{
  "slug": "appviewx-quantum-trust-hub",
  "name": "AppViewX Quantum Trust Hub",
  "vendor": "AppViewX",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Active. Quantum Trust Hub is 'a dedicated PQC module in AVX ONE CLM' (datasheet). Docs version 2026.3.0 is live with the same QTH user-guide text as 2026.2.0. AppViewX's 22 July 2026 CLM release (hybrid composite PQC certificates, MCP Server) did not name QTH. No rename or discontinuation found. A search snippet reports AppViewX was acquired by Haveli Investments in Nov 2024; this was not verified by fetch.",
    "url": "https://docs.appviewx.com/2026.3.0/quantum_trust_hub.html"
  },
  "cells": {
    "C1": {
      "score": 8.5,
      "anchor": "between 8 (5-6 surfaces with algorithm depth) and 10 (>=7 surfaces with parameter depth and PQC/hybrid)",
      "urls": [
        "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html"
      ],
      "quote": "Enabled cryptographic algorithms and protocols (for example, RSA, ECC, TLS 1.2, TLS 1.3, IPsec, SSH)",
      "rationale": "6 surfaces are documented in QTH docs: network/TLS (a), certs via CA/CT/URL (b), source code and dependencies (c), agent config scan of systems/endpoints (g), configurations (h), and SSH/IPsec (i). Key sizes and Classical/Hybrid/PQC classification are documented. Cloud (f) appears only via CLM scheduled discovery. Containers and databases are named once in a blog. HSM/KMS are not documented for QTH.",
      "delta_vs_published": 0
    },
    "C2": {
      "score": 6,
      "anchor": "6: standard-schema export documented, no integrity mechanism",
      "urls": [
        "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
        "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
        "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/"
      ],
      "quote": "industry-standard CycloneDX or CSV formats",
      "rationale": "CycloneDX (version not stated) or CSV export is documented in the vendor's PQC Assessment Tool blog. The user guide says QTH 'Auto-generates a Cryptographic Bill of Materials (CBOM)'. No signature, hash or public sample is documented in the docs pages fetched.",
      "delta_vs_published": -1
    },
    "C3": {
      "score": 5,
      "anchor": "between 4 (point-in-time scans re-run manually) and 6 (scheduled rescans with documented diff/drift reporting)",
      "urls": [
        "https://docs.appviewx.com/2026.2.0/oxy_ex/scheduled_discovery.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/monitoring_pqc_logs.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
        "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/"
      ],
      "quote": "Scheduled discovery is a discovery process execution type that lets you trigger a discovery process one/multiple times according to a predefined schedule.",
      "rationale": "Scheduled certificate discovery (CLM), a posture-trend widget and 'continuous, real-time visibility' in agent mode are documented. Diff/drift reporting, change alerts and tamper-evident history are not documented in the URLs searched. Activity logs record user actions, not asset changes.",
      "delta_vs_published": -3
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical risk levels from algorithm vulnerability plus some context",
      "urls": [
        "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/understanding_pqc.html"
      ],
      "quote": "Generates the Quantum Readiness Score, a quantitative indicator of your organization's readiness for post-quantum cryptography",
      "rationale": "Critical/High/Medium/Low severity comes from algorithm, key size and hash. A readiness score and custom business-context policies exist. No HNDL, data-lifetime or exposure factor and no formula or weights are documented in the URLs searched.",
      "delta_vs_published": -1
    },
    "C5": {
      "score": 0,
      "anchor": "0: not documented",
      "urls": [
        "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
        "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
        "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
        "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
        "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/"
      ],
      "quote": "not documented in the listed URLs (no quote available)",
      "rationale": "No accuracy metric, benchmark or false-positive handling was found in any listed URL or in a web search for AppViewX PQC assessment accuracy or false positives. The only related text is a coverage caveat: 'cryptographic libraries (limited, based on tool data availability)'. The brief's cited sources contain no accuracy evidence behind the published 6.",
      "delta_vs_published": -6
    },
    "C6": {
      "score": 7,
      "anchor": "7: ticketing plus automated remediation actions (cert rotation), credited at CLM-platform level only",
      "urls": [
        "https://docs.appviewx.com/2026.3.0/quantum_trust_hub.html",
        "https://www.appviewx.com/blogs/streamline-certificate-lifecycle-management-with-appviewx-avx-one-clm-and-servicenow/",
        "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/"
      ],
      "quote": "While remediation actions remain manual and user-driven, the platform provides contextual recommendations",
      "rationale": "QTH's own guide (2026.2.0 and 2026.3.0) says PQC remediation is manual. The host platform AVX ONE CLM documents ServiceNow northbound/southbound control, ticket closure and 'push and bind' certificate automation (Jan 2025 blog). No link from QTH findings to tickets or to CLM automation is documented, so 9 is not supported.",
      "delta_vs_published": -2
    },
    "C7": {
      "score": 7,
      "anchor": "between 6 (dashboards plus exports) and 8 (exec and technical reports with documented compliance mapping)",
      "urls": [
        "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
        "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
        "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/"
      ],
      "quote": "Generates detailed reports outlining affected algorithms, risk levels, and exposure areas",
      "rationale": "The datasheet documents a leadership overview dashboard, drill-down reports per certificate/library/service, and CycloneDX/CSV export. A mapping to named compliance frameworks (NIST IR 8547, CNSA 2.0) and a sample report are not documented in the URLs searched.",
      "delta_vs_published": 0
    }
  },
  "total": 5.95,
  "published_total": 7.58,
  "urls_that_failed": [
    "curl from the research host to docs.appviewx.com and www.appviewx.com: HTTP 403 (bot protection); all pages were then read with WebFetch",
    "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/ returned a PDF that WebFetch could not parse; the 2-page PDF was read visually",
    "https://docs.appviewx.com/2026.2.0/oxy_ex/pqc_assessment_tool.html and pqc_scans_and_outcomes.html are navigation pages with no content",
    "https://store.servicenow.com/store/app/93c9eb621b246a50a85b16db234bcb42 (page returned only its title; listing content not verifiable)"
  ],
  "notes": "Fetch method: AppViewX blocked curl (403), so every quote comes from WebFetch results that the tool returned in quotation marks. They are verbatim as far as that tool is reliable. Treat them as lower-fidelity than the curl-extracted text used for the other two products. The ServiceNow bidirectional and closed-loop evidence belongs to AVX ONE CLM (certificate lifecycle), not to QTH's PQC findings. QTH's own user guide says remediation is manual. The published C6=9 relied on 'not contradicted'; it is now contradicted by the product's own docs. The brief's S07 'delivery-pipeline agent' is supported only by a May 2025 vendor blog ('GitHub and AWS CodeBuild (GitLab and Jenkins coming soon)'); it is not in the 2026 docs pages fetched. No CycloneDX version is stated anywhere fetched. C5=0 is a large drop: it means only that no accuracy evidence was found in the 10 URLs listed plus a web search, not that the product is inaccurate."
}
