Rank 6 / Established band / Confidence MOD

SandboxAQ AQtive Guard

SandboxAQ / PQC discovery capability record for edition 2026.7.

6.21Index score / 10[1]

Reviewed SaaS documentation describes broad discovery and continuous inputs; Protect documents ACME-based certificate rotation. S12

Established MOD

Seven criterion scores

C110

Discovery

How broadly and deeply does the product find cryptographic assets?

C54

Correctness

Is detection accuracy measured against named ground truth?

C66.5

Remediation loop

Can a finding move through ownership, action and verified closure?

C76

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

10 / 10

Weight 4/19 · 2.11 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor docs support broad discovery and hybrid TLS, but all seven-plus surfaces/depth are not jointly validated in one test.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Seven surfaces are documented with a mechanism: (a) network TLS through the Network Traffic Scanner and yanadump, with classic, hybrid and PQC detection; (b) certificates (X.509, ACM, Qualys, ServiceNow ingest); (d) container images and executables (Filesystem Scanner and File Inspector); (e) KMS keys ('Keys from AWS Key Management Service (KMS)'); (f) cloud crypto services (ACM, Secrets Manager, SSM, and CloudTrail consumers); (g) hosts, through the Filesystem Scanner on Linux and Windows, orchestrated by CrowdStrike or SentinelOne; (h) application runtime (the Java Code Tracer). Depth is shown by key-size rules for RSA, EC, DH and symmetric keys and by the EC group per handshake. Source code (c), through the GitLab 'AQG Static Code Scanner', is an 8th surface but is not needed to reach 7. I did not count the GitHub integration, which is AI-SPM only. I did not count SSH keys at rest as surface (i). OT/IoT (j) is not documented in the docs I searched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

TLS 1.3 - Extracts client-supported ciphersuites, elliptic curves, and signature algorithms (classic, hybrid, or PQC), along with the server’s selected ciphersuites.

Original scoring anchor: 10: >=7 surfaces with algorithm+parameter depth and PQC/hybrid detection

Evidence artifact

4 / 10

Weight 3/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. CSV export is documented; marketed CBOM mechanism lacks version/sample, so stronger standard-export claim is withheld.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The current docs Exports page documents CSV only. The CBOM docs page covers ingest ('supports uploading ... CBOM files in JSON format'), not export. The marketing homepage claims 'Generate complete Cryptography Bills of Materials (CBOMs)', but I found no export mechanism, schema version or procedure in the docs. The legacy docs for the original release list Print (PDF), CSV and JSON. No signature or hash-chain integrity mechanism is documented. OpenCryptography.com is a public view of AQG output, but it is not a downloadable standard-schema artifact.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Export the displayed data as a CSV for further analysis and reporting.

Original scoring anchor: 4: proprietary export only (CSV/PDF/JSON); a CBOM export is claimed in marketing without a documented mechanism, so it is capped one anchor below 6

Change detection

5 / 10

Weight 3/19 · 0.79 points of the overall score

Internal 1 October claim review: Partial or qualified support. CloudTrail change observation documented; generic quote does not establish diff/alert completeness.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Original assessment: Continuous inputs are documented: event-driven ingestion from CloudTrail and live network monitoring with yanadump. Inventory items carry per-item 'Sessions' (last-scanned history). A side-by-side report diff ('Compare reports') is documented, but only for the original release; I did not find it in the current SaaS docs. I found no drift alerts, signed or hash-chained change history, or published detection latency.

Final review: 6 → 5. The current SaaS docs show continuous, event-driven collection and last-scanned history, with no diff or drift output. The only diff feature, Compare reports, appears in docs labelled 'original release'. Those same docs are the reason the researcher denied the ticketing leg in C6, so crediting them here would be inconsistent. Either both cells credit legacy docs (C3=6, C6=7) or neither does. QC takes the lower path: 5. The published 8 is not restored.

Review evidence and archived ruling

https://docs.aqtiveguard.com/data-sources/aws/ ('Event-driven ingestion from CloudTrail to keep CPM and AI-SPM inventories current'); https://docs.aqtiveguard.com/inventory/ (Sessions = 'Last scanned history'); https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/ (live monitoring, no change detection); https://aqtiveguard.sandboxaq.com/docs/projects/compare-reports/ ('This guide is for the original release of AQtive Guard')

Read the review file
Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Uses CloudTrail to track changes and to discover AWS services that use these assets (for example, EC2, Lambda, API Gateway).

Original scoring anchor: 6: scheduled/continuous rescans with documented diff/change reporting; 8 not met because no tamper-evident history is documented

Risk quantification

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. Policy severity categories documented, without numerical calibration.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Severity is categorical and set by rule parameters. Context comes from Impact Assessment, which counts client IPs that would break on a TLS change, and from marketing claims about owners, dependencies and blast radius ('AQtive Guard maps everykey, certificate, and algorithm to its owners, dependencies, and blast radius' — typo verbatim). I found no numeric score, no data-lifetime or HNDL factor, and no published formula. The docs page on rule severity is login-walled.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Identifies and prioritizes out-of-policy rules based on their severity (critical, high, medium, or low).

Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context

Correctness

4 / 10

Weight 2/19 · 0.42 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor says false positives reduced but provides no method or metric in cited source.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: FP handling is described. The docs mention data enrichment and exclusions. The OpenCryptography post (vendor site) says of 106 Critical/High-tagged objects 'only 10 of those were deemed to carry material risk after a data enrichment process.' No precision or recall metric, benchmark or ground truth is published. The IBM Cryptoscope paper (arXiv:2503.19531) only cites AQtive Guard and does not benchmark it.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

AQG enables you to efficiently and effectively manage and secure NHIs and cryptographic assets, reducing false positives and minimizing risk.

Original scoring anchor: 4: false-positive handling described, no metric

Remediation loop

6.5 / 10

Weight 2/19 · 0.68 points of the overall score

Internal 1 October claim review: Partial or qualified support. Certificate rotation is documented; attribution to the scored AQG product scope and closure needs checking.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The current docs document automated remediation: Protect provides ACME-based short-lived certificate rotation with key generation. They also document one-way GitLab merge-request comments. In the current SaaS docs, the ServiceNow integration is ingest-only. One-way ticket creation (Jira issues and ServiceNow incidents) is documented, but only for the original release; I did not find it in the current SaaS docs. That missing leg holds the score below 7. Neither version documents a bidirectional state or a reopen-on-rescan.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

AQG Protect addresses these challenges with features like automated short-lived certificate rotation and seamless integration, helping you mitigate risks and streamline operations.

Original scoring anchor: midpoint between 6 (one-way ticket/export plus guidance) and 7 (one-way ticket creation plus automated remediation)

Reporting

6 / 10

Weight 2/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. Weak-key/certificate dashboard and export are documented; no compliance evidence mapping asserted.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The Cryptography dashboard and CSV exports are documented. An API exists, but its reference page is login-walled. The only compliance mapping in the docs is for AI-SPM frameworks (EU AI Act, NIST AI RMF, OWASP LLM), not PQC mandates. The CNSA 2.0/NIST proof claims appear only in marketing ('Continuous compliance tracking and exportable reporting.'). No separate executive and technical reports and no published sample report are documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

It highlights potential security and compliance issues, such as weak keys or expiring certificates, so you can take corrective action to protect your data foundations.

Original scoring anchor: 6: dashboards plus exports

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Still offered. Not discontinued or acquired. It has been rebranded onto its own site: sandboxaq.com/solutions/security/discover now returns 301 to aqtiveguard.com, which is branded 'Powered by SandboxAQ' and '2026 © AQtive Guard'. The product is now positioned as Cryptography Posture Management (CPM) plus AI-SPM and non-human-identity (NHI) security. The current SaaS user guide is at docs.aqtiveguard.com. The legacy guide at aqtiveguard.sandboxaq.com/docs is labelled 'for the original release of AQtive Guard'. The public changelog at docs.aqtiveguard.com/changelog/ is stale: its last entry is 25.01.1 (alpha, 2025-01-30). I found no vendor-documented major release after Aug 2026.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

published_total is not stored in the brief. I computed it from the published cells [8,5,8,6,6,7,6] with the rubric weights, and all totals were computed on the research host. Half-point convention: a non-anchor score means the midpoint between the two named anchors, and each such cell names them. Evidence comes from two SandboxAQ-hosted doc sets. The current SaaS guide (docs.aqtiveguard.com) is primary. The legacy guide (aqtiveguard.sandboxaq.com/docs, 'for the original release') documents Jira/ServiceNow ticket export, PDF/CSV/JSON report export and report compare, none of which I found in the current guide. Where only the legacy guide supports a point, the cell says so and scores one step lower. The published C3=8 and C5=6 cannot be reproduced: the rubric's 8 in C3 needs a tamper-evident history, and C5 above 4 needs a published metric. I found neither in any fetched page. The 2026.6 staging note already recorded 'No signed inventory, no change log, no published accuracy', so these drops are rubric-systematic and hit all three of my products the same way, not this vendor alone. C1 moved UP, because the current docs document more surfaces and hybrid/PQC handshake detection. All quotes were checked by exact string match against the fetched page text on 2026-09-26.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes