Capability instrument v4

How every number was produced

A public-evidence capability instrument for comparing what post-quantum discovery software does - and how convincingly it can show its work.

Seven weighted criteria

C121.05%

Discovery

How broadly and deeply does the product find cryptographic assets?

C215.79%

Evidence artifact

Does it produce a portable, verifiable record of what was found?

C510.53%

Correctness

Is detection accuracy measured against named ground truth?

C610.53%

Remediation loop

Can a finding move through ownership, action and verified closure?

C710.53%

Reporting

Can technical and executive readers understand and reuse the result?

Evidence standard

Each product is scored from 0 to 10 per criterion. Fifty-six probes are answered per product. A response must provide a complete enumeration, a verbatim source passage, a measured value, or a yes-or-no answer plus the mechanism that makes it true.

Admissible evidence includes product pages, technical documentation, release notes and published specifications. Analyst reports, reseller pages and press coverage are excluded from the functional score. No vendor was asked for internal data and none supplied any.

Not documented is not absent

Where a capability was not located in public sources, the index records it as not documented. That is an evidence-bound statement, not proof the capability does not exist.

Evidence and confidence classes

Evidence L
Live public endpoint fetched on the verification date
Evidence D
Vendor-published technical documentation
Evidence T
Independent third-party technical source
Evidence E
Estimated with incomplete probe coverage
Confidence DEEP
56 answered probes plus live, hash-bound evidence
Confidence MOD
Multiple sourced pages including primary technical evidence
Confidence THIN
One documentation pass with material uncertainty

Excluded from the functional score

Certifications, install base, customer counts, deployment scale, procurement vehicles, marketplace listings, analyst placement, funding and company age are excluded. They measure vendor assurance or market presence rather than product capability.

They may still matter in procurement, so the report records them separately instead of hiding them.

Correction policy

When a vendor demonstrates that a cell is wrong, the cell changes, the change is logged with its date and evidence, and the index is republished. Corrections remain visible in later editions whether they help QScout or a competitor.

The source report currently contains a correction-count discrepancy: the edition summary says 11 while the methodology says 13. The standalone site records that conflict openly pending an authoritative correction.