{
  "slug": "qusecure-quprotect-r3",
  "name": "QuSecure QuProtect R3",
  "vendor": "QuSecure",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Still offered. It has not been renamed, acquired or discontinued. QuProtect R3 remains the current product; I found no R4 or successor. The site now presents R3 as three pillars: Recon (discovery), Resilience (policy-driven remediation) and Reporting (CycloneDX CBOM). The Reporting page maps output to mandates issued in June 2026 (EO 14412, OMB M-26-15). The vendor-site footer reads '© 2026 QuSecure, Inc.'",
    "url": "https://www.qusecure.com/quprotect/"
  },
  "cells": {
    "C1": {
      "score": 4,
      "anchor": "4: 1-2 surfaces (network/TLS, certificates on the wire), with algorithm, key-size and PQC depth",
      "urls": [
        "https://www.qusecure.com/recon/",
        "https://www.qusecure.com/quprotect/",
        "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/"
      ],
      "quote": "QuProtect Reconnaissance builds a live inventory of the algorithms, protocols, certificates and key sizes your systems negotiate.",
      "rationale": "The documented mechanism is passive sensors on live network traffic. They read TLS versions, key exchange, signatures, ciphers, certificates, key sizes and JA3/JA4 fingerprints, and detect PQC ('Algorithm-level detection (RSA, ECC, PQC) plus key sizes'). That covers surfaces (a) and (b). The older discovery page claims 'Routers, servers, endpoints, applications, cloud, and network infrastructure'. It names no mechanism beyond network observation, and the Recon page contrasts itself with source-code scanning. I found no documented discovery of code, binaries, HSM/KMS, cloud KMS, host configuration, SSH or IPsec. IPsec appears only as an encryptor protocol.",
      "delta_vs_published": -2
    },
    "C2": {
      "score": 6,
      "anchor": "6: standard-schema export documented, no integrity mechanism",
      "urls": [
        "https://www.qusecure.com/quprotect/",
        "https://www.qusecure.com/reporting/"
      ],
      "quote": "QuProtect Reporting generates a CycloneDX v1.6 cryptographic bill of materials from the live inventory the sensors build, on demand and in machine-readable form.",
      "rationale": "A CycloneDX v1.6 CBOM export is documented. I found no signature, hash chain, public sample or verification procedure on the fetched pages.",
      "delta_vs_published": 0
    },
    "C3": {
      "score": 6,
      "anchor": "6: continuous inventory with documented change reporting; 8 not met because no tamper-evident history is documented",
      "urls": [
        "https://www.qusecure.com/reporting/",
        "https://www.qusecure.com/recon/"
      ],
      "quote": "Reports generate on demand from the inventory, which updates continuously from live traffic.",
      "rationale": "The inventory is continuous. Reports show 'What is in and out of policy, and what changed', and the Recon page says configuration drift is found. I found no drift alert mechanism, signed or hash-chained change history, or published detection latency.",
      "delta_vs_published": -2
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical/ranked risk from algorithm vulnerability plus exposure context",
      "urls": [
        "https://www.qusecure.com/quprotect/",
        "https://www.qusecure.com/recon/"
      ],
      "quote": "Find where legacy cryptography is still in use, on live network traffic, ranked by exposure rather than by count.",
      "rationale": "Findings are ranked by exposure. I found no numeric score, no documented data-lifetime or HNDL factor, and no formula. The Resilience page names HNDL only as a finding class to remediate, not as a scoring input.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 0,
      "anchor": "0: not documented",
      "urls": [
        "https://www.qusecure.com/quprotect/",
        "https://www.qusecure.com/recon/",
        "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/",
        "https://www.qusecure.com/reporting/",
        "https://www.qusecure.com/frequently-asked-questions-faqs/",
        "https://www.qusecure.com/cryptographic-bill-of-materials-cbom/"
      ],
      "quote": "The inventory is always accurate, and your compliance posture is always current.",
      "rationale": "The fetched pages give accuracy only as an adjective. Accuracy metrics, false-positive handling and benchmarks are not documented in the URLs searched. The Recon page gives a design argument that wire observation beats code scanning ('Source code tells you what an application might negotiate.'). That is a rationale, not an accuracy-handling mechanism or a metric. The Army TRL-7 item is third-party news or certification and is inadmissible.",
      "delta_vs_published": -6
    },
    "C6": {
      "score": 6.5,
      "anchor": "midpoint between 6 (one-way export plus guidance) and 7 (one-way ticket creation plus automated remediation)",
      "urls": [
        "https://www.qusecure.com/recon/",
        "https://www.qusecure.com/resilience/",
        "https://www.qusecure.com/quprotect/"
      ],
      "quote": "An administrator sets a policy in the Orchestrator. Encryptors carry the connection over post-quantum TLS 1.3 at the network layer, with no application code change, and the inventory records the fix in the next CBOM export.",
      "rationale": "Automated remediation is strongly documented: policy-driven algorithm change and automated certificate provisioning and rotation. Closure is recorded in the next export ('The finding, the policy change, the result'). Ticket creation is not documented. The only outbound integration named is 'Integrations: select vulnerability scanners, SIEM and SOAR', so anchor 7's ticket leg is unmet.",
      "delta_vs_published": 0.5
    },
    "C7": {
      "score": 8,
      "anchor": "8: executive and technical reporting with documented compliance mapping",
      "urls": [
        "https://www.qusecure.com/reporting/"
      ],
      "quote": "Reports export on demand in machine-readable and human-readable form, covering the cryptography in use, the policy in force and the record of changes",
      "rationale": "The Reporting page has a mapping table ('Mapped to the instruments you answer to') covering OMB M-26-15, EO 14412, CNSA 2.0, NIST IR 8547, PCI DSS 4.0 12.3.3 and DORA. It names board/executive reporting ('Visibility into cryptographic posture for risk committees and executives') and per-connection technical detail. I found no published sample report, so 10 is not reached.",
      "delta_vs_published": 0
    }
  },
  "total": 5.21,
  "published_total": 6.53,
  "urls_that_failed": [],
  "notes": "published_total is not stored in the brief. I computed it from the published cells [6,6,8,6,6,6,8] with the rubric weights. Half-point convention: 6.5 is the midpoint between the named anchors. QuSecure publishes no public docs portal or datasheet that I could find; all evidence is from vendor product pages on qusecure.com, which are unusually specific (algorithms, protocols, CycloneDX version, mandate table). C6: the rubric is ticket-centric. QuSecure documents actual automated remediation with closure recorded in the next export, which is arguably stronger in substance than ticketing, but the rubric's ticket leg is not documented. A reviewer who treats SOAR integration as ticket creation would score 7. C5 was published at 6, but I found no methodology, metric or FP-handling description on any fetched page. C3 dropped for the same reason as for the other products: continuous monitoring is documented, tamper-evident history is not. These C3/C5 drops are rubric-systematic across all three products I scored. All quotes were checked by exact string match against the fetched page text on 2026-09-26."
}
