Edition 2026.7 / published record

Inspect every cell behind the ranking

Search the frozen 14-product, seven-criterion assessment. Each card shows the published score, its 1 October source-text and claim review, original rationale, citations and any final-review adjustment.

Separate test record: an owned synthetic QScout lab found a native CBOM schema failure and tested a local candidate correction. It did not change this edition's scores or test peer products. The candidate is not the deployed QScout release.

The complete published record

Explore 98 assessments

Filters change the visible cards in this browser. Every cell remains on its product evidence page and the archived JSON is available without JavaScript.

All 98 assessments are readable below. Filters require JavaScript and become available when ready.

98 of 98 assessments shown. Claim review dated 1 October 2026; source access checked 30 September 2026.

C1 / Discovery

QScout Pulse Gold

8 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor modules document eight surfaces but active production coverage and parameter depth across all eight are not demonstrated.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Module catalog names 8 surfaces: TLS (a), PKI/certs (b), source-code AST (c), container images (d), KMS & Vault (e), AWS/Azure/GCP crypto config (f), database TDE (h), SSH and VPN/IPSec (i); key sizes and hybrid TLS detection documented; host agent (g) and OT (j) not documented for QScout.

Final review: 10 → 8. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Detects hybrid TLS configurations combining classical and post-quantum key exchange mechanisms

C2 / Evidence artifact

QScout Pulse Gold

9 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow public artifact checked. Separate public 13-component own-API CBOM sample was schema/signature/tamper checked; this is not an estate Gold native scan.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CycloneDX 1.7 sample, detached ML-DSA-65 signature, public key and verify command all public. Independently verified on 2026-09-26: SHA-256 matched, signature verified with liboqs, and a 1-bit tamper failed verification.

Final review: 10 → 9. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

ML-DSA-65 detached signature over the exact UTF-8 wire bytes of the CycloneDX CBOM JSON (full document including serialNumber and metadata.timestamp). Verify with libOQS or the companion command in verify_command.

C3 / Change detection

QScout Pulse Gold

8 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Public 500-event hash chain/signatures are inspectable, but 10 unsigned events, before=null and heartbeat labels limit cryptographic drift proof.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Signed, hash-chained event log with published per-source latencies. Independently checked 500 events: all 499 prev_sha256 links match; event hashes recompute and ML-DSA-65 signatures verify for all 490 signed events. 10 events (2026-09-20) are unsigned with sign_error. Estate is the vendor's own, so 10 is not met.

Final review: 9 → 8. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

QScout Gold Pulse performs ongoing governed checks for cryptographic drift, new deployments, and configuration changes within approved scope.

C4 / Risk quantification

QScout Pulse Gold

9 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Published seven-factor model is organization-level while per-asset priority uses different factors; final nine is a contestable interpolation.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The 7-factor model (data sensitivity 25, future decrypt risk 20, adversary 20, timeline 15, targeting 10, hygiene 5, retention 5) is published but defined per organization. The per-system ranking uses a different 30/25/20/25 four-factor scheme with no shelf-life factor. Score below 10.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

HNDL_Score = min(100, Sigma(Factor_i_Weight * Factor_i_Score_Normalized))

C5 / Correctness

QScout Pulse Gold

6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Public corpus arithmetic recomputes but labels are partly detector-derived, legacy, and narrow; it is not an independently adjudicated product miss rate.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Rests on the fetchable per-case /accuracy-corpus, not the /accuracy-metrics number: recall 0.7628 recomputed (tp 550, fn 171, tn 647, fp 0). Labels are partly detector-derived (not independent), which rules out 10 and 8's first branch. 9 fails: 8 of 9 OQS handshakes have handshake_ok=false.

Final review: 8 → 6. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

"ground_truth_kind":"source_table_plus_detector","independent_dual_annotator":false,"recall":0.7628,"f1":0.8655,"case_count":1368

C6 / Remediation loop

QScout Pulse Gold

6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Inbound closure rule is documented/fixture-tested; public harness is not a live tenant and outbound integration defaults dry-run.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Inbound HMAC endpoint and conflict rule are documented, and closure is verified by rescan. The public harness is a recorded fixture (live_tenant=false). Outbound connectors default to dry-run. Remediation artifacts are never auto-applied.

Final review: 8 → 6. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

verify_closure checks ticket status against rescan exposure. Presence of the vulnerability with a closed ticket is a conflict, not a pass.

C7 / Reporting

QScout Pulse Gold

9 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Public role views/framework names/API exist, but sample report is fictional and mappings are not certifications.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The public sample report has an executive summary and technical findings. The 15 named frameworks include CNSA 2.0 and SP 800-131A, and NIST IR 8547 is cited in the HNDL model. JSON/SARIF/PDF/CBOM exports and a public OpenAPI exist. Board/CISO/engineering role views exist.

Final review: 10 → 9. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Findings can map to a scoped subset of 15 enterprise framework families. A mapping is evidence context, never a certification claim.

C1 / Discovery

CBOM Secure

10 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor quote enumerates many surfaces; parameter depth and hybrid detection rely on an inaccessible datasheet and remain documentation-only.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: 8 surfaces are documented: TLS (a), certs/PKI/AD (b), source code in 7 languages (c), PE/ELF binaries (d), HSM/KMIP (e), AWS/Azure/GCP KMS (f), agent for OS trust stores/hosts (g), and database TDE plus keystores (h). Key size is captured, and the datasheet says 'hybrid TLS (X25519MLKEM768) detected in production'.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

20+ production sensors inventory cryptographic assets across cloud platforms, hardware security modules, KMIP servers, TLS endpoints, directory services, databases, file systems, source code, and binaries.

C2 / Evidence artifact

CBOM Secure

7 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Accessible vendor page documents CycloneDX 1.6/1.7 export; it does not document a signature on the exported CBOM.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CycloneDX 1.6/1.7 export is documented. 'Cryptographically verifiable' integrity is claimed only for the audit trail, not the CBOM export, and no mechanism is named. No public sample or signature found.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Audit artifacts generated in CycloneDX 1.6 and 1.7.

C3 / Change detection

CBOM Secure

8 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor documents monitoring, alerts and a tamper-proof audit trail, but publishes no log mechanism or independent verification.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Continuous monitoring that detects configuration changes, email/Teams alerting and a tamper-evident change log are documented. No detection latency is published (needed for 9), and the log's mechanism (hash chain or signature) is not named.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

A tamper-proof audit trail records every asset change in a cryptographically verifiable log: what changed, when, and by whom.

C4 / Risk quantification

CBOM Secure

7 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Accessible V1.1 page confirms 0-100 score and named factors; exact archived datasheet quote was inaccessible (406), and lifetime/HNDL is absent.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: A per-asset 0-100 score and bands are documented, but the listed factors have no data-lifetime or HNDL term. HNDL/TNFL 'enrichment' appears only on the vendor blog page cbom-inventory-to-intelligence, with no mechanism and no stated combination into the numeric score. No weights are published.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Four risk bands: Critical, High, Low, Safe. Scoring weighs algorithm strength, expiry, key reuse, cipher mode, IV/nonce handling, KDF parameters, quantum exposure.

C5 / Correctness

CBOM Secure

4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor says false positives are eliminated but gives no method or precision/recall metric; anchor is only a documented claim.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: False-positive reduction through dormant/conditional/active reachability is described. No precision, recall or benchmark is documented in the URLs searched or in a web search for CBOM Secure accuracy metrics. The V1.1 'Testing and Validation Evidence' section gives outcome claims only (70-80% audit time, >90% incident reduction).

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Rather than treating every discovered asset as an equal risk, this level of precision ensures your team focuses remediation efforts on real-world exposure, eliminating false positives

C6 / Remediation loop

CBOM Secure

6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. CycloneDX export and remediation guidance support final six; named Jira/ServiceNow integration belongs to CertSecure Manager, not this product.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Ticketing integration is named once, with no named system (no Jira/ServiceNow) and no mechanism; the datasheet does not mention ticketing. Remediation guidance and CertSecure Manager integration are documented. No automated remediation or verified closure is documented.

Final review: 5 → 6. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Integrate with SIEM, GRC, and ticketing platforms to streamline remediation workflows.

C7 / Reporting

CBOM Secure

8 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor lists dashboards, KPIs and framework mapping, but no public sample report or assessed mapping accuracy.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: A per-framework mapping table is published (SP 800-131A, FIPS 140-3, CNSA 2.0, CMMC, PCI DSS 4.0, NIST IR 8547, FedRAMP). The datasheet lists role-based dashboards and a REST API with OpenAPI for every widget/KPI. No sample report was found, so 10 is not met.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Reporting includes dashboards built from 29 widgets and 52 built-in KPIs, on-demand compliance evidence, alerting via email and Microsoft Teams, and full inventory export in CycloneDX.
9 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Hybrid group handling is documented, but full surface count and parameter depth require multi-document reconciliation.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Documented surfaces: (a) Network Sensor and the CipherInsights TLS connector; (b) Cert Store Sensor and Command connector; (c) Git, GitHub, GitLab and Bitbucket source scans; (d) binaries, JAR/WAR and Docker/OCI images through the Container and Artifactory sensors; (e) Thales Luna HSM, PKCS#11 and Thales CTM; (f) AWS KMS, Azure Key Vault and GCP KMS; (g) Host Sensor through CrowdStrike and Tanium EDR; (h) MSSQL; (i) SSH key-exchange, encryption and MAC algorithms through CipherInsights. Hybrid KEX and DH-group parameters are handled. Key-size depth is not documented for each surface.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Resolved an issue where PQC hybrid algorithms ( X25519MLKEM768 ) and secure DH groups ( group14 and higher) were being incorrectly flagged as insecure.

C2 / Evidence artifact

Keyfactor AgileSec + Command

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor explicitly documents CycloneDX CBOM 1.6 export per source, without export signature.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CycloneDX 1.6 CBOM export is documented, and 3.5.1 fixed its conformance. Signing, hashing or any other integrity mechanism for the exported CBOM is not documented in the 3.4, 3.5.1, 3.6 or 3.6.4 release notes, the sensors-architecture page or the product page. A web search for signed CBOM export from Keyfactor returned nothing. The published 8 required an integrity mechanism.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Generate and download findings in Cyclone DX CBOM format (spec v1.6). CBOM can be downloaded per source.

C3 / Change detection

Keyfactor AgileSec + Command

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents findings resolved across full scans, a concrete change-state rule.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Documented mechanisms: scheduled scans, incremental scans that compare the current context with the stored one, and auto-resolution between full scans. The product page's continuous-alert language is marketing. Tamper-evident (hash-chained or signed) history is not documented, so anchor 8 is not met.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

It automatically marks findings as "resolved" when they were detected in previous scans but are no longer present in the latest full scan.

C4 / Risk quantification

Keyfactor AgileSec + Command

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents compliant/high/medium/low classification; no numerical asset model inferred.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Each finding gets a policy-based risk score and a categorical class. The product page claims prioritization by 'exposure, severity, and business impact'. Data lifetime, HNDL and the formula are not documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

At this point, findings are no longer considered pending, and each is assigned a score classification displayed as: compliant, high risk, medium risk, or low risk.
4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor records false-positive correction for secure key exchange, without published precision/recall.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: False-positive corrections appear in the release notes. No precision or recall metric or benchmark was found in the AgileSec docs, the release notes 3.4 to 3.6.4, or a search of docs.keyfactor.com.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Fixed: protocol_insecure_kex Policy False Positives on Secure Key Exchange Algorithms.

C6 / Remediation loop

Keyfactor AgileSec + Command

7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Connector API query is documented; ticket creation/automated remediation attribution requires closer source binding.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The ServiceNow VR connector pulls vulnerabilities and vulnerable items from AgileSec into ServiceNow on a schedule, one way. The raw pages were searched for clos, resolv, reopen, state and bidirection, and no write-back or VI closure logic was found. Command automates certificate enrollment, renewal and revocation from ServiceNow. Inside AgileSec, closure is verified by rescan through auto-resolution. The published 9 required documented bidirectional live write-back, which was not found.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

The Connector is used to query AgileSec’s API at a given schedule to perform the following actions: Get aggregation of Vulnerabilities from AgileSec Analytics.
6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents compliance dashboard/export, not a verified per-framework evidence mapping.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Dashboards (OpenSearch), CBOM export and an API are documented. The NIST and PCI-DSS compliance mapping appears only as a product-page marketing line with no mechanism. Separate executive and technical reports and a published sample report were not found.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Continuously assess and report on your compliance posture against industry standards like NIST, and regulatory frameworks like PCI-DSS.

C1 / Discovery

QCecuring CBOM

9 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Algorithm/key-size quote supports depth, but scored surface count and hybrid handling depend on other pages.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Docs scanner reference documents (a) TLS endpoints, (b) certificates/ADCS/Windows store, (c) source code in 6 languages, (d) binaries/linked libraries, (e/f) AWS ACM/KMS and Azure Key Vault, (g) agent filesystem keys/keystores, (i) SSH endpoints, with algorithm and key-size depth; ML-KEM/ML-DSA appear in the risk table, but TLS key_share/named-group (hybrid X25519MLKEM768) detection is not documented, so not 10.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Algorithm, key size, and quantum risk level

C2 / Evidence artifact

QCecuring CBOM

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Public documentation explicitly specifies CycloneDX 1.6 JSON output; no integrity mechanism cited.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CycloneDX v1.6 CBOM export thoroughly documented (algorithmProperties incl. NIST quantum security level, certificateProperties, dependencies, BOM-Link). No signature or hash chain on the exported CBOM is documented (only the license file is Ed25519-signed), and no public sample found; github.com/qcecuring has no public repositories.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Exports your full cryptographic inventory as a CycloneDX v1.6 JSON document. The export includes: bomFormat: "CycloneDX" , specVersion: "1.6" Unique serial number (URN UUID)

C3 / Change detection

QCecuring CBOM

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Documented comparison lists improved/regressed/unchanged and violation deltas; no signed change history shown.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Sensors run scans on hourly/6h/12h/daily/weekly schedules; compliance assessments report deltas vs the previous run; architecture lists 'Email notifications for policy violations and certificate expiry'. No tamper-evident history documented. Caveats: trend delta comes from on-demand 'Run Assessment', and email alerts are Standard/Enterprise only.

Final review: 7 → 6. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Delta vs. the previous assessment for the same standard Direction indicator: IMPROVED, REGRESSED, or UNCHANGED Per-category changes (violations added/resolved)

C4 / Risk quantification

QCecuring CBOM

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents risk categories with algorithm examples; no numerical model asserted.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Docs document 5-level categorical risk (CRITICAL..NONE) by algorithm plus per-standard rules with key-size constraints, deadlines and actions. A 6-factor weighted formula with HNDL/retention exists only in a vendor blog; it is not corroborated in the technical docs (exported properties list has no score fields), so it is not credited.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Every asset is classified automatically: Risk Level Meaning Examples CRITICAL Broken or deprecated MD5, SHA-1, DES, RC4, TLS 1.0/1.1 HIGH Quantum-vulnerable RSA, ECDSA, ECDH, DH, DSA

C5 / Correctness

QCecuring CBOM

4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Parsing limitations describe potential misses, not a measured false-positive rate; score four remains a rubric judgment.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Parse limitations and partial/failed scan status with error lists are documented; no precision/recall, benchmark or ground truth found in the 22 docs pages or product page.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Encrypted PEM keys are detected but cannot be parsed without the passphrase (they still appear as assets with algorithm info) Keystores with individual entry passwords different from the store password may not fully parse

C6 / Remediation loop

QCecuring CBOM

6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. JSON export and Action Required guidance satisfy final six; no named ticket integration inferred.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Per-violation required action and migration deadline plus 'Export the full assessment as JSON' = export plus guidance. No Jira/ServiceNow/ticketing integration documented in docs.qcecuring.com/cbom or on the integrations page; no automated remediation documented for CBOM.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Action Required remediation (e.g., “Migrate to ML-KEM”)

C7 / Reporting

QCecuring CBOM

7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Framework families listed, but mapping output/accuracy not independently checked.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Compliance mapping to CNSA 2.0/NIST PQC/FIPS 140-3 with per-standard reports, CycloneDX/JSON export and REST API are documented; the executive artifact is a dashboard ('executive summary' cards), and the 'Reports' page has no docs entry, so short of 8. No public sample report.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

CNSA 2.0 — NSA Commercial National Security Algorithm Suite NIST PQC — Post-Quantum Cryptography transition requirements FIPS 140-3 — Approved algorithms and minimum key sizes
8.5 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. All five vendor documentation URLs returned 403; surface-count/depth cannot be independently checked.

1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited source unavailable in this screen. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: 6 surfaces are documented in QTH docs: network/TLS (a), certs via CA/CT/URL (b), source code and dependencies (c), agent config scan of systems/endpoints (g), configurations (h), and SSH/IPsec (i). Key sizes and Classical/Hybrid/PQC classification are documented. Cloud (f) appears only via CLM scheduled discovery. Containers and databases are named once in a blog. HSM/KMS are not documented for QTH.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Enabled cryptographic algorithms and protocols (for example, RSA, ECC, TLS 1.2, TLS 1.3, IPsec, SSH)

C2 / Evidence artifact

AppViewX Quantum Trust Hub

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor blog/docs/datasheet returned 403; CycloneDX/CSV export claim remains unverified here.

1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited source unavailable in this screen. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CycloneDX (version not stated) or CSV export is documented in the vendor's PQC Assessment Tool blog. The user guide says QTH 'Auto-generates a Cryptographic Bill of Materials (CBOM)'. No signature, hash or public sample is documented in the docs pages fetched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

industry-standard CycloneDX or CSV formats

C3 / Change detection

AppViewX Quantum Trust Hub

5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Scheduling/drift docs returned 403; archived scheduling quote does not prove diff reporting.

1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited source unavailable in this screen. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Scheduled certificate discovery (CLM), a posture-trend widget and 'continuous, real-time visibility' in agent mode are documented. Diff/drift reporting, change alerts and tamper-evident history are not documented in the URLs searched. Activity logs record user actions, not asset changes.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Scheduled discovery is a discovery process execution type that lets you trigger a discovery process one/multiple times according to a predefined schedule.

C4 / Risk quantification

AppViewX Quantum Trust Hub

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Risk pages returned 403; archived readiness score does not establish the exact asset-risk anchor.

1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited source unavailable in this screen. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Critical/High/Medium/Low severity comes from algorithm, key size and hash. A readiness score and custom business-context policies exist. No HNDL, data-lifetime or exposure factor and no formula or weights are documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Generates the Quantum Readiness Score, a quantitative indicator of your organization's readiness for post-quantum cryptography
4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Zero reflects no documented metric in a 403-constrained search, not evidence of no accuracy work.

1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited source unavailable in this screen. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: No accuracy metric, benchmark or false-positive handling was found in any listed URL or in a web search for AppViewX PQC assessment accuracy or false positives. The only related text is a coverage caveat: 'cryptographic libraries (limited, based on tool data availability)'. The brief's cited sources contain no accuracy evidence behind the published 6.

Final review: 0 → 4. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

not documented in the listed URLs (no quote available)

C6 / Remediation loop

AppViewX Quantum Trust Hub

7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; archived CLM action may be adjacent-platform rather than Quantum Trust Hub behavior.

1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited source unavailable in this screen. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: QTH's own guide (2026.2.0 and 2026.3.0) says PQC remediation is manual. The host platform AVX ONE CLM documents ServiceNow northbound/southbound control, ticket closure and 'push and bind' certificate automation (Jan 2025 blog). No link from QTH findings to tickets or to CLM automation is documented, so 9 is not supported.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

While remediation actions remain manual and user-driven, the platform provides contextual recommendations
7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor report sources returned 403; report and framework scope cannot be independently checked.

1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited source unavailable in this screen. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The datasheet documents a leadership overview dashboard, drill-down reports per certificate/library/service, and CycloneDX/CSV export. A mapping to named compliance frameworks (NIST IR 8547, CNSA 2.0) and a sample report are not documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Generates detailed reports outlining affected algorithms, risk levels, and exposure areas
10 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor docs support broad discovery and hybrid TLS, but all seven-plus surfaces/depth are not jointly validated in one test.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Seven surfaces are documented with a mechanism: (a) network TLS through the Network Traffic Scanner and yanadump, with classic, hybrid and PQC detection; (b) certificates (X.509, ACM, Qualys, ServiceNow ingest); (d) container images and executables (Filesystem Scanner and File Inspector); (e) KMS keys ('Keys from AWS Key Management Service (KMS)'); (f) cloud crypto services (ACM, Secrets Manager, SSM, and CloudTrail consumers); (g) hosts, through the Filesystem Scanner on Linux and Windows, orchestrated by CrowdStrike or SentinelOne; (h) application runtime (the Java Code Tracer). Depth is shown by key-size rules for RSA, EC, DH and symmetric keys and by the EC group per handshake. Source code (c), through the GitLab 'AQG Static Code Scanner', is an 8th surface but is not needed to reach 7. I did not count the GitHub integration, which is AI-SPM only. I did not count SSH keys at rest as surface (i). OT/IoT (j) is not documented in the docs I searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

TLS 1.3 - Extracts client-supported ciphersuites, elliptic curves, and signature algorithms (classic, hybrid, or PQC), along with the server’s selected ciphersuites.

C2 / Evidence artifact

SandboxAQ AQtive Guard

4 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. CSV export is documented; marketed CBOM mechanism lacks version/sample, so stronger standard-export claim is withheld.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The current docs Exports page documents CSV only. The CBOM docs page covers ingest ('supports uploading ... CBOM files in JSON format'), not export. The marketing homepage claims 'Generate complete Cryptography Bills of Materials (CBOMs)', but I found no export mechanism, schema version or procedure in the docs. The legacy docs for the original release list Print (PDF), CSV and JSON. No signature or hash-chain integrity mechanism is documented. OpenCryptography.com is a public view of AQG output, but it is not a downloadable standard-schema artifact.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Export the displayed data as a CSV for further analysis and reporting.

C3 / Change detection

SandboxAQ AQtive Guard

5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. CloudTrail change observation documented; generic quote does not establish diff/alert completeness.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Continuous inputs are documented: event-driven ingestion from CloudTrail and live network monitoring with yanadump. Inventory items carry per-item 'Sessions' (last-scanned history). A side-by-side report diff ('Compare reports') is documented, but only for the original release; I did not find it in the current SaaS docs. I found no drift alerts, signed or hash-chained change history, or published detection latency.

Final review: 6 → 5. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Uses CloudTrail to track changes and to discover AWS services that use these assets (for example, EC2, Lambda, API Gateway).

C4 / Risk quantification

SandboxAQ AQtive Guard

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Policy severity categories documented, without numerical calibration.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Severity is categorical and set by rule parameters. Context comes from Impact Assessment, which counts client IPs that would break on a TLS change, and from marketing claims about owners, dependencies and blast radius ('AQtive Guard maps everykey, certificate, and algorithm to its owners, dependencies, and blast radius' — typo verbatim). I found no numeric score, no data-lifetime or HNDL factor, and no published formula. The docs page on rule severity is login-walled.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Identifies and prioritizes out-of-policy rules based on their severity (critical, high, medium, or low).

C5 / Correctness

SandboxAQ AQtive Guard

4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor says false positives reduced but provides no method or metric in cited source.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: FP handling is described. The docs mention data enrichment and exclusions. The OpenCryptography post (vendor site) says of 106 Critical/High-tagged objects 'only 10 of those were deemed to carry material risk after a data enrichment process.' No precision or recall metric, benchmark or ground truth is published. The IBM Cryptoscope paper (arXiv:2503.19531) only cites AQtive Guard and does not benchmark it.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

AQG enables you to efficiently and effectively manage and secure NHIs and cryptographic assets, reducing false positives and minimizing risk.

C6 / Remediation loop

SandboxAQ AQtive Guard

6.5 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Certificate rotation is documented; attribution to the scored AQG product scope and closure needs checking.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The current docs document automated remediation: Protect provides ACME-based short-lived certificate rotation with key generation. They also document one-way GitLab merge-request comments. In the current SaaS docs, the ServiceNow integration is ingest-only. One-way ticket creation (Jira issues and ServiceNow incidents) is documented, but only for the original release; I did not find it in the current SaaS docs. That missing leg holds the score below 7. Neither version documents a bidirectional state or a reopen-on-rescan.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

AQG Protect addresses these challenges with features like automated short-lived certificate rotation and seamless integration, helping you mitigate risks and streamline operations.
6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Weak-key/certificate dashboard and export are documented; no compliance evidence mapping asserted.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The Cryptography dashboard and CSV exports are documented. An API exists, but its reference page is login-walled. The only compliance mapping in the docs is for AI-SPM frameworks (EU AI Act, NIST AI RMF, OWASP LLM), not PQC mandates. The CNSA 2.0/NIST proof claims appear only in marketing ('Continuous compliance tracking and exportable reporting.'). No separate executive and technical reports and no published sample report are documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

It highlights potential security and compliance issues, such as weak keys or expiring certificates, so you can take corrective action to protect your data foundations.
9 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor documents multiple connector/surface types; cited Zeek quote alone is not a complete depth/hybrid proof.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: 7 surfaces documented (a network via Zeek, b certs, c source code, e KMS/HSM/Vault/DSM, f AWS/Azure/GCP services, g file-system agent, h Oracle/MSSQL DBs); key spec/size and PQC algorithms (ML-KEM/ML-DSA/LMS) documented for keys, but parameter depth not documented for code/file-system findings and hybrid detection not documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Fortanix Key Insight integrates with network security monitoring frameworks (for example, Zeek) to passively analyze mirrored network traffic and detect cryptographic artifacts such as certificates, TLS versions, cipher suites, and key exchange mechanisms on Linux systems.
6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor explicitly documents CycloneDX CBOM JSON export across named environments; no signed-export mechanism.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CycloneDX CBOM export documented (GA 25.07, confirmed); signing/hash integrity and public sample not documented in the URLs searched, so 8 is not reached.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Fortanix Key Insight now supports Cryptography Bill of Materials (CBOM) export in CBOM JSON format, adhering to the CycloneDX standard, for cryptographic assets discovered across cloud environments (AWS, Azure), on-premises deployments, and external key sources
5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor documents manual RESCAN and asset updates; scheduled diff/drift automation needed for higher anchor is absent.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Manual rescan for cloud connections plus systemd-timer scheduling for the on-prem agent are documented; a diff/drift report, change alerts and tamper-evident history are not documented in the URLs searched. 'Continuously analyzes' language has no documented mechanism.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Click RESCAN on the top-right corner of the Overview or Assessment page to perform a rescan and verify if any keys have been added, deleted, or updated in the CSP organization.

C4 / Risk quantification

Fortanix Key Insight / PQC Central

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor documents categorical risk counts with context; scoring details and validation are not published.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Critical/High/Medium/Good categories combine algorithm non-compliance with usage/permission context; PQC readiness is a published formula but only percentage = (total - vulnerableTotal)/total (a vulnerable/not flag aggregate). No data-lifetime/HNDL factor documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

A critical risk score indicates the total number of deleted keys, expired certificates, Services encrypted with cross-account key usage, non-compliant certificates by algorithm, and unencrypted cloud services detected that need attention.
0 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Zero reflects no metric in bounded accessible docs, not an observed correctness result.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: No accuracy metric, test methodology or FP handling documented in any page fetched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

not documented in the URLs listed (no precision, recall, benchmark, accuracy or false-positive handling statement found)
4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor says corrective actions can occur in platform but gives no reproducible ticket/action mechanism.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Docs give recommendations (stronger algorithms, remove unused keys); press release says 'build a roadmap in ... ServiceNow or Jira' and overview claims corrective actions, but no integration or action mechanism is documented on support.fortanix.com (site search for ServiceNow/Jira/ticket in Key Insight returned nothing).

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

This allows organizations not only to identify cryptographic risks but also to take corrective actions from within the same platform.
7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. PDF assessment report is documented; archived excerpt not reproduced and framework-to-report mapping remains unverified.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Dashboards, PDF assessment report, CSV and CBOM exports, API, and policy mapping to NIST 800-57/PCI DSS/FIPS documented; separate executive vs technical reports and PQC frameworks (IR 8547, CNSA 2.0) not documented; no public sample report.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Click DOWNLOAD REPORT on the top-right corner of the Assessment page to view the Data Security Assessment Report for the AWS connection in PDF format.
8 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. IBM lists source-code languages; the 5-6-surface count relies on additional product documents and no common runtime test.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Documented surfaces: (a) network scan of certificates, keys, ciphers and protocols; (b) PKI through Vault PKI and CA plug-ins (ADCS, DigiCert, Sectigo, Venafi); (c) source code through QSE; (e/f) cloud KMS and vaults through AWS, Azure, GCP, Akeyless and HashiCorp plug-ins; (j) mainframe through the IBM zCDI plug-in; plus Kubernetes secrets. The object model records key algorithm, key size and algorithm parameters. The PQC policy names Kyber, Dilithium, FALCON and SPHINCS+. Hybrid-algorithm detection is not documented, and depth is not shown for each plug-in surface, so the score stays at 8.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Quantum Safe™ Explorer supports scanning of source code that is written in Java, C, C++, C#, Python, Dart, Go, Kotlin, JavaScript and Typescript (Node.js).

C2 / Evidence artifact

IBM Guardium + Quantum Safe

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. IBM documentation describes CBOM/CSV/Findings.JSON output; no signature/integrity method cited.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CBOM export is documented. Signing, hashing or any integrity mechanism for the CBOM is not documented in the QSE overview, the CBOMkit blog, the cbomkit GitHub README or the GCM docs index. IBM authored the CBOM standard, but authorship is not an integrity mechanism. The published 8.5 had no integrity evidence behind it.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Scanning generates cryptographic inventory reports in various formats, including a Cryptography Bill of Materials (CBOM), .CSV files, and Findings.JSON.

C3 / Change detection

IBM Guardium + Quantum Safe

4 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor alert/policy wording does not establish crypto-level drift history; final point-in-time cap is conservative.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: GCM discovery profiles can be scheduled, and each scan gets a Run ID and a scan timeline. Diff or drift reporting between scans, change alerts and tamper-evident history are not documented in the GCM managing-discovery page, the GQS overview or the GQS getting-started page. The generic 'alerting mechanisms' line has no mechanism behind it. The published 7 had no change-detection evidence.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

It enables in-depth analysis of associated risks and vulnerabilities, offers robust policy enforcement, and alerting mechanisms to effectively manage cryptographic assets.

C4 / Risk quantification

IBM Guardium + Quantum Safe

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Verified-TLS IBM product documentation reproduces CVSS-style PQC violation wording, but asset-score calibration and current product-suite attribution remain untested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Assets are classified PQC Safe or PQC Unsafe, with CVSS-style impact scores and an 'Exploitability Score'. Data lifetime, HNDL or Mosca factors are not documented. The product page mentions 'customized risk metrics', but no formula is given.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Built-in policies automatically detect risky assets and generate PQC violations, which include CVSS-style based on CVSS impact scores, to prioritize remediation efforts.
0 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Final zero correctly excludes a CBOMkit benchmark not tied to Guardium/Quantum Safe; absence of IBM-specific metric is bounded.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Paper: Näther (XITASO GmbH) and Hirsch (University of Applied Sciences Amberg-Weiden), 'Hidden Ciphers and Where to Find Them', arXiv 2608.04857v1, 5 Aug 2026. The arXiv Comments field says 'accepted at ICICS 2026' (byte-verified). It tests CBOMkit-hyperion (PQCA sonar-cryptography v1.6.1) on 70 Go-invocation occurrences: TP 38, FP 7, FN 32, giving P 0.84, R 0.54, F1 0.66. Ground truth is the synthetic Cryben corpus with a CycloneDX 1.7 CBOM, built by the authors of the competing tool Crypsy. It is independent of CBOMkit, but no dual annotation is stated. Because n<100, anchor 6 is the ceiling.

Final review: 6 → 0. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

On the full Go-invocation ground truth Crypsy reaches F1 = 0.92 (P = 0.95, R = 0.89) versus 0.66 for CBOMkit (P = 0.84, R = 0.54)

C6 / Remediation loop

IBM Guardium + Quantum Safe

7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Jira/ServiceNow ticket creation is documented; automated remediation action beyond a ticket is not tested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Tickets go one way to Jira or ServiceNow, and the status is explicitly tracked in the external system. The product page states 'Automate key generation and certificate renewal'. AI-prefilled remediation fields are documented. Bidirectional sync and rescan-verified closure are not documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

For the tickets that are created in JIRA and ServiceNow, you need to track the ticket status in those particular applications.
6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. IBM documents PDF dashboard export, no stronger report claim inferred.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Documented: a posture dashboard with PDF export, CSV/Excel export of violations, a Swagger API, and 'audit-ready reports'. The only framework referenced is generic NIST quantum-safe alignment. Separate executive and technical reports, and mappings to CNSA 2.0, NIST IR 8547 or OMB, are not documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Export: You can export the dashboard in PDF format.

C1 / Discovery

O3 Security

7 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor lists code/libraries/binaries/configurations; 5-6 surfaces and algorithm depth are not independently enumerated.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: QBOM page documents code, libraries, binaries and configurations; the CBOM page's 'Complete infrastructure coverage' section adds card labels for Container Images, Live Databases, Cloud Infrastructure, Hardware Security Modules, Web Servers & Network and TLS Certificates (with illustrative counts), plus example parameter output (RSA-2048, ECC-P256, ML-KEM). No per-surface mechanism documented (docs portal login-gated); hybrid detection not documented. 10 implied, capped per rubric line 19.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Discovers every cryptographic algorithm across your source code, libraries, binaries, and configurations — then scores each one against Grover's and Shor's algorithms to determine quantum exposure.

C2 / Evidence artifact

O3 Security

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Archived generic industry-format quote does not name CycloneDX; exact standard-schema export support unverified.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Sentence sits under a Standards heading followed by 'SPDX' and 'CycloneDX' labels; the CERT-In page states O3 'generates a CycloneDX CBOM'. 'Every CBOM, versioned' is versioning, not signing or hash-chaining. Signing and a public sample are not documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Industry-standard formats accepted by regulators and supply-chain partners.

C3 / Change detection

O3 Security

5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Versioned CBOM is documented; scheduled re-scan/diff mechanism is not established.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Per-push CI re-generation ('Automatic on every push') and versioned history are stated, exceeding manual point-in-time scans; no diff/drift report mechanism, change alerts or tamper-evident history is documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Every CBOM, versioned. Full history of how your cryptographic posture has changed over time

C4 / Risk quantification

O3 Security

7 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor urgency ranking uses break-year and attack surface; numeric score/data lifetime/weights are not shown.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Break-year estimate, attack surface and an HNDL flag feed a ranked migration priority, with Critical labels and per-asset migration paths; the HNDL flag is algorithm-based and data sensitivity/lifespan appears only in a generic educational guide, not as a documented product factor. No formula published.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Ranks cryptographic assets by urgency — algorithms closest to their break-year with the widest attack surface get the highest migration priority

C5 / Correctness

O3 Security

0 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded no-metric finding; docs portal access limits prevent complete correctness review.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: No correctness evidence found; public GitHub repos contain no CBOM/QBOM/PQC tooling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

not documented in the URLs listed (no accuracy metric, benchmark, test methodology or false-positive handling found; docs portal login-gated)

C6 / Remediation loop

O3 Security

4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Migration report is named, but concrete remedial step quality is not checked.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Per-asset migration paths (e.g. RSA-2048 -> ML-DSA-65, 3DES -> AES-256-GCM) are guidance; Jira appears only in the platform-wide integrations list on the homepage, with no crypto-finding ticketing, automated remediation or closure mechanism documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

produces a CBOM and migration report in one pass

C7 / Reporting

O3 Security

7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. CNSA gaps are named; actual framework-to-evidence mapping and executive report unavailable for review.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CNSA 2.0 gap mapping and CERT-In parameters named, migration report plus JSON/CSV/CycloneDX/SPDX exports; separate executive vs technical reports, API documentation and a public sample report are not documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Compares your current cryptographic posture against NSA's Commercial National Security Algorithm Suite 2.0 requirements and surfaces every gap

C1 / Discovery

ISARA Advance

8 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor lists many surfaces broadly; independently checked detail is insufficient for exact 5-6-surface depth anchor.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The Azure whitepaper (§5–6) documents mechanisms for passive network monitoring of TLS and SSH via vTAP and the ISARA Network Analyzer, which covers surfaces (a) and (i). It also documents Azure Key Vault (e/f), endpoint scans (g) and database encryption queries (h). Certificates (b) are covered across pages. Depth: 'Inventory algorithms, protocols, primitives, key lengths, and device information.' That is 6 surfaces. Code (c) and OT/SCADA (j) are claimed without a mechanism. PQC/hybrid detection by the product is not documented in the URLs searched; only a vendor blog checklist mentions PQC validators.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Agentless-first discovery across networks, servers, databases, code, CMDBs, KMSs, and more to map your complete cryptographic posture

C2 / Evidence artifact

ISARA Advance

3 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Primary Azure whitepaper documents dashboards/APIs but no explicit standard/proprietary export; midpoint three is discretionary.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Dashboards, APIs and webhook integrations are documented, but no export format (CSV/PDF/JSON/CBOM) is documented in the URLs searched. I found no integrity mechanism or public sample. The vendor's own blog argues CBOMs are not essential, and I found no CBOM export claim. The 'Cryptography Validator Report' is form-gated and I did not fetch it.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Provides dashboards and APIs for remediation prioritization

C3 / Change detection

ISARA Advance

5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Primary Azure whitepaper documents continuous monitoring and historical trends; no tamper-evident mechanism shown.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Continuous monitoring, historical trend analysis and 'snapshots, trend views, and burn-down reporting' are documented. I found no drift alert mechanism, signed or hash-chained change history, or published latency. Drift detection appears only in a generic best-practice guide, not as a product mechanism.

Final review: 6 → 5. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Supports continuous monitoring and historical analysis of cryptographic trends

C4 / Risk quantification

ISARA Advance

7 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Primary whitepaper names algorithm strength, key size and usage context risk scores; no lifetime/HNDL or ranking formula.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The posture score combines several factors and drives prioritized remediation. The Solutions page adds 'Risk scoring aligned to data sensitivity and exposure'. Data lifetime or HNDL is not documented as a scoring input; HNDL appears only as risk framing. No formula is published.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Assigns risk-based posture scores based on algorithm strength, key size, and usage context

C5 / Correctness

ISARA Advance

0 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded lack of public accuracy metric; source marketing claim is not a benchmark.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: This text describes the analysis method only. Accuracy metrics, false-positive handling and benchmarks are not documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

ISARA Advance uses automated agentless scanning to discover cryptographic assets across your environment, then analyzes each asset against current standards and best practices to identify risks, misconfigurations, and vulnerabilities.

C6 / Remediation loop

ISARA Advance

6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents ticket workflows and CMDB integration, without closure test.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Ticketing and CMDB integration are documented ('connects with CMDBs, cloud-based KMSs, databases, and ticketing systems through built-in or webhook integrations'), along with prioritized remediation actions. I found no documented automated remediation action by the product itself. The key-rotation text in the Azure guide is generic advice. Bidirectional sync and verified closure are not documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Remediate vulnerabilities through ticket-based workflows and CMDB integrations.

C7 / Reporting

ISARA Advance

7 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor executive/trend views are documented; exact framework mapping and report artifact not tested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Separate stakeholder views are documented: executive and board, GRC and application owners, and engineers. Compliance support is claimed ('Meet cryptographic inventory and reporting requirements under NSM-10 and OMB M-23-02'; PCI-DSS, DORA, NERC CIP), but no mapping mechanism, export or sample report is documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Gain visibility into enterprise cryptographic risk through snapshots, trend views, and burn-down reporting that support executive decision-making.
6 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Hybrid group support is documented; the single quote does not itself prove the scored number of discovery surfaces.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Documented surfaces: (a) public TLS endpoints, (b) certificates (TLM, CyberArk/Keyfactor/CSV import), (e/f) keys in Azure Key Vault/AWS KMS/Google Cloud KMS via customer-run export script; algorithm + key size/curve + ML-DSA/SLH-DSA and hybrid ML-KEM key-agreement detection documented. Only the public-endpoint scan and TLM sync are product-driven discovery; the rest is ingestion of customer-produced CSV. Applications/libraries: 'Application inventory is on the roadmap'. 3-4 surfaces -> 6.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Key agreements using X25519MLKEM768 , SecP256r1MLKEM768 , and SecP384r1MLKEM1024 are considered quantum-safe and count towards your Quantum Readiness % .

C2 / Evidence artifact

DigiCert Quantum Central

4 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents export for offline use, without a standard-schema CBOM or integrity mechanism in cited material.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CBOM export is claimed on the product page ('Export CBOMs for internal and external stakeholders', WebFetch-extracted) and GA press release, but no schema is named and none of the 32 docs pages documents a CBOM export; documented exports are dashboard/inventory data, violation records and AI-Assist CSV/PDF. Claimed anchor 6 capped at the anchor below (rubric line 19). No integrity mechanism documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Export dashboard and inventory data for offline review or reporting.

C3 / Change detection

DigiCert Quantum Central

5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor states imports after stale sync; automatic import is not the same as verified cryptographic diff detection.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Re-evaluation against policies on asset change and a violation lifecycle (first-detected time, closed history) exist, but sync is sign-in-triggered, endpoint scans are manual, no scheduled rescan or diff report is documented, no tamper-evident history, and Essentials retains history 1 month.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Quantum Central can automatically import newly discovered certificates and TLS endpoints from Trust Lifecycle Manager when you sign in. This automatic import runs only if asset data was last synced more than 24 hours ago.

C4 / Risk quantification

DigiCert Quantum Central

5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Policy severity is documented; exact per-asset contextual risk scoring remains a rubric interpolation.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Built-in assessment is a quantum-safe true/false flag plus a Quantum Readiness %; Critical/High/Medium/Low exists only as user-assigned policy severity (Essentials allows 1 policy). No HNDL/data-lifetime factor or formula documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Every violation created by a policy inherits the policy’s severity. Choose the severity based on the risk represented by the condition and the expected urgency of remediation.

C5 / Correctness

DigiCert Quantum Central

4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents manual handling for false positives, without a published accuracy metric.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: False-positive handling and the exact quantum-safe classification rules (subjectPublicKeyInfo, signatureAlgorithm, named key-agreement groups) are documented; no accuracy metric, benchmark or ground truth found in the 32 docs pages.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Use manual resolution for situations such as an accepted risk, a false positive, a nonessential asset, or an asset approaching retirement.

C6 / Remediation loop

DigiCert Quantum Central

8 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Vendor describes external task status readback, but a comparative live workflow test is absent.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Outbound Jira task creation plus inbound status sync mapped to Open/In Progress/Done/Cancelled (shipped 9 Sep 2026, after the 2026.5 review), and verified closure: 'Automated indicates that Quantum Central verified that the asset passes the policy.' Caveat: 'Completing the task in the connected system does not close the violation.' Jira only; ServiceNow/GitHub 'planned'. TLM PQC certificate upgrade is a one-line Essentials-plan claim with no workflow page, not relied on.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Quantum Central retrieves the current status and maps it to a standardized state. The connected system remains the source of truth, and Quantum Central does not change the task’s status.
6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents filtered dashboard/inventory export; no stronger report behavior is inferred.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Dashboard, violation export, AI-Assist PDF/CSV reports documented. No role-specific executive/technical report, no mapping of assets to frameworks (NIST IR 8547 appears only as a timeline table and the FAQ is a resource list), and the Essentials REST API is 'Import only', so no export API.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Export the filtered records for audit or compliance review.

C1 / Discovery

QuSecure QuProtect R3

4 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Reconnaissance documents network-negotiated algorithms/certs; exact one-to-two surface boundary is a rubric judgment.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The documented mechanism is passive sensors on live network traffic. They read TLS versions, key exchange, signatures, ciphers, certificates, key sizes and JA3/JA4 fingerprints, and detect PQC ('Algorithm-level detection (RSA, ECC, PQC) plus key sizes'). That covers surfaces (a) and (b). The older discovery page claims 'Routers, servers, endpoints, applications, cloud, and network infrastructure'. It names no mechanism beyond network observation, and the Recon page contrasts itself with source-code scanning. I found no documented discovery of code, binaries, HSM/KMS, cloud KMS, host configuration, SSH or IPsec. IPsec appears only as an encryptor protocol.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

QuProtect Reconnaissance builds a live inventory of the algorithms, protocols, certificates and key sizes your systems negotiate.

C2 / Evidence artifact

QuSecure QuProtect R3

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Vendor documents CycloneDX 1.6 CBOM export from live inventory; exported bytes were not tested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: A CycloneDX v1.6 CBOM export is documented. I found no signature, hash chain, public sample or verification procedure on the fetched pages.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

QuProtect Reporting generates a CycloneDX v1.6 cryptographic bill of materials from the live inventory the sensors build, on demand and in machine-readable form.

C3 / Change detection

QuSecure QuProtect R3

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Continuous traffic inventory is documented, but explicit cryptographic diff and tamper history are absent.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The inventory is continuous. Reports show 'What is in and out of policy, and what changed', and the Recon page says configuration drift is found. I found no drift alert mechanism, signed or hash-chained change history, or published detection latency.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Reports generate on demand from the inventory, which updates continuously from live traffic.

C4 / Risk quantification

QuSecure QuProtect R3

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Exposure-based risk ordering is documented; model and calibration not supplied.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Findings are ranked by exposure. I found no numeric score, no documented data-lifetime or HNDL factor, and no formula. The Resilience page names HNDL only as a finding class to remediate, not as a scoring input.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Find where legacy cryptography is still in use, on live network traffic, ranked by exposure rather than by count.

C5 / Correctness

QuSecure QuProtect R3

0 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor says always accurate but provides no benchmark; zero means not documented under rubric, not measured inaccuracy.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The fetched pages give accuracy only as an adjective. Accuracy metrics, false-positive handling and benchmarks are not documented in the URLs searched. The Recon page gives a design argument that wire observation beats code scanning ('Source code tells you what an application might negotiate.'). That is a rationale, not an accuracy-handling mechanism or a metric. The Army TRL-7 item is third-party news or certification and is inadmissible.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

The inventory is always accurate, and your compliance posture is always current.

C6 / Remediation loop

QuSecure QuProtect R3

6.5 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Orchestrator action is an adjacent network control and inventory refresh; no cross-product peer run verifies closure.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Automated remediation is strongly documented: policy-driven algorithm change and automated certificate provisioning and rotation. Closure is recorded in the next export ('The finding, the policy change, the result'). Ticket creation is not documented. The only outbound integration named is 'Integrations: select vulnerability scanners, SIEM and SOAR', so anchor 7's ticket leg is unmet.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

An administrator sets a policy in the Orchestrator. Encryptors carry the connection over post-quantum TLS 1.3 at the network layer, with no application code change, and the inventory records the fix in the next CBOM export.

C7 / Reporting

QuSecure QuProtect R3

8 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Human/machine report outputs are documented; compliance mapping detail needs direct report review.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The Reporting page has a mapping table ('Mapped to the instruments you answer to') covering OMB M-26-15, EO 14412, CNSA 2.0, NIST IR 8547, PCI DSS 4.0 12.3.3 and DORA. It names board/executive reporting ('Visibility into cryptographic posture for risk committees and executives') and per-connection technical detail. I found no published sample report, so 10 is not reached.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Reports export on demand in machine-readable and human-readable form, covering the cryptography in use, the policy in force and the record of changes
8 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor product pages returned 403; third-party Elastic PR does not establish scored surface count/depth.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Surfaces backed by a fetched quote: (a) passive network through ACDI Sniffer; (b) certificates; (d) crypto libraries and archives; (g) endpoints; (i) VPN clients, IPsec and MACsec; (j) OT and IoT. The product page states 'detects both hybrid and pure post-quantum cryptographic implementations'. The partner Elastic schema has key_length_bits and pqc_algos. Containers and cloud storage (the brief's S11) were not found on current pages and were not counted, and source code, HSM and cloud KMS are not documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

ACDI Sniffer analyzes packet capture data to identify cryptographic protocols, algorithms, certificates, and network services without installing software on the systems being observed.

C2 / Evidence artifact

TYCHON Quantum Command

4 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; third-party integration PR does not prove a product CycloneDX export.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: The only CBOM evidence is one product-page line. The partner Elastic package documents NDJSON/JSON output, and its fields.yml has no CBOM field (grep for 'cbom' returned no match). Signing or integrity is not documented on the product page, the cryptographic-inventory page or the Elastic PR.

Final review: 5 → 4. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Complete Inventory: CBOM (CycloneDX) format

C3 / Change detection

TYCHON Quantum Command

4 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; archived change-alert wording has no accessible mechanism.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Vendor pages claim real-time endpoint monitoring, change alerts and an 'Audit trail', but give no mechanism, schedule or diff report. The only technical artifact is the Elastic package, which upserts current state ('rescans update the same entity record'). That is not a change history. Tamper-evident history is not documented. The published 8 was carried unchanged from 2026.4 after a 403.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Understand, analyze, and score your risk posture – monitor, trace, and alert on cryptographic inventory changes.

C4 / Risk quantification

TYCHON Quantum Command

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; exact risk score factors and categories unverified.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Vendor pages name a '100-point scoring system'. The Elastic schema has quantum_risk, risk_level and overall_score fields. The factors, weights, data lifetime and HNDL are not documented, so anchor 8 is not met.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Automatically generate the cryptographic inventories required under OMB M-26-15, H.R. 7535 and M-23-02, with built-in risk scoring and audit-ready reporting.

C5 / Correctness

TYCHON Quantum Command

0 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; zero is bounded no metric, not a product accuracy result.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Accuracy metrics, benchmarks and product false-positive handling were not found in the URLs listed, or in a web search for TYCHON Quantum Command accuracy, false positives or benchmarks. The only quote is generic advice in a 2024 vendor blog, not a product mechanism. The Elastic PR's pipeline tests check ingest parsing, not detection accuracy. The published 5 had no source.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Be prepared to handle false positives. Some legitimate uses of these algorithms may be flagged.

C6 / Remediation loop

TYCHON Quantum Command

6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; archived response-action claim cannot verify automation/product scope.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Automated response actions are claimed, and export to a SIEM (Elastic, Splunk) is shown. ServiceNow or Jira ticketing, bidirectional sync and rescan-verified closure are not documented on the product page or in the Elastic PR, so anchor 7 (ticket plus automated action) is not met.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Response Actions let you act directly from the platform, disabling weak ciphers, enforcing updated policies, and targeting your most vulnerable systems first.
6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; dashboard/export claim unverified.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Dashboards are documented, including partner Kibana dashboards for inventory, application, certificate and cost reports, along with JSON export. The product page lists 'M-26-15 NSM-10 H.R. 7535 NIST FIPS 203/204/205 CNSA 2.0 CISA Aligned' as badges. No documented mapping, executive versus technical reports or sample report was found, so it lands with its peers at 6.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

With TYCHON's intuitive dashboards, you can monitor the cryptographic status of every endpoint in real time.

C1 / Discovery

CryptoNext COMPASS

6 / 10

Weight 4/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Primary Network Probe PDF confirms TLS/SSH/ISAKMP and parameters; archived longer protocol list and cross-surface count need further corroboration.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Native discovery is the passive network probe: (a) TLS/network, (b) certificates in transit, (i) SSH/IPsec/ISAKMP, (j) OT protocols (dnp3 etc.) = 4 surfaces with 'algorithms, parameters, keys, certificates' extraction. Other sources (CLM, scanners, EDRs) are third-party feeds via API, not COMPASS discovery; PQC/hybrid detection not documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Inspected Protocols TLS/SSL, DTLS, QUIC, SSH, ISAKMP, Kerberos, DNSSec, SMB

C2 / Evidence artifact

CryptoNext COMPASS

6 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Narrow feature documented. Primary Network Probe PDF states CBOM files based on OWASP CycloneDX; PDF text extraction splits the standard name.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: CycloneDX CBOM output streamed via Kafka is documented; the datasheet's 'code signing' and 'software integrity checks' refer to the appliance, not to the CBOM artifact. CBOM signing/hash chain and a public sample are not documented in the URLs searched.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

The CryptoNext COMPASS Network Probe produces CBOM files, based on the OWASP CycloneDX standard, enabling easy integration with any system that supports this format.

C3 / Change detection

CryptoNext COMPASS

5 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Primary PDF explicitly describes passive continuous traffic monitoring; no diff/drift reporting or alert timing shown, making midpoint discretionary.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Continuous passive capture is documented (exceeds point-in-time), but diff/drift reporting, change alerts and tamper-evident change history are not documented in the URLs searched; published 8 requires drift alerts AND signed/hash-chained history.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

The CryptoNext COMPASS Network Probe is a hardware appliance designed for passive and continuous network traffic monitoring, enabling the detection and collection of cryptographic assets in transit to build a comprehensive inventory.

C4 / Risk quantification

CryptoNext COMPASS

4 / 10

Weight 3/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Data sensitivity/criticality linkage is vendor-documented; formula and per-asset risk behavior are not verified.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Detection of weak/non-compliant algorithms plus a claimed sensitivity/criticality context for prioritization; no score, categories, formula or HNDL/data-lifetime factor documented, so the claim is capped below the anchor it implies.

Final review: 5 → 4. Read the ruling.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

COMPASS does more than identify cryptographic assets: it links them to the data they protect, with information on sensitivity and criticality, to enable risk-based prioritization.

C5 / Correctness

CryptoNext COMPASS

0 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded absence of published accuracy evidence, not measured error rate; archived no-hit search was not reproduced.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Throughput ('up to 1 Gbps') and 'no packets lost' are performance claims, not detection-correctness metrics.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

not documented in the URLs listed (no accuracy metric, benchmark, test methodology or false-positive handling found)

C6 / Remediation loop

CryptoNext COMPASS

4 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. API/CMDB integration is vendor-documented; ticket creation or closure is not demonstrated, consistent with guidance-only cap.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Source accessible; excerpt not reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Downstream API export named; ticket creation, automated remediation or closure verification not documented in the URLs searched. CryptoNext 'Remediation' SDK is a separate product and not credited to COMPASS.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Standard APIs for easy upstream (sensors: CLM, scanners, EDRs, etc.) and downstream (platforms: CMDB, CTEM, etc.) integrations

C7 / Reporting

CryptoNext COMPASS

6 / 10

Weight 2/19 · Researched 2026-09-26 · Archived access check 2026-09-30

Internal 1 October claim review: Partial or qualified support. Compliance reports are named; actual standards-to-finding mapping and report output are not independently examined.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the score.

Historical 30 September source-access check

Cited excerpt reproduced. Checked 2026-09-30; this earlier access state remains separate from the later source-text and claim-review results, which may differ.

Archived assessment: Dashboards, a 'personalized report generation module', REST API and CBOM/Kafka export are documented; compliance reports and DORA/NIS2/ANSSI/NIST references are named but no report content, framework mapping or sample is documented.

Original excerpt and cited sources

URL availability labels below reflect the historical 30 September source-access screen.

Use ready-made compliance reports, customize them, and respond to audits at any time.

[1] Publisher and product relationship. Qtonic Quantum Corp publishes this Index and builds QScout; QScout's evidence was reviewed more deeply than peer evidence. Read the complete method and disclosure.