Capability instrument public-evidence re-score

How every number was produced

A public-evidence capability instrument for comparing what post-quantum discovery software does - and how convincingly it can show its work.

Seven weighted criteria

C121.05%

Discovery

How broadly and deeply does the product find cryptographic assets?

C215.79%

Evidence artifact

Does it produce a portable, verifiable record of what was found?

C510.53%

Correctness

Is detection accuracy measured against named ground truth?

C610.53%

Remediation loop

Can a finding move through ownership, action and verified closure?

C710.53%

Reporting

Can technical and executive readers understand and reuse the result?

Evidence standard

Each product is scored from 0 to 10 per criterion. For edition 2026.7 the publisher reports that researchers scored every cell with URLs read, an archived source passage and a rationale, then three adversarial reviews could only lower or raise a cell with new evidence. The files are published under /evidence/2026-7/; the total is the weighted sum over 19.

The independent 30 September 2026 source-access screen reproduced an archived excerpt for 71 of 98 cells, found accessible sources without reproducing the excerpt for 20, and could not access cited sources for 7. This screen does not validate each complete rationale or product behavior. Inspect the dated check records.

Admissible evidence includes product pages, technical documentation, release notes and published specifications. Analyst reports, reseller pages and press coverage are excluded from the functional score. No vendor was asked for internal data and none supplied any.

Not documented is not absent

Where a capability was not located in public sources, the index records it as not documented. That is an evidence-bound statement, not proof the capability does not exist.

Evidence and confidence classes

Evidence L
Live public endpoint fetched on the verification date
Evidence D
Vendor-published technical documentation
Evidence T
Independent third-party technical source
Evidence E
Estimated where the public documentation was incomplete for a cell
Confidence DEEP
Live public endpoints plus ten or more distinct documentation sources
Confidence MOD
Six or more distinct sources including primary technical documentation
Confidence THIN
One documentation pass with material uncertainty

Excluded from the functional score

Certifications, install base, customer counts, deployment scale, procurement vehicles, marketplace listings, analyst placement, funding and company age are excluded. They measure vendor assurance or market presence rather than product capability.

They may still matter in procurement, so the report records them separately instead of hiding them.

Correction policy

When a vendor demonstrates that a cell is wrong, the cell changes, the change is logged with its date and evidence, and the index is republished. Corrections remain visible in later editions whether they help QScout or a competitor.

Edition 2026.7 (27 September 2026): the 2026.5 scores were withdrawn after an audit found that four of QScout's seven cells were asserted by the vendor instrument and that the phrase "56 probes" had no enumeration behind it. Every product was re-scored; the changes are listed under withdrawn claims and in the published evidence files.