{
  "qc_run": "Adversarial QC C, 2026-09-26. Every URL below was fetched in this QC pass, with WebFetch or with curl+pdftotext on the research host for PDFs. Scores are QC candidates. The default was the lower anchor.",
  "half_point_rule_applied": "A half point stays only when the evidence fully meets the lower anchor AND meets at least one component of the upper anchor through a documented mechanism (not an adjective or a single marketing line). A capability named once with no mechanism is capped AT the lower anchor (rubric line 19), not halfway. For C3 specifically: 5 = recurring or continuous collection by a documented mechanism, with history or trend at most; 6 needs a documented diff/drift output ('what changed', drift, added/removed). Docs that the vendor itself labels 'for the original release' and redirects away from are not credited, and this applies the same way in every cell.",
  "cell_rulings": [
    {
      "slug": "cryptonext-compass",
      "cell": "C3",
      "researcher_score": 5,
      "qc_score": 5,
      "verdict": "upheld",
      "evidence": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf (pdftotext on the research host: 'hardware appliance designed for passive and continuous network traffic monitoring'); https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/ ('Keep cryptographic discovery continuous and multi-source')",
      "reason": "Anchor 4 is exceeded because the appliance collects continuously, and that is a documented mechanism, which is one component of anchor 6. The datasheet and product page document no diff, drift or change output, so 6 is not met. The evidence is clearly between 4 and 6. The published 8 was carried_thin, and no evidence was found to restore it. Big-drop check (8 to 5): no drift alerts or tamper-evident history found; not restored."
    },
    {
      "slug": "cryptonext-compass",
      "cell": "C4",
      "researcher_score": 5,
      "qc_score": 4,
      "verdict": "lowered",
      "evidence": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/ ('Quickly identify weak, obsolete, or non-compliant cryptographic algorithms'); https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/ ('Connect each cryptographic asset to the data it protects and its business criticality')",
      "reason": "The only documented output is a weak or non-compliant flag, which is anchor 4. The sensitivity and criticality linkage is a marketing sentence with no categories, score or mechanism. The researcher cited rubric line 19 but put the score above the cap that line sets, so it snaps to 4."
    },
    {
      "slug": "digicert-quantum-central",
      "cell": "C3",
      "researcher_score": 5,
      "qc_score": 5,
      "verdict": "upheld",
      "evidence": "https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-trust-lifecycle-manager.html ('automatically import newly discovered certificates and TLS endpoints ... when you sign in ... only if asset data was last synced more than 24 hours ago'); https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html (evaluates when 'The status or attributes of an asset change')",
      "reason": "Two mechanisms are documented: automatic re-import, and policy re-evaluation when an asset changes. Both go beyond a manual point-in-time scan. The import is triggered by sign-in rather than a schedule, and no diff report is documented. The evidence is between 4 and 6."
    },
    {
      "slug": "digicert-quantum-central",
      "cell": "C4",
      "researcher_score": 5,
      "qc_score": 5,
      "verdict": "upheld",
      "evidence": "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html ('Every violation created by a policy inherits the policy's severity' with Critical/High/Medium/Low definitions)",
      "reason": "The built-in quantum-safe flag meets anchor 4. Documented Critical/High/Medium/Low categorical levels meet one component of anchor 6, but the user assigns them rather than deriving them from algorithm vulnerability. That places the evidence between 4 and 6."
    },
    {
      "slug": "appviewx-quantum-trust-hub",
      "cell": "C3",
      "researcher_score": 5,
      "qc_score": 5,
      "verdict": "upheld",
      "evidence": "https://docs.appviewx.com/2026.2.0/oxy_ex/scheduled_discovery.html ('lets you trigger a discovery process one/multiple times according to a predefined schedule'; certificates only); https://docs.appviewx.com/2026.2.0/oxy_ex/monitoring_pqc_logs.html (logs record user actions); https://docs.appviewx.com/2026.3.0/quantum_trust_hub.html (no scheduling, trend or drift content)",
      "reason": "Scheduled rescans are documented, but only for certificate discovery on the CLM host platform. No diff, drift or change output and no tamper-evident history is documented, and the PQC logs record user actions, not asset changes. The score stays at 5, the upper edge of what the evidence supports. The published 8 (drift alerts plus tamper-evident history) cannot be restored. Big-drop check: also fetched https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/ (\"continuous visibility\" is an adjective) and the QTH datasheet PDF (no drift/alert/history text)."
    },
    {
      "slug": "fortanix-key-insight-pqc-central",
      "cell": "C3",
      "researcher_score": 5,
      "qc_score": 5,
      "verdict": "upheld",
      "evidence": "https://support.fortanix.com/docs/fortanix-key-insight-file-system-and-network-scanner-agent-configuration-linux ('The systemd timer automatically triggers the scanner at the specified intervals', OnCalendar=Sun 03:45); https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md (manual RESCAN; page 'reflects the current state')",
      "reason": "Scheduled rescans are documented (weekly systemd timer), which is one component of anchor 6. After a rescan the page shows current state only, with no diff or drift report. The evidence is between 4 and 6."
    },
    {
      "slug": "o3-security",
      "cell": "C3",
      "researcher_score": 5,
      "qc_score": 5,
      "verdict": "upheld",
      "evidence": "https://o3.security/cryptographic-bill-of-materials ('Automatic on every push'; 'Every CBOM, versioned ... Full history of how your cryptographic posture has changed over time — immutable and auditable')",
      "reason": "CBOMs regenerate automatically on every CI push, a documented trigger, and versioned history is shown. No diff or drift report is documented. 'Immutable' is an adjective with no signing or hash mechanism, so it earns no credit toward 8. The evidence is between 4 and 6."
    },
    {
      "slug": "isara-advance",
      "cell": "C2",
      "researcher_score": 3,
      "qc_score": 3,
      "verdict": "upheld",
      "evidence": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf (pdftotext: 'Provides dashboards and APIs for remediation prioritization'); https://www.isara.com/ ('connects with CMDBs, cloud-based KMSs, databases, and ticketing systems through built-in or webhook integrations')",
      "reason": "APIs and webhook integrations move data out of the dashboard, which exceeds anchor 2 (dashboard-only). No export format (CSV, PDF, JSON or CBOM) is documented on the product page, the whitepaper or isara.com, so anchor 4 is not met. The evidence is between 2 and 4. The published 5 was carried_thin, and it was not restored. Big-drop check: https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html and https://www.isara.com/solutions.html also fetched; no export format found."
    },
    {
      "slug": "tychon-quantum-command",
      "cell": "C2",
      "researcher_score": 5,
      "qc_score": 4,
      "verdict": "lowered",
      "evidence": "https://tychon.io/tychoncryptographicinventory/ ('Complete Inventory: CBOM (CycloneDX) format', a single line); https://tychon.io/products/tychon/pqc-management-module/ (no CBOM or export text); https://github.com/elastic/integrations/pull/20142 (NDJSON/JSON output, PR still open)",
      "reason": "CycloneDX appears once, in a feature list, with no version, schema, procedure or sample. Rubric line 19 caps it AT anchor 4. The documented output is NDJSON/JSON, which is proprietary (anchor 4). This matches how the researcher scored DigiCert C2 (a CBOM export claimed with no schema scored 4)."
    },
    {
      "slug": "sandboxaq-aqtive-guard",
      "cell": "C6",
      "researcher_score": 6.5,
      "qc_score": 6.5,
      "verdict": "upheld",
      "evidence": "https://docs.aqtiveguard.com/aqg-protect/ ('Certificate rotation is handled through the ACME protocol'; 'New keys are created when a certificate is first issued and each time it's rotated'); https://aqtiveguard.sandboxaq.com/docs/integrations/jira/issue-export/ ('This guide is for the original release of AQtive Guard'); https://docs.aqtiveguard.com/data-sources/servicenow/ (ingest-only)",
      "reason": "The current docs document automated remediation (ACME rotation with key generation), which is one component of anchor 7. Jira and ServiceNow ticket creation is documented only on pages that call themselves 'for the original release' and point to the current SaaS docs, so the ticket leg is not credited. CSV export plus guidance meets anchor 6. The evidence is between 6 and 7."
    },
    {
      "slug": "qusecure-quprotect-r3",
      "cell": "C6",
      "researcher_score": 6.5,
      "qc_score": 6.5,
      "verdict": "upheld",
      "evidence": "https://www.qusecure.com/resilience/ ('Automated certificate provisioning and rotation, with your CA keys staying yours'); https://www.qusecure.com/recon/ ('Encryptors carry the connection over post-quantum TLS 1.3 ... and the inventory records the fix in the next CBOM export')",
      "reason": "Automated remediation is documented through policy-driven PQ TLS and certificate rotation, one component of anchor 7. CycloneDX export plus guidance meets anchor 6. The Recon, Resilience and FAQ pages document no ticket creation. The evidence is between 6 and 7."
    },
    {
      "slug": "appviewx-quantum-trust-hub",
      "cell": "C5",
      "researcher_score": 0,
      "qc_score": 4,
      "verdict": "raised",
      "evidence": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html ('If the cryptographic algorithm is referenced from a constant, variable, configuration, or resolved at runtime and cannot be determined through static analysis, the algorithm cannot be determined and will be marked as Unknown')",
      "reason": "This is a documented product rule for accuracy handling. The product labels indeterminate detections Unknown instead of misclassifying them, which meets anchor 4 ('accuracy or false-positive handling described, no metric'), the same bar as the DigiCert and Keyfactor C5=4 precedents. No metric was found, so the published 6 is not restored. This is the weakest raise in this QC pass."
    },
    {
      "slug": "fortanix-key-insight-pqc-central",
      "cell": "C5",
      "researcher_score": 0,
      "qc_score": 0,
      "verdict": "upheld",
      "evidence": "https://support.fortanix.com/docs/key-insight-release-notes (index: no false-positive or accuracy items); https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md; WebSearch 'Fortanix Key Insight scan accuracy false positive suppress ignore finding documentation'; gh repo list fortanix (only mbedtls matches)",
      "reason": "No accuracy, false-positive handling or benchmark was found under the searched denominator. Not documented in these sources, which is a bounded finding, not a claim of absence."
    },
    {
      "slug": "isara-advance",
      "cell": "C5",
      "researcher_score": 0,
      "qc_score": 0,
      "verdict": "upheld",
      "evidence": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html (no accuracy/FP text); https://github.com/isaracorp/Bad-Crypto-Examples (one Java file, no README, no metrics); WebSearch 'ISARA Advance cryptographic inventory accuracy \"false positives\" OR validation OR benchmark'",
      "reason": "Not documented. The only candidate artifact, Bad-Crypto-Examples, is an undocumented single-file repo, not ground truth. The published 5 was carried_thin and had no source."
    },
    {
      "slug": "o3-security",
      "cell": "C5",
      "researcher_score": 0,
      "qc_score": 0,
      "verdict": "upheld",
      "evidence": "https://o3.security/cryptographic-bill-of-materials (no accuracy, FP, reachability or confidence text); https://o3.security/qbom (no accuracy validation); gh repo list o3security (only an osv-scanner fork); WebSearch 'O3 Security CBOM QBOM scanner false positives accuracy github'",
      "reason": "Not documented in the listed sources. The docs portal requires a login, which is a residual."
    },
    {
      "slug": "tychon-quantum-command",
      "cell": "C5",
      "researcher_score": 0,
      "qc_score": 0,
      "verdict": "upheld",
      "evidence": "https://tychon.io/implementing-quantum-safe-cryptographic-discovery-in-your-ci-cd-pipeline-part-8-of-8/ (Jim Walker, 31 Oct 2024: 'Be prepared to handle false positives. Some legitimate uses of these algorithms may be flagged.'); https://tychon.io/discovering-and-validating-quantum-vulnerable-algorithms-in-windows-and-linux-parts-3-4-of-8/ (10 Oct 2024, generic PowerShell/OpenSSL scripts, no validation metrics); https://tychon.io/products/tychon/pqc-management-module/; https://github.com/elastic/integrations/pull/20142",
      "reason": "The quoted line does NOT meet anchor 4. It comes from an educational blog series about DIY scripts, not about Quantum Command, and it tells the reader to expect false positives. It does not describe how the product handles them (no allowlist, suppression, triage state or rule). Compare DigiCert (a product 'false positive' resolution state) and Keyfactor (product release-note FP fixes). The Elastic PR tests check ingest parsing, not detection accuracy."
    },
    {
      "slug": "qusecure-quprotect-r3",
      "cell": "C5",
      "researcher_score": 0,
      "qc_score": 0,
      "verdict": "upheld",
      "evidence": "https://www.qusecure.com/recon/ ; https://www.qusecure.com/frequently-asked-questions-faqs/ (no accuracy/FP Q&A); WebSearch 'QuSecure QuProtect R3 discovery false positives accuracy validation test results'; gh repo list QuSecure (no public repos matched)",
      "reason": "Accuracy is stated only as an adjective ('always accurate'). No metric, methodology or FP handling is described. Third-party TRL and news items are inadmissible."
    },
    {
      "slug": "cryptonext-compass",
      "cell": "C5",
      "researcher_score": 0,
      "qc_score": 0,
      "verdict": "upheld",
      "evidence": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf (pdftotext grep for accura/false/valid: no hits); https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/; WebSearch 'CryptoNext COMPASS probe detection accuracy evaluation paper OR whitepaper false positives'",
      "reason": "Not documented. Throughput ('1 Gbs Continuous') is performance, not correctness."
    },
    {
      "slug": "appviewx-quantum-trust-hub",
      "cell": "C6",
      "researcher_score": 7,
      "qc_score": 7,
      "verdict": "upheld",
      "evidence": "https://www.appviewx.com/blogs/streamline-certificate-lifecycle-management-with-appviewx-avx-one-clm-and-servicenow/ ('With both northbound and southbound integration capabilities'; 'Automated incident creation, resolution workflows and ticket closure'; no QTH/PQC findings mentioned); https://docs.appviewx.com/2026.3.0/quantum_trust_hub.html ('While remediation actions remain manual and user-driven'); https://store.servicenow.com/store/app/93c9eb621b246a50a85b16db234bcb42 (fetched; description not rendered)",
      "reason": "The published 9 is not restored, and 8 is not reached either. The bidirectional ServiceNow document covers the CLM certificate-request round trip and never mentions QTH. The QTH guide itself says PQC remediation is \"manual and user-driven\", so bidirectional handling of the scored PQC findings is not documented. Seven stands because the same platform documents one-way incident creation plus automated push-and-bind certificate remediation for the certificate surface that QTH scans."
    },
    {
      "slug": "fortanix-key-insight-pqc-central",
      "cell": "C6",
      "researcher_score": 4,
      "qc_score": 4,
      "verdict": "upheld",
      "evidence": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md (CBOM JSON export 'adhering to CycloneDX' plus CSV exports of keys, certificates and services); https://support.fortanix.com/docs/fortanix-key-insight-gcp-connection-user-interface-components ('Recommended remediation actions to strengthen the overall security status'); https://support.fortanix.com/docs/users-guide-plugin-library (ServiceNow incident plugin is DSM-only, not credited)",
      "reason": "Upheld at 4. Key Insight documents remediation recommendations and data exports (CSV, CycloneDX CBOM), but no ticketing, workflow-tool export or remediation action. The ServiceNow incident plugin is Fortanix DSM, not Key Insight, and the ServiceNow/Jira roadmap line in the press release has no mechanism (rubric line 19). The \"ticket/export\" in anchor 6 is read narrowly, as export into a remediation workflow, for three reasons: C2 already scores data exports; the slash pairs export with ticket; and the researcher scored CryptoNext C6=4 despite CBOM-via-Kafka and CMDB/CTEM APIs. The published 6 is not restored. Open rubric question: on a literal reading, file export plus guidance would give 6 (see overall_verdict)."
    },
    {
      "slug": "isara-advance",
      "cell": "C3",
      "researcher_score": 6,
      "qc_score": 5,
      "verdict": "lowered",
      "evidence": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf (product section: 'Supports continuous monitoring and historical analysis of cryptographic trends'; 'Continuously track changes' appears only under generic 'Key Principles'); https://www.isara.com/partner-msazure.html ('snapshots, trend views, and burn-down reporting')",
      "reason": "The researcher's 6 depended on change tracking. On the fetched whitepaper, the 'track changes' line sits in a generic principles list, not in the ISARA Advance capability list. What ISARA Advance itself documents is continuous monitoring plus trend and history views, with no diff or drift output. Under the rule applied to O3 and Fortanix, that is 5. The published 8 was carried_thin, and nothing restores it."
    },
    {
      "slug": "sandboxaq-aqtive-guard",
      "cell": "C3",
      "researcher_score": 6,
      "qc_score": 5,
      "verdict": "lowered",
      "evidence": "https://docs.aqtiveguard.com/data-sources/aws/ ('Event-driven ingestion from CloudTrail to keep CPM and AI-SPM inventories current'); https://docs.aqtiveguard.com/inventory/ (Sessions = 'Last scanned history'); https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/ (live monitoring, no change detection); https://aqtiveguard.sandboxaq.com/docs/projects/compare-reports/ ('This guide is for the original release of AQtive Guard')",
      "reason": "The current SaaS docs show continuous, event-driven collection and last-scanned history, with no diff or drift output. The only diff feature, Compare reports, appears in docs labelled 'original release'. Those same docs are the reason the researcher denied the ticketing leg in C6, so crediting them here would be inconsistent. Either both cells credit legacy docs (C3=6, C6=7) or neither does. QC takes the lower path: 5. The published 8 is not restored."
    },
    {
      "slug": "digicert-quantum-central",
      "cell": "C2",
      "researcher_score": 4,
      "qc_score": 4,
      "verdict": "upheld",
      "evidence": "https://www.digicert.com/quantum-central ('Export CBOMs for internal and external stakeholders', no format named); https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html ('Export dashboard and inventory data for offline review or reporting', no format); WebSearch 'DigiCert Quantum Central export CBOM CycloneDX' (only news hits, which are inadmissible)",
      "reason": "The product page claims CBOM export but names no schema, and the docs and release notes document only dashboard and inventory export. Rubric line 19 caps it at 4. The published 6 is not restored."
    },
    {
      "slug": "tychon-quantum-command",
      "cell": "C3",
      "researcher_score": 4,
      "qc_score": 4,
      "verdict": "upheld",
      "evidence": "https://tychon.io/use-cases/quantumreadiness/ ('monitor, trace, and alert on cryptographic inventory changes', one line); https://tychon.io/tychoncryptographicinventory/ ('Historical Tracking: Audit trail', a label); https://tychon.io/products/tychon/pqc-management-module/ (no alert, audit or history mechanism); https://github.com/elastic/integrations/pull/20142",
      "reason": "Change alerting and an audit trail are named with no mechanism, schedule or diff. Line 19 caps the claim at 4. The published 8 was carried_thin after an HTTP 403, and it is not restored."
    },
    {
      "slug": "qusecure-quprotect-r3",
      "cell": "C1",
      "researcher_score": 4,
      "qc_score": 4,
      "verdict": "upheld",
      "evidence": "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/ ('Routers, servers, endpoints, applications, cloud, and network infrastructure. Agentless deployment'); https://www.qusecure.com/quprotect/ ('QuProtect sensors observe live network traffic passively')",
      "reason": "The listed layers are network vantage points observed by passive traffic sensors, not separate cryptographic surfaces with their own mechanisms. Documented surfaces are (a) network/TLS and (b) certificate metadata, with algorithm, key-size and PQC depth. That is 1-2 surfaces, so 4. The published 6 is not restored."
    },
    {
      "slug": "qusecure-quprotect-r3",
      "cell": "C3",
      "researcher_score": 6,
      "qc_score": 6,
      "verdict": "upheld",
      "evidence": "https://www.qusecure.com/reporting/ ('What is in and out of policy, and what changed'; 'Reports generate on demand from the inventory, which updates continuously from live traffic'); https://www.qusecure.com/recon/ ('Configuration drift, self-signed and vendor certificates, found')",
      "reason": "Continuous collection and reports that state 'what changed' and drift meet anchor 6. No tamper-evident history or change alerts are documented, so the published 8 is not restored."
    },
    {
      "slug": "sandboxaq-aqtive-guard",
      "cell": "C5",
      "researcher_score": 4,
      "qc_score": 4,
      "verdict": "upheld",
      "evidence": "https://www.sandboxaq.com/post/introducing-opencryptography (30 Oct 2025: '106 objects tagged ... only 10 of those were deemed to carry material risk after a data enrichment process'; no methodology or ground truth); https://docs.aqtiveguard.com/ ('reducing false positives'); https://docs.aqtiveguard.com/inventory/exclusions/",
      "reason": "False-positive handling is described (enrichment, exclusions). The 106-to-10 figure is a triage ratio with no test methodology or ground truth, so anchor 6 is not met. The published 6 is not restored. arXiv 2608.04857 does not mention AQtive Guard."
    },
    {
      "slug": "keyfactor-agilesec-command",
      "cell": "C2",
      "researcher_score": 6,
      "qc_score": 6,
      "verdict": "upheld",
      "evidence": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes ('Generate and download findings in Cyclone DX CBOM format (spec v1.6)', no signing or integrity text); WebSearch 'Keyfactor AgileSec CBOM export signed OR signature OR integrity OR hash docs.keyfactor.com' (no hit)",
      "reason": "CycloneDX 1.6 export is documented with no integrity mechanism, which is anchor 6. The published 8 is not restored."
    },
    {
      "slug": "keyfactor-agilesec-command",
      "cell": "C3",
      "researcher_score": 6,
      "qc_score": 6,
      "verdict": "upheld",
      "evidence": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview ('on-demand or scheduled execution'; 'Compares the current context with the stored context'; auto-resolution marks findings 'resolved' when no longer present)",
      "reason": "Scheduled scans plus documented change output (auto-resolution of findings that have disappeared) meet anchor 6. No hash-chained or signed history or alerts are documented, so the published 8 is not restored."
    },
    {
      "slug": "keyfactor-agilesec-command",
      "cell": "C6",
      "researcher_score": 7,
      "qc_score": 7,
      "verdict": "upheld",
      "evidence": "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr ('The Connector is used to query AgileSec's API at a given schedule', one-way, no write-back); https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr-operations (no close/reopen logic); https://www.keyfactor.com/servicenow-announcement/ ('automate certificate enrollment, renewal, and revocation')",
      "reason": "One-way ticket creation (the VR connector) plus automated certificate actions (Command) meet anchor 7. No bidirectional write-back or reopen logic is documented, so the published 9 is not restored."
    }
  ],
  "c5_convention_note": "Precedent bar for C5=4, taken from the researcher's own cells: a PRODUCT mechanism or product documentation for false-positive or accuracy handling (DigiCert: a 'false positive' manual-resolution state; Keyfactor: FP fixes in product release notes; SandboxAQ: product enrichment and exclusions). Generic advice to the reader does not qualify. TYCHON's quote fails this bar. It comes from an Oct 2024 educational blog about DIY scripts (Part 8 of 8, by Jim Walker), not from Quantum Command docs, and it describes no product handling. TYCHON stays 0. Searches run per vendor on 2026-09-26, beyond the researcher's: (1) peer-reviewed benchmarks: arXiv 2608.04857 (Crypsy vs CBOMkit-hyperion) evaluates none of the seven; ARES 2026 'Empirical Analysis of Open-Source Tools for Cryptographic Asset Discovery' covers open-source tools by its title (the full text returned 403/auth redirect, which is a residual); (2) `gh repo list <org>` on the research host for o3security, appviewx, fortanix, isaracorp and QuSecure: no CBOM or detector test corpus (cryptonext and tychon-io orgs were not found); (3) a vendor-targeted WebSearch for accuracy, false-positive or benchmark terms for each of the 7; (4) re-fetch of the vendor docs pages listed in each ruling. Result: AppViewX was raised to 4 on a documented product rule that labels indeterminate static-analysis results 'Unknown'. The other six stay 0, stated as 'not documented in the searched sources', not as a claim that the evidence does not exist. Residuals: O3's docs portal needs a login, the ISARA 'Cryptography Validator Report' is behind a form, and the ARES paper full text was not fetched.",
  "overall_verdict": "Tally (from the 30 deduplicated rulings, recomputed with jq): upheld 25, lowered 4, raised 1. Of 11 off-anchor cells, 9 were kept and 2 were snapped down: CryptoNext C4 5 to 4 and TYCHON C2 5 to 4. In both, the researcher cited the rubric line 19 cap and then scored above it. Of the 7 C5=0 cells, 6 stay at 0 and AppViewX was raised to 4, the weakest raise (a documented rule that labels indeterminate static-analysis results Unknown). The TYCHON false-positive quote does not meet anchor 4 because it is advice in a generic 2024 blog, not a product mechanism. Of the 22 cells that dropped by 2 or more, 19 were upheld, 1 raised (AppViewX C5 0 to 4) and 2 lowered a further point: ISARA C3 6 to 5, because \"track changes\" appears only in a generic-principles list, and SandboxAQ C3 6 to 5, because docs labelled \"original release\" were credited in C3 but not in C6. No big-drop cell was restored to its published value. Open rubric question, with no score change: read literally, C6 anchor 6 (\"ticket/export plus guidance\") would lift Fortanix C6 and O3 C6 from 4 to 6 on file export plus guidance. QC applied the narrow workflow-export reading, which matches the researcher's CryptoNext C6=4. The index owner should settle which reading applies. Published cells for TYCHON C3/C5, ISARA C2/C3/C5, CryptoNext C3/C5 and O3 C5 were carried_thin with no source, so the drops there reflect missing evidence rather than a change of opinion."
}
