{
  "slug": "tychon-quantum-command",
  "name": "TYCHON Quantum Command",
  "vendor": "TYCHON",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "No rename, acquisition or discontinuation was found, and the product page still titles it 'TYCHON Quantum Command'. Two changes: TYCHON's ACDI technology is being integrated into HCL BigFix (tychon.io post dated 25 Feb 2026), and an Elastic 'tychon_quantum_command' integration package, v0.1.0 type partner, is an open, unmerged PR (elastic/integrations#20142, opened 2026-07-15, last updated 2026-09-23). No new major Quantum Command release since Aug 2026 was found.",
    "url": "https://tychon.io/tychon-partners-with-hclsoftware/"
  },
  "cells": {
    "C1": {
      "score": 8,
      "anchor": "8: 5-6 surfaces with algorithm depth (10 needs >=7 surfaces)",
      "urls": [
        "https://tychon.io/products/tychon/pqc-management-module/",
        "https://tychon.io/tychoncryptographicinventory/",
        "https://github.com/elastic/integrations/pull/20142"
      ],
      "quote": "ACDI Sniffer analyzes packet capture data to identify cryptographic protocols, algorithms, certificates, and network services without installing software on the systems being observed.",
      "rationale": "Surfaces backed by a fetched quote: (a) passive network through ACDI Sniffer; (b) certificates; (d) crypto libraries and archives; (g) endpoints; (i) VPN clients, IPsec and MACsec; (j) OT and IoT. The product page states 'detects both hybrid and pure post-quantum cryptographic implementations'. The partner Elastic schema has key_length_bits and pqc_algos. Containers and cloud storage (the brief's S11) were not found on current pages and were not counted, and source code, HSM and cloud KMS are not documented.",
      "delta_vs_published": 0
    },
    "C2": {
      "score": 5,
      "anchor": "between 4 and 6: proprietary NDJSON/JSON output documented; CycloneDX CBOM named once on a product page with no version, schema detail or sample",
      "urls": [
        "https://tychon.io/tychoncryptographicinventory/",
        "https://github.com/elastic/integrations/pull/20142",
        "https://tychon.io/products/tychon/pqc-management-module/"
      ],
      "quote": "Complete Inventory: CBOM (CycloneDX) format",
      "rationale": "The only CBOM evidence is one product-page line. The partner Elastic package documents NDJSON/JSON output, and its fields.yml has no CBOM field (grep for 'cbom' returned no match). Signing or integrity is not documented on the product page, the cryptographic-inventory page or the Elastic PR.",
      "delta_vs_published": -1
    },
    "C3": {
      "score": 4,
      "anchor": "4: marketing claim of continuous change alerting with no documented mechanism caps below anchor 6",
      "urls": [
        "https://tychon.io/use-cases/quantumreadiness/",
        "https://tychon.io/products/tychon/pqc-management-module/",
        "https://tychon.io/tychoncryptographicinventory/",
        "https://github.com/elastic/integrations/pull/20142"
      ],
      "quote": "Understand, analyze, and score your risk posture – monitor, trace, and alert on cryptographic inventory changes.",
      "rationale": "Vendor pages claim real-time endpoint monitoring, change alerts and an 'Audit trail', but give no mechanism, schedule or diff report. The only technical artifact is the Elastic package, which upserts current state ('rescans update the same entity record'). That is not a change history. Tamper-evident history is not documented. The published 8 was carried unchanged from 2026.4 after a 403.",
      "delta_vs_published": -4
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical risk levels from algorithm vulnerability plus some context",
      "urls": [
        "https://tychon.io/products/tychon/pqc-management-module/",
        "https://tychon.io/tychoncryptographicinventory/",
        "https://github.com/elastic/integrations/pull/20142"
      ],
      "quote": "Automatically generate the cryptographic inventories required under OMB M-26-15, H.R. 7535 and M-23-02, with built-in risk scoring and audit-ready reporting.",
      "rationale": "Vendor pages name a '100-point scoring system'. The Elastic schema has quantum_risk, risk_level and overall_score fields. The factors, weights, data lifetime and HNDL are not documented, so anchor 8 is not met.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 0,
      "anchor": "0: not documented",
      "urls": [
        "https://tychon.io/products/tychon/pqc-management-module/",
        "https://tychon.io/cryptographic-inventory/",
        "https://tychon.io/tychoncryptographicinventory/",
        "https://tychon.io/use-cases/quantumreadiness/",
        "https://tychon.io/implementing-quantum-safe-cryptographic-discovery-in-your-ci-cd-pipeline-part-8-of-8/",
        "https://github.com/elastic/integrations/pull/20142"
      ],
      "quote": "Be prepared to handle false positives. Some legitimate uses of these algorithms may be flagged.",
      "rationale": "Accuracy metrics, benchmarks and product false-positive handling were not found in the URLs listed, or in a web search for TYCHON Quantum Command accuracy, false positives or benchmarks. The only quote is generic advice in a 2024 vendor blog, not a product mechanism. The Elastic PR's pipeline tests check ingest parsing, not detection accuracy. The published 5 had no source.",
      "delta_vs_published": -5
    },
    "C6": {
      "score": 6,
      "anchor": "6: one-way export plus guidance (automated remediation claimed, no ticketing documented)",
      "urls": [
        "https://tychon.io/products/tychon/pqc-management-module/",
        "https://github.com/elastic/integrations/pull/20142"
      ],
      "quote": "Response Actions let you act directly from the platform, disabling weak ciphers, enforcing updated policies, and targeting your most vulnerable systems first.",
      "rationale": "Automated response actions are claimed, and export to a SIEM (Elastic, Splunk) is shown. ServiceNow or Jira ticketing, bidirectional sync and rescan-verified closure are not documented on the product page or in the Elastic PR, so anchor 7 (ticket plus automated action) is not met.",
      "delta_vs_published": 0
    },
    "C7": {
      "score": 6,
      "anchor": "6: dashboards plus exports (compliance frameworks listed as badges, mapping not documented)",
      "urls": [
        "https://tychon.io/products/tychon/pqc-management-module/",
        "https://github.com/elastic/integrations/pull/20142"
      ],
      "quote": "With TYCHON's intuitive dashboards, you can monitor the cryptographic status of every endpoint in real time.",
      "rationale": "Dashboards are documented, including partner Kibana dashboards for inventory, application, certificate and cost reports, along with JSON export. The product page lists 'M-26-15 NSM-10 H.R. 7535 NIST FIPS 203/204/205 CNSA 2.0 CISA Aligned' as badges. No documented mapping, executive versus technical reports or sample report was found, so it lands with its peers at 6.",
      "delta_vs_published": -1
    }
  },
  "total": 5.32,
  "published_total": 6.74,
  "urls_that_failed": [
    "curl from the research host to https://tychon.io/products/tychon/pqc-management-module/ returned HTTP 403 (a Cloudflare JavaScript challenge). WebFetch loaded it, so the tychon.io quotes are WebFetch-extracted and not byte-verified.",
    "https://tychon.io/wp-content/uploads/2025/12/TYCHON_Capabilities_VPM_2026_001.pdf loaded, but it is the Vulnerability & Patch Management use case and does not cover Quantum Command."
  ],
  "notes": "Confidence is THIN. There are no docs portal, datasheet, release notes, public sample or paper for Quantum Command. Evidence is vendor product pages plus an unmerged Elastic integration PR, owner type 'partner', authored by GitHub user Audience2801 with no stated affiliation, v0.1.0. That PR is the only technical artifact. It shows NDJSON/JSON output and datasets for certificates, ciphers, crypto libraries, keystores, VPN, IPsec, MACsec, archives and system readiness, with key-length and PQC fields. It was read through the GitHub API on the research host. It is not merged, so it is not shipped Elastic content. All published 2026.6 cells were carried unchanged from 2026.4 after a 403, so this is the first live re-read. C3 (-4) and C5 (-5) are large moves: neither published value had an admissible source. The HCL BigFix partnership date comes from tychon.io (25 Feb 2026); the HCL press release dates it 11 Feb 2026. PUBLISHED_TOTAL: the brief gives no total, so 6.74 is recomputed from published_cells with the rubric formula."
}
