{
  "slug": "o3-security",
  "name": "O3 Security",
  "vendor": "O3 Security Inc.",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Active; CBOM/QBOM sit inside a broader software-supply-chain platform (SAST, SCA, secrets, SBOM/AIBOM/HBOM/QBOM). The CBOM page is currently positioned for India BFSI/CERT-In with 'Three sovereign data centres' (Mumbai, Chennai). No rename, acquisition or dated major release found. Docs portal (docs.o3.security) redirects to a login page.",
    "url": "https://o3.security/cryptographic-bill-of-materials"
  },
  "cells": {
    "C1": {
      "score": 7,
      "anchor": "midpoint between 6 (3-4 surfaces) and 8 (5-6 surfaces with algorithm depth); 10 claimed but capped per rubric line 19",
      "urls": [
        "https://o3.security/qbom",
        "https://o3.security/cryptographic-bill-of-materials"
      ],
      "quote": "Discovers every cryptographic algorithm across your source code, libraries, binaries, and configurations — then scores each one against Grover's and Shor's algorithms to determine quantum exposure.",
      "rationale": "QBOM page documents code, libraries, binaries and configurations; the CBOM page's 'Complete infrastructure coverage' section adds card labels for Container Images, Live Databases, Cloud Infrastructure, Hardware Security Modules, Web Servers & Network and TLS Certificates (with illustrative counts), plus example parameter output (RSA-2048, ECC-P256, ML-KEM). No per-surface mechanism documented (docs portal login-gated); hybrid detection not documented. 10 implied, capped per rubric line 19.",
      "delta_vs_published": 0
    },
    "C2": {
      "score": 6,
      "anchor": "6: standard-schema export documented, no integrity mechanism",
      "urls": [
        "https://o3.security/cryptographic-bill-of-materials",
        "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines"
      ],
      "quote": "Industry-standard formats accepted by regulators and supply-chain partners.",
      "rationale": "Sentence sits under a Standards heading followed by 'SPDX' and 'CycloneDX' labels; the CERT-In page states O3 'generates a CycloneDX CBOM'. 'Every CBOM, versioned' is versioning, not signing or hash-chaining. Signing and a public sample are not documented in the URLs searched.",
      "delta_vs_published": 0
    },
    "C3": {
      "score": 5,
      "anchor": "midpoint between 4 (point-in-time scans) and 6 (scheduled rescans with documented diff/drift reporting)",
      "urls": [
        "https://o3.security/cryptographic-bill-of-materials",
        "https://o3.security/"
      ],
      "quote": "Every CBOM, versioned. Full history of how your cryptographic posture has changed over time",
      "rationale": "Per-push CI re-generation ('Automatic on every push') and versioned history are stated, exceeding manual point-in-time scans; no diff/drift report mechanism, change alerts or tamper-evident history is documented in the URLs searched.",
      "delta_vs_published": 1
    },
    "C4": {
      "score": 7,
      "anchor": "midpoint between 6 (categorical risk levels plus context) and 8 (numeric score, >=2 factors incl. data lifetime/HNDL, ranked priority, formula not fully published)",
      "urls": [
        "https://o3.security/qbom",
        "https://o3.security/cryptographic-bill-of-materials",
        "https://o3.security/academy/qbom-quantum-bill-of-materials"
      ],
      "quote": "Ranks cryptographic assets by urgency — algorithms closest to their break-year with the widest attack surface get the highest migration priority",
      "rationale": "Break-year estimate, attack surface and an HNDL flag feed a ranked migration priority, with Critical labels and per-asset migration paths; the HNDL flag is algorithm-based and data sensitivity/lifespan appears only in a generic educational guide, not as a documented product factor. No formula published.",
      "delta_vs_published": -1
    },
    "C5": {
      "score": 0,
      "anchor": "0: not documented",
      "urls": [
        "https://o3.security/cryptographic-bill-of-materials",
        "https://o3.security/qbom",
        "https://o3.security/academy/qbom-quantum-bill-of-materials",
        "https://o3.security/",
        "https://github.com/o3security",
        "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines",
        "web search 2026-09-26: site:o3.security CBOM OR QBOM \"false positive\" OR accuracy OR precision (no hits on correctness)"
      ],
      "quote": "not documented in the URLs listed (no accuracy metric, benchmark, test methodology or false-positive handling found; docs portal login-gated)",
      "rationale": "No correctness evidence found; public GitHub repos contain no CBOM/QBOM/PQC tooling.",
      "delta_vs_published": -3
    },
    "C6": {
      "score": 4,
      "anchor": "4: remediation guidance only",
      "urls": [
        "https://o3.security/cryptographic-bill-of-materials",
        "https://o3.security/"
      ],
      "quote": "produces a CBOM and migration report in one pass",
      "rationale": "Per-asset migration paths (e.g. RSA-2048 -> ML-DSA-65, 3DES -> AES-256-GCM) are guidance; Jira appears only in the platform-wide integrations list on the homepage, with no crypto-finding ticketing, automated remediation or closure mechanism documented.",
      "delta_vs_published": -1
    },
    "C7": {
      "score": 7,
      "anchor": "midpoint between 6 (dashboards plus exports) and 8 (executive and technical reports with documented compliance mapping)",
      "urls": [
        "https://o3.security/qbom",
        "https://o3.security/cryptographic-bill-of-materials"
      ],
      "quote": "Compares your current cryptographic posture against NSA's Commercial National Security Algorithm Suite 2.0 requirements and surfaces every gap",
      "rationale": "CNSA 2.0 gap mapping and CERT-In parameters named, migration report plus JSON/CSV/CycloneDX/SPDX exports; separate executive vs technical reports, API documentation and a public sample report are not documented in the URLs searched.",
      "delta_vs_published": 0
    }
  },
  "total": 5.47,
  "published_total": 5.89,
  "urls_that_failed": [
    "https://docs.o3.security/ (307 redirect to https://app.o3.security/login - login-gated, not fetched)"
  ],
  "notes": "All O3 evidence is from vendor product/marketing pages; no public technical docs, GitHub CBOM tooling or sample artifact was found, so every cell is capped by rubric line 19 (named capability without mechanism earns at most the anchor below). The academy QBOM guide describes a generic three-layer QBOM (inventory, vulnerability class, sensitivity/lifespan) and was not credited as a product capability. The brief's S17 summary (sensitivity and data lifespan in migration priority) is not supported by the current product pages. The CBOM page quotes include UI mock rows (e.g. 'RSA-2048 auth-svc / jwt Critical Deprecated YES ML-DSA-65'), which are illustrative, not customer data. Quotes were extracted via a fetch tool and requested verbatim. Between-anchor convention: integer midpoint, both anchors named. O3 C1/C2 quotes were re-checked: the CBOM page presents surfaces and formats as card/badge labels, so the cited quotes are single contiguous sentences and the labels are described in the rationale."
}