{
  "slug": "qscout-pulse-gold",
  "name": "QScout Pulse Gold",
  "vendor": "Qtonic Quantum Corp",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Active. Public API reports service qscout-api version 4.0.0, git_sha 9497e7090e57e63df4e46809799177e7b523900c (fetched 2026-09-26T15:18Z). The vendor site names the product 'QScout Gold Pulse' (the brief says 'Pulse Gold') and states it 'carries approved evidence forward across the governed QScout tiers; it is not a fourth flagship product.' No rename, acquisition or discontinuation found.",
    "url": "https://qtonicquantum.com/qscout"
  },
  "cells": {
    "C1": {
      "score": 10,
      "anchor": "10: >=7 surfaces documented with algorithm+parameter depth and PQC/hybrid detection",
      "urls": [
        "https://qtonicquantum.com/modules",
        "https://qtonicquantum.com/cryptographic-inventory",
        "https://api.qtonicquantum.com/public/capabilities/source-depth",
        "https://api.qtonicquantum.com/public/trust/cbom.sample.json"
      ],
      "quote": "Detects hybrid TLS configurations combining classical and post-quantum key exchange mechanisms",
      "rationale": "Module catalog names 8 surfaces: TLS (a), PKI/certs (b), source-code AST (c), container images (d), KMS & Vault (e), AWS/Azure/GCP crypto config (f), database TDE (h), SSH and VPN/IPSec (i); key sizes and hybrid TLS detection documented; host agent (g) and OT (j) not documented for QScout.",
      "delta_vs_published": 0
    },
    "C2": {
      "score": 10,
      "anchor": "10: publicly downloadable signed standard-schema sample with published verification procedure",
      "urls": [
        "https://api.qtonicquantum.com/public/trust/cbom.sample.json",
        "https://api.qtonicquantum.com/public/trust/cbom.verification.json",
        "https://api.qtonicquantum.com/public/verification-key",
        "https://api.qtonicquantum.com/public/verifier-cli"
      ],
      "quote": "ML-DSA-65 detached signature over the exact UTF-8 wire bytes of the CycloneDX CBOM JSON (full document including serialNumber and metadata.timestamp). Verify with libOQS or the companion command in verify_command.",
      "rationale": "CycloneDX 1.7 sample, detached ML-DSA-65 signature, public key and verify command all public. Independently verified on 2026-09-26: SHA-256 matched, signature verified with liboqs, and a 1-bit tamper failed verification.",
      "delta_vs_published": 0
    },
    "C3": {
      "score": 9,
      "anchor": "9: event-sourced, tamper-evident change history with a PUBLISHED detection latency",
      "urls": [
        "https://qtonicquantum.com/cryptographic-inventory",
        "https://api.qtonicquantum.com/public/trust/pulse",
        "https://api.qtonicquantum.com/public/trust/pulse-changes",
        "https://qtonicquantum.com/modules"
      ],
      "quote": "QScout Gold Pulse performs ongoing governed checks for cryptographic drift, new deployments, and configuration changes within approved scope.",
      "rationale": "Signed, hash-chained event log with published per-source latencies. Independently checked 500 events: all 499 prev_sha256 links match; event hashes recompute and ML-DSA-65 signatures verify for all 490 signed events. 10 events (2026-09-20) are unsigned with sign_error. Estate is the vendor's own, so 10 is not met.",
      "delta_vs_published": 0
    },
    "C4": {
      "score": 9,
      "anchor": "between 8 and 10: full formula and weights published with all required factors, but ranked per-asset priority is not produced by that model",
      "urls": [
        "https://qtonicquantum.com/downloads/qscout-hndl-methodology.md",
        "https://api.qtonicquantum.com/public/trust/hndl",
        "https://qtonicquantum.com/cryptographic-inventory"
      ],
      "quote": "HNDL_Score = min(100, Sigma(Factor_i_Weight * Factor_i_Score_Normalized))",
      "rationale": "The 7-factor model (data sensitivity 25, future decrypt risk 20, adversary 20, timeline 15, targeting 10, hygiene 5, retention 5) is published but defined per organization. The per-system ranking uses a different 30/25/20/25 four-factor scheme with no shelf-life factor. Score below 10.",
      "delta_vs_published": -1
    },
    "C5": {
      "score": 8,
      "anchor": "8 (second branch): external corpus n>=1000 with published recall",
      "urls": [
        "https://api.qtonicquantum.com/public/trust/accuracy-metrics",
        "https://api.qtonicquantum.com/public/trust/accuracy-corpus",
        "https://api.qtonicquantum.com/public/trust/independent-corpus"
      ],
      "quote": "\"ground_truth_kind\":\"source_table_plus_detector\",\"independent_dual_annotator\":false,\"recall\":0.7628,\"f1\":0.8655,\"case_count\":1368",
      "rationale": "Rests on the fetchable per-case /accuracy-corpus, not the /accuracy-metrics number: recall 0.7628 recomputed (tp 550, fn 171, tn 647, fp 0). Labels are partly detector-derived (not independent), which rules out 10 and 8's first branch. 9 fails: 8 of 9 OQS handshakes have handshake_ok=false.",
      "delta_vs_published": 0
    },
    "C6": {
      "score": 8,
      "anchor": "8: bidirectional integration or inbound state machine implemented and documented, but no live demonstration",
      "urls": [
        "https://qtonicquantum.com/integrations",
        "https://api.qtonicquantum.com/public/trust/workflow",
        "https://api.qtonicquantum.com/public/trust/workflow/inbound",
        "https://api.qtonicquantum.com/public/trust/closed-loop-harness"
      ],
      "quote": "verify_closure checks ticket status against rescan exposure. Presence of the vulnerability with a closed ticket is a conflict, not a pass.",
      "rationale": "Inbound HMAC endpoint and conflict rule are documented, and closure is verified by rescan. The public harness is a recorded fixture (live_tenant=false). Outbound connectors default to dry-run. Remediation artifacts are never auto-applied.",
      "delta_vs_published": 0
    },
    "C7": {
      "score": 10,
      "anchor": "10: role-specific exec and technical reports, compliance mappings, export plus API, published sample report",
      "urls": [
        "https://qtonicquantum.com/qscout/sample-report",
        "https://qtonicquantum.com/qscout",
        "https://api.qtonicquantum.com/public/trust/framework-inventory",
        "https://api.qtonicquantum.com/public/trust/board-pack",
        "https://api.qtonicquantum.com/openapi-public.json"
      ],
      "quote": "Findings can map to a scoped subset of 15 enterprise framework families. A mapping is evidence context, never a certification claim.",
      "rationale": "The public sample report has an executive summary and technical findings. The 15 named frameworks include CNSA 2.0 and SP 800-131A, and NIST IR 8547 is cited in the HNDL model. JSON/SARIF/PDF/CBOM exports and a public OpenAPI exist. Board/CISO/engineering role views exist.",
      "delta_vs_published": 0
    }
  },
  "total": 9.26,
  "published_total": 9.42,
  "urls_that_failed": [
    "https://qtonicquantum.com/downloads (HTTP 404; individual files under /downloads/ do load)",
    "https://api.qtonicquantum.com/public/trust/ (trailing slash: connect timeout; /public/trust without slash loads)",
    "curl from the research host (OpenSSL 3.0.13) to qtonicquantum.com and api.qtonicquantum.com: TLS handshake-failure alert. Same URLs loaded with Node 22 / OpenSSL 3.5.7 and with WebFetch."
  ],
  "notes": "Conflict of interest: the index publisher makes this product. Scored on public documentation only. Every self-rating on Qtonic endpoints was ignored: v4_cell, index 9.42, competitive-score, field_total, lab_total, and the grades inside the board-pack. (1) DISCOVERABILITY: the C2/C3/C5 evidence came from enumerating /openapi-public.json (150+ routes). /api-reference lists only 4 endpoints and says signed reports, raw findings and artifact downloads are not public routes, so a buyer following the documented path would not reach this evidence. (2) C2: the signed sample is a 13-component CBOM of the API's own crypto, flagged 'qscout:sample-not-estate-cbom'. It is not a customer-estate Gold CBOM. The /public/trust/cbom endpoint carries only a SHA-256 header; the signed copy is cbom.sample.json. (3) C3: all 500 public change events have before=null and carry only host/account identifiers, no crypto-level diff. 119 of 500 are 'watch tick' or 'dogfood estate tick' heartbeats labelled configuration_change. So the public log is a signed observation log, not a diff record. The headline drift latency (p50 0.022 s) is pipeline time, not detection time ('not collector ingest SLO'). Per-source detection samples: repository webhook n=500, CT n=5, cloud audit n=5. The estate is Qtonic's own. (4) C4: the site publishes two inconsistent weight sets: the 7-factor HNDL model (25/20/20/15/10/5/5) and the 4-factor CBOM prioritization (30/25/20/25). (5) C5: 1,056 of 1,368 cases are IANA registry rows; the rest are 122 trust-store, 97 crt.sh (Qtonic's own domains), 64 badssl, 18 badssl-live, 9 OQS and 2 live. Only two capabilities are covered: tls_surface and cert_expiry. Precision 1.0 is flagged by the vendor as a 'construction_artifact'. The 8 is a literal reading of the anchor; a stricter reading of independence would give 6. (6) C7: the role views differ only by a few projected JSON fields. The sample report is an HTML demo with fictional data. The competitive-score gaps list 'requester signed PDF is unavailable on this SHA'. (7) C6: /integrations says connectors are 'one-way creation today', while /public/trust/workflow says connectors_are_one_way:false; the pages contradict each other. Verification work ran on the research host. Files are in the research working directory (8) C3 verification detail: the event_sha256 canonicalization rule is not published. It was recovered by trial: sorted-key compact JSON excluding event_sha256, ml_dsa65_signature, materialized_at, ml_dsa65_verify_key_sha256 and signed. So a stranger can check the chain links and signatures but must guess the hash rule, which weakens the brief's 'verifiable by a stranger' strength line. Ten events at indices 10-19 (observed 2026-09-20T14:31Z) carry signed=false with a sign_error field, even though /public/trust/pulse reports unsigned_legacy_count 0 for its 24h window. (9) C5 hinge: the per-case 'detected' field is the vendor's own detector output. A reviewer can recompute the arithmetic from the artifact but cannot re-run the detection."
}
