Discovery
How broadly and deeply does the product find cryptographic assets?
Capability instrument v4
A public-evidence capability instrument for comparing what post-quantum discovery software does - and how convincingly it can show its work.
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Each product is scored from 0 to 10 per criterion. Fifty-six probes are answered per product. A response must provide a complete enumeration, a verbatim source passage, a measured value, or a yes-or-no answer plus the mechanism that makes it true.
Admissible evidence includes product pages, technical documentation, release notes and published specifications. Analyst reports, reseller pages and press coverage are excluded from the functional score. No vendor was asked for internal data and none supplied any.
Where a capability was not located in public sources, the index records it as not documented. That is an evidence-bound statement, not proof the capability does not exist.
Certifications, install base, customer counts, deployment scale, procurement vehicles, marketplace listings, analyst placement, funding and company age are excluded. They measure vendor assurance or market presence rather than product capability.
They may still matter in procurement, so the report records them separately instead of hiding them.
When a vendor demonstrates that a cell is wrong, the cell changes, the change is logged with its date and evidence, and the index is republished. Corrections remain visible in later editions whether they help QScout or a competitor.
The source report currently contains a correction-count discrepancy: the edition summary says 11 while the methodology says 13. The standalone site records that conflict openly pending an authoritative correction.