version/sample, so stronger standard-export claim is withheld.Exact cell and citations | S12 |
| 11 | DigiCert Quantum CentralDigiCert | 4 | 5.37 | Narrow feature documentedVendor documents export for offline use, without a standard-schema CBOM or integrity mechanism in cited material.Exact cell and citations | S18 |
| 11 | TYCHON Quantum CommandTYCHON | 4 | 5.16 | Claim not verified from accessible evidenceVendor pages returned 403; third-party integration PR does not prove a product CycloneDX export.Exact cell and citations | S11 |
| 14 | ISARA AdvanceISARA | 3 | 5.42 | Partial or qualified supportPrimary Azure whitepaper documents dashboards/APIs but no explicit standard/proprietary export; midpoint three is discretionary.Exact cell and citations | S14 |