Discovery
How broadly and deeply does the product find cryptographic assets?
Rank 1 / Leading band / Confidence DEEP
Qtonic Quantum Corp / PQC discovery capability record for edition 2026.7.
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals
Research record · reviewed 2026-09-26
Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.
Weight 4/19 · 1.68 points of the overall score
Internal 1 October claim review: Partial or qualified support. Vendor modules document eight surfaces but active production coverage and parameter depth across all eight are not demonstrated.
Read the full review record · Cell qscout-pulse-gold/C1. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: Module catalog names 8 surfaces: TLS (a), PKI/certs (b), source-code AST (c), container images (d), KMS & Vault (e), AWS/Azure/GCP crypto config (f), database TDE (h), SSH and VPN/IPSec (i); key sizes and hybrid TLS detection documented; host agent (g) and OT (j) not documented for QScout.
Final review: 10 → 8. Anchor 10 requires >=7 surfaces WITH algorithm+parameter depth and PQC/hybrid detection. Parameter depth (e.g. RSA-2048) and hybrid/PQC detection are documented only for TLS/certificates. SSH and IKE get 'quantum-vulnerable' detection, not PQC. The other surfaces are one-line catalog entries with no mechanism, and the vendor says specifications come only in a sales engagement. Several 'surfaces' ingest customer-provided snapshots rather than discover assets. About 6 surfaces have algorithm-level wording (a,b,c,d,e,i), which fits anchor 8 (5-6 surfaces with algorithm depth). Host agent (g) and OT (j) were not documented. Symmetry check: CBOM Secure's datasheet documents per-surface detail (PKCS#11 HSMs, 7 languages and 70+ libraries, binary scanning, 'Agents for depth, agentless for reach', 'hybrid TLS (X25519MLKEM768) detected in production'), so its 10 survives the same rule.
https://qtonicquantum.com/modules: 'All 74 catalog modules shown. Full module specifications available during sales engagement.' Every surface has a one-line entry, e.g. 'KMS & Vault Inventory: Summarizes KMS and Vault key metadata -- assesses key age, rotation posture, and algorithm strength', 'TLS Termination Mapper: Parses TLS termination configuration snapshots', 'Service Mesh Crypto Mapper: Summarizes mesh crypto posture from provided config snapshots', 'Cloud Metadata Collector: Summarizes cloud assets from provided metadata snapshots'. https://api.qtonicquantum.com/public/capabilities/source-depth: languages count 5; 'libraries':{'status':'unpublished'}, 'function_patterns':{'status':'unpublished'}. https://qtonicquantum.com/downloads/qscout-hndl-methodology.md line 535: 'Future Decrypt Risk (20%) | Directly measured from TLS cipher suites, certificate key types, key exchange algorithms'.
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
Detects hybrid TLS configurations combining classical and post-quantum key exchange mechanisms
Original scoring anchor: 10: >=7 surfaces documented with algorithm+parameter depth and PQC/hybrid detection
Weight 3/19 · 1.42 points of the overall score
Internal 1 October claim review: Narrow public artifact checked. Separate public 13-component own-API CBOM sample was schema/signature/tamper checked; this is not an estate Gold native scan.
Read the full review record · Cell qscout-pulse-gold/C2. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: CycloneDX 1.7 sample, detached ML-DSA-65 signature, public key and verify command all public. Independently verified on 2026-09-26: SHA-256 matched, signature verified with liboqs, and a 1-bit tamper failed verification.
Final review: 10 → 9. The signature is real and verifiable by an outsider with OpenSSL 3.5, so the claim is above 8. It sits clearly between 8 and 10: the signed file is a self-inventory of the vendor's own API ('sample-not-estate-cbom'), not a sample of what the product produces for a scanned estate. No documentation page links to it, and the API reference says the opposite. The public product pages also disagree about the export format (JSON/SARIF on cryptographic-inventory versus CycloneDX 1.7 on /qscout).
https://api.qtonicquantum.com/public/trust/cbom.sample.json is 'CycloneDX 1.7 13' components, with metadata.component 'qscout-api ... internal crypto surface (algorithms, protocols, and related material that the service itself implements)', and properties 'qscout:sample-not-estate-cbom=true' and 'qscout:not=estate-scale Gold CBOM'. sha256 06e2fcec...883c3 equals cbom.verification.json cbom_sha256 and is stable across two fetches. Independent verification with stock OpenSSL 3.5.7 (no liboqs), after wrapping the 1952-byte key in an ML-DSA-65 SPKI: 'Signature Verified Successfully'; a 1-bit flip gives 'Signature Verification Failure'. /api-reference: 'signed reports ... are not exposed as anonymous public routes'. /cryptographic-inventory: 'CBOM data exports to JSON and SARIF formats'.
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
ML-DSA-65 detached signature over the exact UTF-8 wire bytes of the CycloneDX CBOM JSON (full document including serialNumber and metadata.timestamp). Verify with libOQS or the companion command in verify_command.
Original scoring anchor: 10: publicly downloadable signed standard-schema sample with published verification procedure
Weight 3/19 · 1.26 points of the overall score
Internal 1 October claim review: Partial or qualified support. Public 500-event hash chain/signatures are inspectable, but 10 unsigned events, before=null and heartbeat labels limit cryptographic drift proof.
Read the full review record · Cell qscout-pulse-gold/C3. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: Signed, hash-chained event log with published per-source latencies. Independently checked 500 events: all 499 prev_sha256 links match; event hashes recompute and ML-DSA-65 signatures verify for all 490 signed events. 10 events (2026-09-20) are unsigned with sign_error. Estate is the vendor's own, so 10 is not met.
Final review: 9 → 8. Three independent reasons 9 fails. (1) The endpoint cited for the latency and chain labels itself 'not_gold_pulse', so it belongs to a different product than the one scored. (2) The 'change history' holds no change content: all 500 events have before=null and host-level 'after' fields, with no crypto diff. (3) The headline latency is pipeline time by the vendor's own note, and the detection samples are n=5. Anchor 8 is met: scheduled and event-triggered monitoring with drift reporting is documented, and a signed hash chain exists. A stricter reading (history without change content is not change history) would give 6.
https://api.qtonicquantum.com/public/trust/pulse: '"product":"qscout_pulse","not_gold_pulse":true', 'dogfood':true, 'third_party_customer':false, 'real_time':false, drift_latency note 'not collector ingest SLO', per-source cloud_audit_event and certificate_transparency sample_count 5 each. https://api.qtonicquantum.com/public/trust/pulse-changes: 500 changes, python Counter of before-is-null gives 'Counter({True: 500})'. A sample event has after={'host':'qtonicquantum.com','customer_estate':true,'third_party_customer':false}. https://qtonicquantum.com/qscout/pulse: 'scheduled reassessment, event-triggered updates when a certificate rotates or a domain appears, and drift reporting when posture regresses'.
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
QScout Gold Pulse performs ongoing governed checks for cryptographic drift, new deployments, and configuration changes within approved scope.
Original scoring anchor: 9: event-sourced, tamper-evident change history with a PUBLISHED detection latency
Weight 3/19 · 1.42 points of the overall score
Internal 1 October claim review: Partial or qualified support. Published seven-factor model is organization-level while per-asset priority uses different factors; final nine is a contestable interpolation.
Read the full review record · Cell qscout-pulse-gold/C4. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: The 7-factor model (data sensitivity 25, future decrypt risk 20, adversary 20, timeline 15, targeting 10, hygiene 5, retention 5) is published but defined per organization. The per-system ranking uses a different 30/25/20/25 four-factor scheme with no shelf-life factor. Score below 10.
URL availability labels below reflect the historical 30 September source-access screen.
HNDL_Score = min(100, Sigma(Factor_i_Weight * Factor_i_Score_Normalized))
Original scoring anchor: between 8 and 10: full formula and weights published with all required factors, but ranked per-asset priority is not produced by that model
Weight 2/19 · 0.63 points of the overall score
Internal 1 October claim review: Partial or qualified support. Public corpus arithmetic recomputes but labels are partly detector-derived, legacy, and narrow; it is not an independently adjudicated product miss rate.
Read the full review record · Cell qscout-pulse-gold/C5. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: Rests on the fetchable per-case /accuracy-corpus, not the /accuracy-metrics number: recall 0.7628 recomputed (tp 550, fn 171, tn 647, fp 0). Labels are partly detector-derived (not independent), which rules out 10 and 8's first branch. 9 fails: 8 of 9 OQS handshakes have handshake_ok=false.
Final review: 8 → 6. The rubric NOTE says detector-in-label ground truth is NOT independent, and anchor 6 names exactly this case ('ground truth not independent'). Anchor 8's second branch drops the independence requirement and contradicts both. Default-to-lower resolves this to 6. Substance: 77% of cases classify IANA registry rows (a table lookup, not discovery), 97 cases are the vendor's own certificates, and only 2 of 7 claimed capabilities are measured.
https://api.qtonicquantum.com/public/trust/accuracy-corpus: case_count 1368, precision 1.0, recall 0.7628. Sources: tls-signaturescheme.csv 538, tls-parameters-4.csv 448, tls-parameters-8.csv 70 (1,056 IANA registry rows), badssl 82, crt.sh %.qryptonic.com 71 and %.qtonicquantum.com 26 (the vendor's own domains), test.openquantumsafe.org 9. Capabilities: tls_surface 1246, cert_expiry 122. A sample case: 'ground_truth':'positive','signal':'tls-ciphersuites TLS_NULL_WITH_NULL_NULL','detected':false.
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
"ground_truth_kind":"source_table_plus_detector","independent_dual_annotator":false,"recall":0.7628,"f1":0.8655,"case_count":1368
Original scoring anchor: 8 (second branch): external corpus n>=1000 with published recall
Weight 2/19 · 0.63 points of the overall score
Internal 1 October claim review: Partial or qualified support. Inbound closure rule is documented/fixture-tested; public harness is not a live tenant and outbound integration defaults dry-run.
Read the full review record · Cell qscout-pulse-gold/C6. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: Inbound HMAC endpoint and conflict rule are documented, and closure is verified by rescan. The public harness is a recorded fixture (live_tenant=false). Outbound connectors default to dry-run. Remediation artifacts are never auto-applied.
Final review: 8 → 6. Under the admissibility rule, the vendor's two linked product pages say one-way and control over an unlinked route. Anchor 8 (bidirectional or inbound state machine) is not established as available to customers. Anchor 7 needs automated remediation actions, and none are documented. Anchor 6 applies: one-way ticketing plus guidance. Documented rescan closure verification ('Presence of the vulnerability with a closed ticket is a conflict, not a pass') is noted as a plus but does not reach 7.
https://qtonicquantum.com/integrations: 'Connectors are one-way creation today: QScout opens or updates tickets outbound. They are dry-run by default (dry_run=true)... Bidirectional ticket-driven state and non-dry write-back are on the Workflow 10 path'. https://qtonicquantum.com/qscout: 'Workflow connectors (Jira / ServiceNow) are one-way ticket creation and dry-run by default today.' https://api.qtonicquantum.com/public/trust/workflow/inbound: 'customer_estate':false. https://api.qtonicquantum.com/public/trust/closed-loop-harness: 'mode':'recorded_http_fixture','live_tenant':false.
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
verify_closure checks ticket status against rescan exposure. Presence of the vulnerability with a closed ticket is a conflict, not a pass.
Original scoring anchor: 8: bidirectional integration or inbound state machine implemented and documented, but no live demonstration
Weight 2/19 · 0.95 points of the overall score
Internal 1 October claim review: Partial or qualified support. Public role views/framework names/API exist, but sample report is fictional and mappings are not certifications.
Read the full review record · Cell qscout-pulse-gold/C7. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: The public sample report has an executive summary and technical findings. The 15 named frameworks include CNSA 2.0 and SP 800-131A, and NIST IR 8547 is cited in the HNDL model. JSON/SARIF/PDF/CBOM exports and a public OpenAPI exist. Board/CISO/engineering role views exist.
Final review: 10 → 9. A published sample report exists, which CBOM Secure lacks, so the claim is above 8. It is not 10: the sample is one combined report, not separate role-specific executive and technical reports. It shows no compliance mapping, and the 15 frameworks are a name list rather than a mapping. CBOM Secure publishes a per-framework table. The evidence is clearly between 8 and 10.
https://qtonicquantum.com/qscout/sample-report: 'Illustrative sample. This report uses synthetic demonstration data'. It is one document containing an 'Executive summary' and 'Top findings'. Its only framework reference is 'may not meet upcoming NIST PQC CNSA 2.0 requirements'. https://api.qtonicquantum.com/public/trust/framework-inventory: a list of 15 framework names with no control mapping. https://api.qtonicquantum.com/public/trust/board-pack: 'sample':true, role_views board/ciso/engineering, and embedded self-ratings 'field_total':9.3,'lab_total':9.54 (inadmissible). https://qtonicquantum.com/qscout/pulse: 'Methodology mapped to NIST IR 8547 (initial public draft) / FIPS 203-205 / CNSA 2.0'.
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
Findings can map to a scoped subset of 15 enterprise framework families. A mapping is evidence context, never a certification claim.
Original scoring anchor: 10: role-specific exec and technical reports, compliance mappings, export plus API, published sample report
Documentation reviewed 2026-09-26: Active. Public API reports service qscout-api version 4.0.0, git_sha 9497e7090e57e63df4e46809799177e7b523900c (fetched 2026-09-26T15:18Z). The vendor site names the product 'QScout Gold Pulse' (the brief says 'Pulse Gold') and states it 'carries approved evidence forward across the governed QScout tiers; it is not a fourth flagship product.' No rename, acquisition or discontinuation found.
Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.
Conflict of interest: the index publisher makes this product. Scored on public documentation only. Every self-rating on Qtonic endpoints was ignored: v4_cell, index 9.42, competitive-score, field_total, lab_total, and the grades inside the board-pack. (1) DISCOVERABILITY: the C2/C3/C5 evidence came from enumerating /openapi-public.json (150+ routes). /api-reference lists only 4 endpoints and says signed reports, raw findings and artifact downloads are not public routes, so a buyer following the documented path would not reach this evidence. (2) C2: the signed sample is a 13-component CBOM of the API's own crypto, flagged 'qscout:sample-not-estate-cbom'. It is not a customer-estate Gold CBOM. The /public/trust/cbom endpoint carries only a SHA-256 header; the signed copy is cbom.sample.json. (3) C3: all 500 public change events have before=null and carry only host/account identifiers, no crypto-level diff. 119 of 500 are 'watch tick' or 'dogfood estate tick' heartbeats labelled configuration_change. So the public log is a signed observation log, not a diff record. The headline drift latency (p50 0.022 s) is pipeline time, not detection time ('not collector ingest SLO'). Per-source detection samples: repository webhook n=500, CT n=5, cloud audit n=5. The estate is Qtonic's own. (4) C4: the site publishes two inconsistent weight sets: the 7-factor HNDL model (25/20/20/15/10/5/5) and the 4-factor CBOM prioritization (30/25/20/25). (5) C5: 1,056 of 1,368 cases are IANA registry rows; the rest are 122 trust-store, 97 crt.sh (Qtonic's own domains), 64 badssl, 18 badssl-live, 9 OQS and 2 live. Only two capabilities are covered: tls_surface and cert_expiry. Precision 1.0 is flagged by the vendor as a 'construction_artifact'. The 8 is a literal reading of the anchor; a stricter reading of independence would give 6. (6) C7: the role views differ only by a few projected JSON fields. The sample report is an HTML demo with fictional data. The competitive-score gaps list 'requester signed PDF is unavailable on this SHA'. (7) C6: /integrations says connectors are 'one-way creation today', while /public/trust/workflow says connectors_are_one_way:false; the pages contradict each other. Verification work ran on the research host. Files are in the research working directory (8) C3 verification detail: the event_sha256 canonicalization rule is not published. It was recovered by trial: sorted-key compact JSON excluding event_sha256, ml_dsa65_signature, materialized_at, ml_dsa65_verify_key_sha256 and signed. So a stranger can check the chain links and signatures but must guess the hash rule, which weakens the brief's 'verifiable by a stranger' strength line. Ten events at indices 10-19 (observed 2026-09-20T14:31Z) carry signed=false with a sign_error field, even though /public/trust/pulse reports unsigned_legacy_count 0 for its 24h window. (9) C5 hinge: the per-case 'detected' field is the vendor's own detector output. A reviewer can recompute the arithmetic from the artifact but cannot re-run the detection.
Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes