Discovery is documented; comparable product proof remains limited.
The most useful conclusions are not small differences in rank. They are the recurring evidence, accuracy and remediation gaps across the market.
Category findings
F-01
Published accuracy measures were uncommon in the reviewed sources
In the public sources reviewed for this edition, QScout publishes its own per-detector figures. Separate research measures open-source toolchains, but those results do not establish accuracy for the scored vendor products. We did not locate comparable published product error rates for the other scored products in this source set. S23S26S28
F-02
Verifiable evidence was uncommon in the reviewed sources
In the reviewed sources, CBOM Secure claims a tamper-evident asset-change log without a specified verification mechanism; QScout publishes a signed sample CBOM for its own API, a public key and a verification procedure. Neither statement establishes signed customer-estate output for both products. S02S05
F-03
Discovery scores require mechanism and scope limits
A documented discovery surface does not establish measured detection accuracy. The final criterion matrix separates discovery breadth from evidence, correctness, risk and remediation; read each product's sources and scope before comparing scores.
F-04
Assurance and certification are outside this ranking
Certification and deployment assurance are not among the seven scored criteria. This index does not rank vendor assurance; buyers should assess those requirements separately. S11S12S13
F-05
Remediation is the criterion where QScout does not lead
The reviewed records distinguish DigiCert's Jira task/status exchange, Keyfactor's scheduled one-way ServiceNow imports, IBM's one-way ticket export and QTH's manual PQC remediation. QScout scores 6, but its published loopback proof does not demonstrate a live ticketing tenant. The frozen scores should not be read as proof of equivalent closed-loop deployment. S24S25
F-06
Re-scoring from public evidence moved every product
The publisher reports that five researchers re-read the public record for all fourteen products on 26 September 2026 and that three adversarial reviews ruled on 52 of the 98 cells, touching every product. Thirteen scores fell and one rose; the order at the top is unchanged (QScout 8.00, CBOM Secure 7.47) and the field now spans 4.68 to 8.00. S31
Where QScout is weak
Remediation loop, 6/10. The inbound HMAC receipt and the conflict-reopen rule are implemented, but no live ticketing tenant is demonstrated: every published proof runs against a loopback mock, and the public statements describe the write-back client as not deployed. S29
Change detection, 8/10. The public change window holds hourly folds of Qtonic Quantum Corp's own estate, signed and hash-chained. A real two-minute TLS monitor exists, but at verification its change events were not in the signed journal, the published drift latency measured pipeline write time rather than observation-to-materialization, and the window is not a 24-hour wall clock on a third-party estate. S27
Correctness, 6/10. The published 1,368-case corpus reports recall of 0.7628, but its labels were derived with the detector's own vocabulary, its precision is marked a construction artifact by the vendor, and no completed post-quantum handshake is in the corpus. S28
Assurance, not scored. The report states that Qtonic Quantum Corp has no company-held product certification; infrastructure-provider certifications are inherited controls, not Qtonic Quantum Corp attestations. S01
Six withdrawn Qtonic Quantum claims
These claims were previously made by Qtonic Quantum Corp or by earlier editions of this index and are contradicted by the evidence. Keeping them visible is part of the correction record.
Withdrawn claim
Correction
Sources
QScout Pulse Gold scores 9.42 (edition 2026.5)
Four of the seven cells behind 9.42 were asserted by the vendor instrument, not measured. Re-scored from public evidence, QScout is 8.00 and still first; the instrument is now cited only as a vendor self-measurement.
No enumeration of 56 probes exists in the instrument code or its published artifacts; the phrase was prose. Edition 2026.7 scores seven cells per product with archived cited URLs, excerpts and rationales. The 30 September source screen reproduced 71 excerpts, did not reproduce 20 and could not access cited sources for 7 cells.