{
  "slug": "sandboxaq-aqtive-guard",
  "name": "SandboxAQ AQtive Guard",
  "vendor": "SandboxAQ",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Still offered. Not discontinued or acquired. It has been rebranded onto its own site: sandboxaq.com/solutions/security/discover now returns 301 to aqtiveguard.com, which is branded 'Powered by SandboxAQ' and '2026 © AQtive Guard'. The product is now positioned as Cryptography Posture Management (CPM) plus AI-SPM and non-human-identity (NHI) security. The current SaaS user guide is at docs.aqtiveguard.com. The legacy guide at aqtiveguard.sandboxaq.com/docs is labelled 'for the original release of AQtive Guard'. The public changelog at docs.aqtiveguard.com/changelog/ is stale: its last entry is 25.01.1 (alpha, 2025-01-30). I found no vendor-documented major release after Aug 2026.",
    "url": "https://www.aqtiveguard.com/"
  },
  "cells": {
    "C1": {
      "score": 10,
      "anchor": "10: >=7 surfaces with algorithm+parameter depth and PQC/hybrid detection",
      "urls": [
        "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/reference/",
        "https://docs.aqtiveguard.com/data-sources/aws/",
        "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/",
        "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/supported-formats/",
        "https://docs.aqtiveguard.com/data-sources/aqg-java-tracer/",
        "https://docs.aqtiveguard.com/data-sources/crowdstrike/",
        "https://docs.aqtiveguard.com/data-sources/gitlab/",
        "https://docs.aqtiveguard.com/aqtive-scanning/"
      ],
      "quote": "TLS 1.3 - Extracts client-supported ciphersuites, elliptic curves, and signature algorithms (classic, hybrid, or PQC), along with the server’s selected ciphersuites.",
      "rationale": "Seven surfaces are documented with a mechanism: (a) network TLS through the Network Traffic Scanner and yanadump, with classic, hybrid and PQC detection; (b) certificates (X.509, ACM, Qualys, ServiceNow ingest); (d) container images and executables (Filesystem Scanner and File Inspector); (e) KMS keys ('Keys from AWS Key Management Service (KMS)'); (f) cloud crypto services (ACM, Secrets Manager, SSM, and CloudTrail consumers); (g) hosts, through the Filesystem Scanner on Linux and Windows, orchestrated by CrowdStrike or SentinelOne; (h) application runtime (the Java Code Tracer). Depth is shown by key-size rules for RSA, EC, DH and symmetric keys and by the EC group per handshake. Source code (c), through the GitLab 'AQG Static Code Scanner', is an 8th surface but is not needed to reach 7. I did not count the GitHub integration, which is AI-SPM only. I did not count SSH keys at rest as surface (i). OT/IoT (j) is not documented in the docs I searched.",
      "delta_vs_published": 2
    },
    "C2": {
      "score": 4,
      "anchor": "4: proprietary export only (CSV/PDF/JSON); a CBOM export is claimed in marketing without a documented mechanism, so it is capped one anchor below 6",
      "urls": [
        "https://docs.aqtiveguard.com/exports/",
        "https://docs.aqtiveguard.com/data-sources/cbom/",
        "https://www.aqtiveguard.com/",
        "https://aqtiveguard.sandboxaq.com/docs/fundamentals/report-fundamentals/"
      ],
      "quote": "Export the displayed data as a CSV for further analysis and reporting.",
      "rationale": "The current docs Exports page documents CSV only. The CBOM docs page covers ingest ('supports uploading ... CBOM files in JSON format'), not export. The marketing homepage claims 'Generate complete Cryptography Bills of Materials (CBOMs)', but I found no export mechanism, schema version or procedure in the docs. The legacy docs for the original release list Print (PDF), CSV and JSON. No signature or hash-chain integrity mechanism is documented. OpenCryptography.com is a public view of AQG output, but it is not a downloadable standard-schema artifact.",
      "delta_vs_published": -1
    },
    "C3": {
      "score": 6,
      "anchor": "6: scheduled/continuous rescans with documented diff/change reporting; 8 not met because no tamper-evident history is documented",
      "urls": [
        "https://docs.aqtiveguard.com/data-sources/aws/",
        "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/",
        "https://docs.aqtiveguard.com/inventory/",
        "https://aqtiveguard.sandboxaq.com/docs/projects/compare-reports/"
      ],
      "quote": "Uses CloudTrail to track changes and to discover AWS services that use these assets (for example, EC2, Lambda, API Gateway).",
      "rationale": "Continuous inputs are documented: event-driven ingestion from CloudTrail and live network monitoring with yanadump. Inventory items carry per-item 'Sessions' (last-scanned history). A side-by-side report diff ('Compare reports') is documented, but only for the original release; I did not find it in the current SaaS docs. I found no drift alerts, signed or hash-chained change history, or published detection latency.",
      "delta_vs_published": -2
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical risk levels from algorithm vulnerability plus some context",
      "urls": [
        "https://docs.aqtiveguard.com/dashboard/",
        "https://docs.aqtiveguard.com/issues/",
        "https://docs.aqtiveguard.com/impact-assessment/",
        "https://www.aqtiveguard.com/"
      ],
      "quote": "Identifies and prioritizes out-of-policy rules based on their severity (critical, high, medium, or low).",
      "rationale": "Severity is categorical and set by rule parameters. Context comes from Impact Assessment, which counts client IPs that would break on a TLS change, and from marketing claims about owners, dependencies and blast radius ('AQtive Guard maps everykey, certificate, and algorithm to its owners, dependencies, and blast radius' — typo verbatim). I found no numeric score, no data-lifetime or HNDL factor, and no published formula. The docs page on rule severity is login-walled.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 4,
      "anchor": "4: false-positive handling described, no metric",
      "urls": [
        "https://docs.aqtiveguard.com/",
        "https://www.sandboxaq.com/post/introducing-opencryptography"
      ],
      "quote": "AQG enables you to efficiently and effectively manage and secure NHIs and cryptographic assets, reducing false positives and minimizing risk.",
      "rationale": "FP handling is described. The docs mention data enrichment and exclusions. The OpenCryptography post (vendor site) says of 106 Critical/High-tagged objects 'only 10 of those were deemed to carry material risk after a data enrichment process.' No precision or recall metric, benchmark or ground truth is published. The IBM Cryptoscope paper (arXiv:2503.19531) only cites AQtive Guard and does not benchmark it.",
      "delta_vs_published": -2
    },
    "C6": {
      "score": 6.5,
      "anchor": "midpoint between 6 (one-way ticket/export plus guidance) and 7 (one-way ticket creation plus automated remediation)",
      "urls": [
        "https://docs.aqtiveguard.com/aqg-protect/",
        "https://docs.aqtiveguard.com/aqg-protect/deployment-orchestration/",
        "https://docs.aqtiveguard.com/data-sources/servicenow/",
        "https://docs.aqtiveguard.com/data-sources/gitlab/",
        "https://aqtiveguard.sandboxaq.com/docs/integrations/servicenow/",
        "https://aqtiveguard.sandboxaq.com/docs/integrations/jira/issue-export/"
      ],
      "quote": "AQG Protect addresses these challenges with features like automated short-lived certificate rotation and seamless integration, helping you mitigate risks and streamline operations.",
      "rationale": "The current docs document automated remediation: Protect provides ACME-based short-lived certificate rotation with key generation. They also document one-way GitLab merge-request comments. In the current SaaS docs, the ServiceNow integration is ingest-only. One-way ticket creation (Jira issues and ServiceNow incidents) is documented, but only for the original release; I did not find it in the current SaaS docs. That missing leg holds the score below 7. Neither version documents a bidirectional state or a reopen-on-rescan.",
      "delta_vs_published": -0.5
    },
    "C7": {
      "score": 6,
      "anchor": "6: dashboards plus exports",
      "urls": [
        "https://docs.aqtiveguard.com/dashboard/",
        "https://docs.aqtiveguard.com/exports/",
        "https://docs.aqtiveguard.com/aqg-aispm/compliance/framework-mapping/",
        "https://www.aqtiveguard.com/"
      ],
      "quote": "It highlights potential security and compliance issues, such as weak keys or expiring certificates, so you can take corrective action to protect your data foundations.",
      "rationale": "The Cryptography dashboard and CSV exports are documented. An API exists, but its reference page is login-walled. The only compliance mapping in the docs is for AI-SPM frameworks (EU AI Act, NIST AI RMF, OWASP LLM), not PQC mandates. The CNSA 2.0/NIST proof claims appear only in marketing ('Continuous compliance tracking and exportable reporting.'). No separate executive and technical reports and no published sample report are documented.",
      "delta_vs_published": 0
    }
  },
  "total": 6.37,
  "published_total": 6.68,
  "urls_that_failed": [
    "https://docs.aqtiveguard.com/api/ (login required)",
    "https://docs.aqtiveguard.com/rules/rule-severity/ (login required)",
    "https://docs.aqtiveguard.com/cryptography-rules-reference/ciphersuite_offered-quantum-vulnerable-kex-005/ (login required)",
    "https://www.hpcwire.com/aiwire/2026/03/23/sandboxaq-launches-new-aqtive-guard-capabilities/ (HTTP 403; news, inadmissible anyway)",
    "https://www.sandboxaq.com/press (fetched, but it was a thin JS shell with no release list)"
  ],
  "notes": "published_total is not stored in the brief. I computed it from the published cells [8,5,8,6,6,7,6] with the rubric weights, and all totals were computed on the research host. Half-point convention: a non-anchor score means the midpoint between the two named anchors, and each such cell names them. Evidence comes from two SandboxAQ-hosted doc sets. The current SaaS guide (docs.aqtiveguard.com) is primary. The legacy guide (aqtiveguard.sandboxaq.com/docs, 'for the original release') documents Jira/ServiceNow ticket export, PDF/CSV/JSON report export and report compare, none of which I found in the current guide. Where only the legacy guide supports a point, the cell says so and scores one step lower. The published C3=8 and C5=6 cannot be reproduced: the rubric's 8 in C3 needs a tamper-evident history, and C5 above 4 needs a published metric. I found neither in any fetched page. The 2026.6 staging note already recorded 'No signed inventory, no change log, no published accuracy', so these drops are rubric-systematic and hit all three of my products the same way, not this vendor alone. C1 moved UP, because the current docs document more surfaces and hybrid/PQC handshake detection. All quotes were checked by exact string match against the fetched page text on 2026-09-26."
}
