{
  "qc_role": "Adversarial QC A (demote by default). Fetched 2026-09-26 ~15:20-15:55Z from the research host with OpenSSL 3.5.7 curl; working copies in the research working directory",
  "admissibility_rule_applied": "One rule for every cell: an unauthenticated, fetchable vendor URL (page or API artifact) is admissible, as the rubric lists 'public downloadable sample artifacts'. Two limits apply. (1) Where the vendor's own linked documentation contradicts an unlinked API route, the linked documentation controls, because that is what a buyer reads. (2) Artifact content is judged on what it actually contains, not on its label. Self-ratings (v4_cell, field_total, lab_total, board-pack grades) are ignored. Discoverability is recorded as a caveat and does not disqualify on its own: none of 15 fetched site pages (modules, cryptographic-inventory, qscout, qscout/sample-report, api-reference, integrations, trust, verify-proof, proof-center, qscout/methodology, methodology, release-proof, qscout/benchmark, qscout/pulse) contains a link or string 'public/trust'. /api-reference says: 'Raw findings, requester artifact downloads, signed reports, and automated execution APIs are not exposed as anonymous public routes.' A WebSearch for the sample did not return its URL.",
  "reachability": "api.qtonicquantum.com negotiates ONLY X25519MLKEM768. OpenSSL 3.5.7 s_client: '-groups X25519MLKEM768 -> Negotiated TLS1.3 group: X25519MLKEM768'; '-groups X25519', '-groups MLKEM768' and '-groups SecP256r1MLKEM768' each return 'SSL alert number 40'. Classic curl (OpenSSL 3.0.13) fails with rc=35. Current Chrome, Firefox and Safari offer X25519MLKEM768 by default, so a 2026 browser can fetch it. Older curl, Python on OpenSSL 3.0, and older Java/.NET clients cannot. WebFetch also reached cbom.sample.json. Result: reachable by a normal outsider using a current browser, but not by common scripted tooling.",
  "cell_rulings": [
    {
      "slug": "qscout-pulse-gold",
      "cell": "C1",
      "researcher_score": 10,
      "qc_score": 8,
      "verdict": "lowered",
      "evidence": "https://qtonicquantum.com/modules: 'All 74 catalog modules shown. Full module specifications available during sales engagement.' Every surface has a one-line entry, e.g. 'KMS & Vault Inventory: Summarizes KMS and Vault key metadata -- assesses key age, rotation posture, and algorithm strength', 'TLS Termination Mapper: Parses TLS termination configuration snapshots', 'Service Mesh Crypto Mapper: Summarizes mesh crypto posture from provided config snapshots', 'Cloud Metadata Collector: Summarizes cloud assets from provided metadata snapshots'. https://api.qtonicquantum.com/public/capabilities/source-depth: languages count 5; 'libraries':{'status':'unpublished'}, 'function_patterns':{'status':'unpublished'}. https://qtonicquantum.com/downloads/qscout-hndl-methodology.md line 535: 'Future Decrypt Risk (20%) | Directly measured from TLS cipher suites, certificate key types, key exchange algorithms'.",
      "reason": "Anchor 10 requires >=7 surfaces WITH algorithm+parameter depth and PQC/hybrid detection. Parameter depth (e.g. RSA-2048) and hybrid/PQC detection are documented only for TLS/certificates. SSH and IKE get 'quantum-vulnerable' detection, not PQC. The other surfaces are one-line catalog entries with no mechanism, and the vendor says specifications come only in a sales engagement. Several 'surfaces' ingest customer-provided snapshots rather than discover assets. About 6 surfaces have algorithm-level wording (a,b,c,d,e,i), which fits anchor 8 (5-6 surfaces with algorithm depth). Host agent (g) and OT (j) were not documented. Symmetry check: CBOM Secure's datasheet documents per-surface detail (PKCS#11 HSMs, 7 languages and 70+ libraries, binary scanning, 'Agents for depth, agentless for reach', 'hybrid TLS (X25519MLKEM768) detected in production'), so its 10 survives the same rule."
    },
    {
      "slug": "qscout-pulse-gold",
      "cell": "C2",
      "researcher_score": 10,
      "qc_score": 9,
      "verdict": "lowered",
      "evidence": "https://api.qtonicquantum.com/public/trust/cbom.sample.json is 'CycloneDX 1.7 13' components, with metadata.component 'qscout-api ... internal crypto surface (algorithms, protocols, and related material that the service itself implements)', and properties 'qscout:sample-not-estate-cbom=true' and 'qscout:not=estate-scale Gold CBOM'. sha256 06e2fcec...883c3 equals cbom.verification.json cbom_sha256 and is stable across two fetches. Independent verification with stock OpenSSL 3.5.7 (no liboqs), after wrapping the 1952-byte key in an ML-DSA-65 SPKI: 'Signature Verified Successfully'; a 1-bit flip gives 'Signature Verification Failure'. /api-reference: 'signed reports ... are not exposed as anonymous public routes'. /cryptographic-inventory: 'CBOM data exports to JSON and SARIF formats'.",
      "reason": "The signature is real and verifiable by an outsider with OpenSSL 3.5, so the claim is above 8. It sits clearly between 8 and 10: the signed file is a self-inventory of the vendor's own API ('sample-not-estate-cbom'), not a sample of what the product produces for a scanned estate. No documentation page links to it, and the API reference says the opposite. The public product pages also disagree about the export format (JSON/SARIF on cryptographic-inventory versus CycloneDX 1.7 on /qscout)."
    },
    {
      "slug": "qscout-pulse-gold",
      "cell": "C3",
      "researcher_score": 9,
      "qc_score": 8,
      "verdict": "lowered",
      "evidence": "https://api.qtonicquantum.com/public/trust/pulse: '\"product\":\"qscout_pulse\",\"not_gold_pulse\":true', 'dogfood':true, 'third_party_customer':false, 'real_time':false, drift_latency note 'not collector ingest SLO', per-source cloud_audit_event and certificate_transparency sample_count 5 each. https://api.qtonicquantum.com/public/trust/pulse-changes: 500 changes, python Counter of before-is-null gives 'Counter({True: 500})'. A sample event has after={'host':'qtonicquantum.com','customer_estate':true,'third_party_customer':false}. https://qtonicquantum.com/qscout/pulse: 'scheduled reassessment, event-triggered updates when a certificate rotates or a domain appears, and drift reporting when posture regresses'.",
      "reason": "Three independent reasons 9 fails. (1) The endpoint cited for the latency and chain labels itself 'not_gold_pulse', so it belongs to a different product than the one scored. (2) The 'change history' holds no change content: all 500 events have before=null and host-level 'after' fields, with no crypto diff. (3) The headline latency is pipeline time by the vendor's own note, and the detection samples are n=5. Anchor 8 is met: scheduled and event-triggered monitoring with drift reporting is documented, and a signed hash chain exists. A stricter reading (history without change content is not change history) would give 6."
    },
    {
      "slug": "qscout-pulse-gold",
      "cell": "C4",
      "researcher_score": 9,
      "qc_score": 9,
      "verdict": "upheld",
      "evidence": "https://qtonicquantum.com/downloads/qscout-hndl-methodology.md line 87: 'HNDL_Score = min(100, Sigma(Factor_i_Weight * Factor_i_Score_Normalized))', plus a weight table 25/20/20/15/10/5/5 including '7 | Data Retention Window | 5%'. https://qtonicquantum.com/cryptographic-inventory prioritization table: Data Sensitivity 30%, Algorithm Vulnerability 25%, Migration Complexity 20%, Business Criticality 25%, with example 'Customer Payment API ... 91.5'.",
      "reason": "The formula and all weights are published and include shelf-life and sensitivity, so it exceeds 8. The ranked per-system priority comes from a different four-factor scheme without a lifetime term. Three of the seven HNDL factors (50% of weight) are industry defaults or user input, not measured. The evidence is clearly between 8 and 10, so 9 stands."
    },
    {
      "slug": "qscout-pulse-gold",
      "cell": "C5",
      "researcher_score": 8,
      "qc_score": 6,
      "verdict": "lowered",
      "evidence": "https://api.qtonicquantum.com/public/trust/accuracy-corpus: case_count 1368, precision 1.0, recall 0.7628. Sources: tls-signaturescheme.csv 538, tls-parameters-4.csv 448, tls-parameters-8.csv 70 (1,056 IANA registry rows), badssl 82, crt.sh %.qryptonic.com 71 and %.qtonicquantum.com 26 (the vendor's own domains), test.openquantumsafe.org 9. Capabilities: tls_surface 1246, cert_expiry 122. A sample case: 'ground_truth':'positive','signal':'tls-ciphersuites TLS_NULL_WITH_NULL_NULL','detected':false.",
      "reason": "The rubric NOTE says detector-in-label ground truth is NOT independent, and anchor 6 names exactly this case ('ground truth not independent'). Anchor 8's second branch drops the independence requirement and contradicts both. Default-to-lower resolves this to 6. Substance: 77% of cases classify IANA registry rows (a table lookup, not discovery), 97 cases are the vendor's own certificates, and only 2 of 7 claimed capabilities are measured."
    },
    {
      "slug": "qscout-pulse-gold",
      "cell": "C6",
      "researcher_score": 8,
      "qc_score": 6,
      "verdict": "lowered",
      "evidence": "https://qtonicquantum.com/integrations: 'Connectors are one-way creation today: QScout opens or updates tickets outbound. They are dry-run by default (dry_run=true)... Bidirectional ticket-driven state and non-dry write-back are on the Workflow 10 path'. https://qtonicquantum.com/qscout: 'Workflow connectors (Jira / ServiceNow) are one-way ticket creation and dry-run by default today.' https://api.qtonicquantum.com/public/trust/workflow/inbound: 'customer_estate':false. https://api.qtonicquantum.com/public/trust/closed-loop-harness: 'mode':'recorded_http_fixture','live_tenant':false.",
      "reason": "Under the admissibility rule, the vendor's two linked product pages say one-way and control over an unlinked route. Anchor 8 (bidirectional or inbound state machine) is not established as available to customers. Anchor 7 needs automated remediation actions, and none are documented. Anchor 6 applies: one-way ticketing plus guidance. Documented rescan closure verification ('Presence of the vulnerability with a closed ticket is a conflict, not a pass') is noted as a plus but does not reach 7."
    },
    {
      "slug": "qscout-pulse-gold",
      "cell": "C7",
      "researcher_score": 10,
      "qc_score": 9,
      "verdict": "lowered",
      "evidence": "https://qtonicquantum.com/qscout/sample-report: 'Illustrative sample. This report uses synthetic demonstration data'. It is one document containing an 'Executive summary' and 'Top findings'. Its only framework reference is 'may not meet upcoming NIST PQC CNSA 2.0 requirements'. https://api.qtonicquantum.com/public/trust/framework-inventory: a list of 15 framework names with no control mapping. https://api.qtonicquantum.com/public/trust/board-pack: 'sample':true, role_views board/ciso/engineering, and embedded self-ratings 'field_total':9.3,'lab_total':9.54 (inadmissible). https://qtonicquantum.com/qscout/pulse: 'Methodology mapped to NIST IR 8547 (initial public draft) / FIPS 203-205 / CNSA 2.0'.",
      "reason": "A published sample report exists, which CBOM Secure lacks, so the claim is above 8. It is not 10: the sample is one combined report, not separate role-specific executive and technical reports. It shows no compliance mapping, and the 15 frameworks are a name list rather than a mapping. CBOM Secure publishes a per-framework table. The evidence is clearly between 8 and 10."
    }
  ],
  "qscout_public_only_total": 8.0,
  "qscout_public_only_arithmetic": "(4*8 + 3*9 + 3*8 + 3*9 + 2*6 + 2*6 + 2*9)/19 = (32+27+24+27+12+12+18)/19 = 152/19 = 8.00. Researcher: 9.26. Delta -1.26.",
  "rubric_bias_findings": [
    {
      "cell": "C5",
      "biased": true,
      "finding": "Anchor 8's second branch ('external corpus n>=1000 with published recall') drops independence. It contradicts the rubric's own NOTE and anchor 6 ('ground truth not independent'). Its only use is to lift a vendor-built, partly detector-labelled corpus like QScout's 1,368-case set to 8. Anchor 9's 'completed live PQC handshakes' is a QScout-instrument artifact, not an accuracy measure.",
      "neutral_anchor": "10: precision+recall vs independent dual-annotated ground truth, n>=1000. 8: a published metric vs an independently constructed or third-party benchmark. 6: a published metric on a vendor-built or non-independent corpus, or n<100. 4: FP handling described, no metric. 0: not documented.",
      "rescore": {
        "qscout-pulse-gold": 6,
        "cbom-secure": 4
      }
    },
    {
      "cell": "C3",
      "biased": true,
      "finding": "Anchors 9 and 10 ('event-sourced', 'PUBLISHED detection latency', 'each change signed', '24h wall-clock') copy QScout's implementation and its /public/trust/pulse fields. A competitor with identical monitoring could reach 9 only by publishing a latency number, which is a disclosure act. The anchors never ask whether the history records what cryptography changed, the capability a buyer actually needs, and QScout's log fails that test (before=null x500).",
      "neutral_anchor": "10: continuous (event-driven or <=24h) monitoring of customer estates with documented crypto-level diffs (before/after algorithm or parameter), alerting, and tamper-evident history. 8: continuous or scheduled monitoring with change alerts plus either tamper-evident history or documented diffs. 6: scheduled rescans with drift reporting. 4: manual re-runs. 0: not documented.",
      "rescore": {
        "qscout-pulse-gold": 8,
        "cbom-secure": 8
      }
    },
    {
      "cell": "C6",
      "biased": true,
      "finding": "Anchor 8's 'inbound state machine implemented' credits code that exists but that the vendor itself says is not a customer capability ('one-way creation today'). Anchor 9's 'live tenant write-back' mirrors QScout's harness vocabulary.",
      "neutral_anchor": "9: customer-deployed bidirectional write-back documented as generally available. 8: bidirectional integration documented as available to customers. 7: one-way ticketing plus automated remediation actions. 6: one-way ticketing plus guidance. 4: guidance only.",
      "rescore": {
        "qscout-pulse-gold": 6,
        "cbom-secure": 5
      }
    },
    {
      "cell": "C2",
      "biased": false,
      "finding": "The anchor is disclosure-weighted, because publishing a signed sample is a documentation act, but it is not exclusive: any vendor can publish a signed sample, and verifiability has real buyer value. Clarification: the '10' sample must be product output (a sample of what a customer receives) and must be reachable from documentation. No score changes beyond the C2=9 already ruled.",
      "rescore": {
        "qscout-pulse-gold": 9,
        "cbom-secure": 7
      }
    },
    {
      "cell": "C1/C4/C7",
      "biased": false,
      "finding": "No QScout-exclusive element was found. The C7 '10' element 'published sample report' is disclosure, but it is open to all vendors.",
      "rescore": {
        "qscout-pulse-gold": "C1 8, C4 9, C7 9",
        "cbom-secure": "C1 10, C4 7, C7 8 (as given)"
      }
    }
  ],
  "neutral_rubric_totals": {
    "qscout-pulse-gold": 8.0,
    "cbom-secure": 7.37
  },
  "neutral_rubric_arithmetic": "QScout (8,9,8,9,6,6,9): 152/19 = 8.00. CBOM Secure (10,7,8,7,4,5,8): (40+21+24+21+8+10+16)/19 = 140/19 = 7.37. The neutral anchors do not move CBOM Secure. Its cells were taken as given apart from a spot check of C1 (vendor page quote '20+ production sensors ... source code, and binaries' confirmed; datasheet confirms agents, 7 languages, PKCS#11 HSMs and X25519MLKEM768 detection).",
  "overall_verdict": "The researcher's 9.26 is not defensible. A defensible QScout total is 8.00, with 6 cells lowered (C1 10->8, C2 10->9, C3 9->8, C5 8->6, C6 8->6, C7 10->9) and 1 upheld (C4 9). Real strengths that survive: the ML-DSA-65 signed CycloneDX sample verifies with stock OpenSSL 3.5 and fails on tamper; the HNDL formula and weights are published; a public sample report exists. What fell: the discovery breadth is catalog one-liners with specifications held for sales; the Pulse evidence is self-labelled 'not_gold_pulse', dogfood-only, and records no crypto diffs; the accuracy corpus is 77% IANA-row lookups; the vendor's own pages say ticketing is one-way. The C3, C5 and C6 top anchors are QScout-shaped. Under neutral anchors QScout scores 8.00 and CBOM Secure 7.37: QScout stays #1, but the gap shrinks from 1.89 to 0.63. The whole QScout evidence base (other than the site pages) sits on API routes that no documentation page links to, and those routes are reachable only with X25519MLKEM768-capable clients. That discoverability caveat should be disclosed next to any ranking."
}
