Discovery
How broadly and deeply does the product find cryptographic assets?
Rank 5 / Established band / Confidence MOD
AppViewX / PQC discovery capability record for edition 2026.7.
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals
Research record · reviewed 2026-09-26
Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.
Weight 4/19 · 1.79 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. All five vendor documentation URLs returned 403; surface-count/depth cannot be independently checked.
Read the full review record · Cell appviewx-quantum-trust-hub/C1. This status does not independently validate the numeric score.
1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Cited sources unavailable from this check. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: 6 surfaces are documented in QTH docs: network/TLS (a), certs via CA/CT/URL (b), source code and dependencies (c), agent config scan of systems/endpoints (g), configurations (h), and SSH/IPsec (i). Key sizes and Classical/Hybrid/PQC classification are documented. Cloud (f) appears only via CLM scheduled discovery. Containers and databases are named once in a blog. HSM/KMS are not documented for QTH.
URL availability labels below reflect the historical 30 September source-access screen.
Enabled cryptographic algorithms and protocols (for example, RSA, ECC, TLS 1.2, TLS 1.3, IPsec, SSH)
Original scoring anchor: between 8 (5-6 surfaces with algorithm depth) and 10 (>=7 surfaces with parameter depth and PQC/hybrid)
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor blog/docs/datasheet returned 403; CycloneDX/CSV export claim remains unverified here.
Read the full review record · Cell appviewx-quantum-trust-hub/C2. This status does not independently validate the numeric score.
1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Cited sources unavailable from this check. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: CycloneDX (version not stated) or CSV export is documented in the vendor's PQC Assessment Tool blog. The user guide says QTH 'Auto-generates a Cryptographic Bill of Materials (CBOM)'. No signature, hash or public sample is documented in the docs pages fetched.
URL availability labels below reflect the historical 30 September source-access screen.
industry-standard CycloneDX or CSV formats
Original scoring anchor: 6: standard-schema export documented, no integrity mechanism
Weight 3/19 · 0.79 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Scheduling/drift docs returned 403; archived scheduling quote does not prove diff reporting.
Read the full review record · Cell appviewx-quantum-trust-hub/C3. This status does not independently validate the numeric score.
1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Cited sources unavailable from this check. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Scheduled certificate discovery (CLM), a posture-trend widget and 'continuous, real-time visibility' in agent mode are documented. Diff/drift reporting, change alerts and tamper-evident history are not documented in the URLs searched. Activity logs record user actions, not asset changes.
URL availability labels below reflect the historical 30 September source-access screen.
Scheduled discovery is a discovery process execution type that lets you trigger a discovery process one/multiple times according to a predefined schedule.
Original scoring anchor: between 4 (point-in-time scans re-run manually) and 6 (scheduled rescans with documented diff/drift reporting)
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Risk pages returned 403; archived readiness score does not establish the exact asset-risk anchor.
Read the full review record · Cell appviewx-quantum-trust-hub/C4. This status does not independently validate the numeric score.
1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Cited sources unavailable from this check. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Critical/High/Medium/Low severity comes from algorithm, key size and hash. A readiness score and custom business-context policies exist. No HNDL, data-lifetime or exposure factor and no formula or weights are documented in the URLs searched.
URL availability labels below reflect the historical 30 September source-access screen.
Generates the Quantum Readiness Score, a quantitative indicator of your organization's readiness for post-quantum cryptography
Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context
Weight 2/19 · 0.42 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Zero reflects no documented metric in a 403-constrained search, not evidence of no accuracy work.
Read the full review record · Cell appviewx-quantum-trust-hub/C5. This status does not independently validate the numeric score.
1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Cited sources unavailable from this check. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: No accuracy metric, benchmark or false-positive handling was found in any listed URL or in a web search for AppViewX PQC assessment accuracy or false positives. The only related text is a coverage caveat: 'cryptographic libraries (limited, based on tool data availability)'. The brief's cited sources contain no accuracy evidence behind the published 6.
Final review: 0 → 4. This is a documented product rule for accuracy handling. The product labels indeterminate detections Unknown instead of misclassifying them, which meets anchor 4 ('accuracy or false-positive handling described, no metric'), the same bar as the DigiCert and Keyfactor C5=4 precedents. No metric was found, so the published 6 is not restored. This is the weakest raise in this QC pass.
https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html ('If the cryptographic algorithm is referenced from a constant, variable, configuration, or resolved at runtime and cannot be determined through static analysis, the algorithm cannot be determined and will be marked as Unknown')
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
not documented in the listed URLs (no quote available)
Original scoring anchor: 0: not documented
Weight 2/19 · 0.74 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; archived CLM action may be adjacent-platform rather than Quantum Trust Hub behavior.
Read the full review record · Cell appviewx-quantum-trust-hub/C6. This status does not independently validate the numeric score.
1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Cited sources unavailable from this check. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: QTH's own guide (2026.2.0 and 2026.3.0) says PQC remediation is manual. The host platform AVX ONE CLM documents ServiceNow northbound/southbound control, ticket closure and 'push and bind' certificate automation (Jan 2025 blog). No link from QTH findings to tickets or to CLM automation is documented, so 9 is not supported.
URL availability labels below reflect the historical 30 September source-access screen.
While remediation actions remain manual and user-driven, the platform provides contextual recommendations
Original scoring anchor: 7: ticketing plus automated remediation actions (cert rotation), credited at CLM-platform level only
Weight 2/19 · 0.74 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor report sources returned 403; report and framework scope cannot be independently checked.
Read the full review record · Cell appviewx-quantum-trust-hub/C7. This status does not independently validate the numeric score.
1 October source-text check: Cited source unavailable in this check. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Cited sources unavailable from this check. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: The datasheet documents a leadership overview dashboard, drill-down reports per certificate/library/service, and CycloneDX/CSV export. A mapping to named compliance frameworks (NIST IR 8547, CNSA 2.0) and a sample report are not documented in the URLs searched.
URL availability labels below reflect the historical 30 September source-access screen.
Generates detailed reports outlining affected algorithms, risk levels, and exposure areas
Original scoring anchor: between 6 (dashboards plus exports) and 8 (exec and technical reports with documented compliance mapping)
Documentation reviewed 2026-09-26: Active. Quantum Trust Hub is 'a dedicated PQC module in AVX ONE CLM' (datasheet). Docs version 2026.3.0 is live with the same QTH user-guide text as 2026.2.0. AppViewX's 22 July 2026 CLM release (hybrid composite PQC certificates, MCP Server) did not name QTH. No rename or discontinuation found. A search snippet reports AppViewX was acquired by Haveli Investments in Nov 2024; this was not verified by fetch.
Archived product-status source · Source check: HTTP 403. The archived summary has not been independently revalidated in full.
Fetch method: AppViewX blocked curl (403), so every quote comes from WebFetch results that the tool returned in quotation marks. They are verbatim as far as that tool is reliable. Treat them as lower-fidelity than the curl-extracted text used for the other two products. The ServiceNow bidirectional and closed-loop evidence belongs to AVX ONE CLM (certificate lifecycle), not to QTH's PQC findings. QTH's own user guide says remediation is manual. The published C6=9 relied on 'not contradicted'; it is now contradicted by the product's own docs. The brief's S07 'delivery-pipeline agent' is supported only by a May 2025 vendor blog ('GitHub and AWS CodeBuild (GitLab and Jenkins coming soon)'); it is not in the 2026 docs pages fetched. No CycloneDX version is stated anywhere fetched. C5=0 is a large drop: it means only that no accuracy evidence was found in the 10 URLs listed plus a web search, not that the product is inaccurate.
Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes