Discovery
How broadly and deeply does the product find cryptographic assets?
Rank 13 / Developing band / Confidence MOD
TYCHON / PQC discovery capability record for edition 2026.7.
Vendor pages describe endpoint and passive-network discovery; an unmerged partner Elastic integration shows a proposed export schema. S11
Developing MOD
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals
Research record · reviewed 2026-09-26
Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.
Weight 4/19 · 1.68 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor product pages returned 403; third-party Elastic PR does not establish scored surface count/depth.
Read the full review record · Cell tychon-quantum-command/C1. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Surfaces backed by a fetched quote: (a) passive network through ACDI Sniffer; (b) certificates; (d) crypto libraries and archives; (g) endpoints; (i) VPN clients, IPsec and MACsec; (j) OT and IoT. The product page states 'detects both hybrid and pure post-quantum cryptographic implementations'. The partner Elastic schema has key_length_bits and pqc_algos. Containers and cloud storage (the brief's S11) were not found on current pages and were not counted, and source code, HSM and cloud KMS are not documented.
URL availability labels below reflect the historical 30 September source-access screen.
ACDI Sniffer analyzes packet capture data to identify cryptographic protocols, algorithms, certificates, and network services without installing software on the systems being observed.
Original scoring anchor: 8: 5-6 surfaces with algorithm depth (10 needs >=7 surfaces)
Weight 3/19 · 0.63 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; third-party integration PR does not prove a product CycloneDX export.
Read the full review record · Cell tychon-quantum-command/C2. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: The only CBOM evidence is one product-page line. The partner Elastic package documents NDJSON/JSON output, and its fields.yml has no CBOM field (grep for 'cbom' returned no match). Signing or integrity is not documented on the product page, the cryptographic-inventory page or the Elastic PR.
Final review: 5 → 4. CycloneDX appears once, in a feature list, with no version, schema, procedure or sample. Rubric line 19 caps it AT anchor 4. The documented output is NDJSON/JSON, which is proprietary (anchor 4). This matches how the researcher scored DigiCert C2 (a CBOM export claimed with no schema scored 4).
https://tychon.io/tychoncryptographicinventory/ ('Complete Inventory: CBOM (CycloneDX) format', a single line); https://tychon.io/products/tychon/pqc-management-module/ (no CBOM or export text); https://github.com/elastic/integrations/pull/20142 (NDJSON/JSON output, PR still open)
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
Complete Inventory: CBOM (CycloneDX) format
Original scoring anchor: between 4 and 6: proprietary NDJSON/JSON output documented; CycloneDX CBOM named once on a product page with no version, schema detail or sample
Weight 3/19 · 0.63 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; archived change-alert wording has no accessible mechanism.
Read the full review record · Cell tychon-quantum-command/C3. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Vendor pages claim real-time endpoint monitoring, change alerts and an 'Audit trail', but give no mechanism, schedule or diff report. The only technical artifact is the Elastic package, which upserts current state ('rescans update the same entity record'). That is not a change history. Tamper-evident history is not documented. The published 8 was carried unchanged from 2026.4 after a 403.
URL availability labels below reflect the historical 30 September source-access screen.
Understand, analyze, and score your risk posture – monitor, trace, and alert on cryptographic inventory changes.
Original scoring anchor: 4: marketing claim of continuous change alerting with no documented mechanism caps below anchor 6
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; exact risk score factors and categories unverified.
Read the full review record · Cell tychon-quantum-command/C4. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Vendor pages name a '100-point scoring system'. The Elastic schema has quantum_risk, risk_level and overall_score fields. The factors, weights, data lifetime and HNDL are not documented, so anchor 8 is not met.
URL availability labels below reflect the historical 30 September source-access screen.
Automatically generate the cryptographic inventories required under OMB M-26-15, H.R. 7535 and M-23-02, with built-in risk scoring and audit-ready reporting.
Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context
Weight 2/19 · 0.00 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; zero is bounded no metric, not a product accuracy result.
Read the full review record · Cell tychon-quantum-command/C5. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Accuracy metrics, benchmarks and product false-positive handling were not found in the URLs listed, or in a web search for TYCHON Quantum Command accuracy, false positives or benchmarks. The only quote is generic advice in a 2024 vendor blog, not a product mechanism. The Elastic PR's pipeline tests check ingest parsing, not detection accuracy. The published 5 had no source.
URL availability labels below reflect the historical 30 September source-access screen.
Be prepared to handle false positives. Some legitimate uses of these algorithms may be flagged.
Original scoring anchor: 0: not documented
Weight 2/19 · 0.63 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; archived response-action claim cannot verify automation/product scope.
Read the full review record · Cell tychon-quantum-command/C6. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Automated response actions are claimed, and export to a SIEM (Elastic, Splunk) is shown. ServiceNow or Jira ticketing, bidirectional sync and rescan-verified closure are not documented on the product page or in the Elastic PR, so anchor 7 (ticket plus automated action) is not met.
URL availability labels below reflect the historical 30 September source-access screen.
Response Actions let you act directly from the platform, disabling weak ciphers, enforcing updated policies, and targeting your most vulnerable systems first.
Original scoring anchor: 6: one-way export plus guidance (automated remediation claimed, no ticketing documented)
Weight 2/19 · 0.63 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Vendor pages returned 403; dashboard/export claim unverified.
Read the full review record · Cell tychon-quantum-command/C7. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Dashboards are documented, including partner Kibana dashboards for inventory, application, certificate and cost reports, along with JSON export. The product page lists 'M-26-15 NSM-10 H.R. 7535 NIST FIPS 203/204/205 CNSA 2.0 CISA Aligned' as badges. No documented mapping, executive versus technical reports or sample report was found, so it lands with its peers at 6.
URL availability labels below reflect the historical 30 September source-access screen.
With TYCHON's intuitive dashboards, you can monitor the cryptographic status of every endpoint in real time.
Original scoring anchor: 6: dashboards plus exports (compliance frameworks listed as badges, mapping not documented)
Documentation reviewed 2026-09-26: No rename, acquisition or discontinuation was found, and the product page still titles it 'TYCHON Quantum Command'. Two changes: TYCHON's ACDI technology is being integrated into HCL BigFix (tychon.io post dated 25 Feb 2026), and an Elastic 'tychon_quantum_command' integration package, v0.1.0 type partner, is an open, unmerged PR (elastic/integrations#20142, opened 2026-07-15, last updated 2026-09-23). No new major Quantum Command release since Aug 2026 was found.
Archived product-status source · Source check: HTTP 403. The archived summary has not been independently revalidated in full.
Confidence is THIN. There are no docs portal, datasheet, release notes, public sample or paper for Quantum Command. Evidence is vendor product pages plus an unmerged Elastic integration PR, owner type 'partner', authored by GitHub user Audience2801 with no stated affiliation, v0.1.0. That PR is the only technical artifact. It shows NDJSON/JSON output and datasets for certificates, ciphers, crypto libraries, keystores, VPN, IPsec, MACsec, archives and system readiness, with key-length and PQC fields. It was read through the GitHub API on the research host. It is not merged, so it is not shipped Elastic content. All published 2026.6 cells were carried unchanged from 2026.4 after a 403, so this is the first live re-read. C3 (-4) and C5 (-5) are large moves: neither published value had an admissible source. The HCL BigFix partnership date comes from tychon.io (25 Feb 2026); the HCL press release dates it 11 Feb 2026. PUBLISHED_TOTAL: the brief gives no total, so 6.74 is recomputed from published_cells with the rubric formula.
Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes