{
  "components": [
    {
      "bom-ref": "crypto:algorithm:aes-128-cbc",
      "cryptoProperties": {
        "algorithmProperties": {
          "classicalSecurityLevel": 128,
          "cryptoFunctions": [
            "decrypt",
            "encrypt"
          ],
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "nistQuantumSecurityLevel": 1,
          "parameterSetIdentifier": "AES-128-CBC",
          "primitive": "block-cipher",
          "algorithmFamily": "AES"
        },
        "assetType": "algorithm",
        "oid": "2.16.840.1.101.3.4.1.2"
      },
      "description": "AES-128 in CBC mode. Composed into Fernet (with HMAC-SHA256) for authenticated encryption of scan tokens at rest. Disclosed as a component primitive of the Fernet construction.",
      "name": "AES-128-CBC",
      "properties": [
        {
          "name": "qscout:composes-into",
          "value": "crypto:related:fernet-aead"
        },
        {
          "name": "qscout:post-quantum-status",
          "value": "quantum-safe-grover-128-equiv-64"
        },
        {
          "name": "qscout:role",
          "value": "fernet-component-primitive"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/utils/security.py:201"
        },
        {
          "name": "qscout:standard",
          "value": "NIST FIPS 197 + NIST SP 800-38A"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:algorithm:aes-128-cbc\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:algorithm:aes-256-gcm",
      "cryptoProperties": {
        "algorithmProperties": {
          "classicalSecurityLevel": 256,
          "cryptoFunctions": [
            "decrypt",
            "encrypt"
          ],
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "nistQuantumSecurityLevel": 1,
          "parameterSetIdentifier": "AES-256-GCM",
          "primitive": "ae",
          "algorithmFamily": "AES"
        },
        "assetType": "algorithm",
        "oid": "2.16.840.1.101.3.4.1.46"
      },
      "description": "Authenticated encryption (AEAD) with AES-256 in Galois/Counter Mode (NIST SP 800-38D). Used to encrypt the visitor-intel replay token payload at rest.",
      "name": "AES-256-GCM",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "quantum-safe-grover-256-equiv-128"
        },
        {
          "name": "qscout:role",
          "value": "visitor-intel-replay-token-encryption"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/visitor_intel_shared.py:18"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/visitor_intel_shared.py:464"
        },
        {
          "name": "qscout:standard",
          "value": "NIST SP 800-38D"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:algorithm:aes-256-gcm\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:related:fernet-aead",
      "cryptoProperties": {
        "assetType": "related-crypto-material",
        "algorithmProperties": {
          "algorithmFamily": "AES"
        }
      },
      "description": "Fernet authenticated-encryption construction: AES-128-CBC for confidentiality + HMAC-SHA256 for integrity. Used to encrypt scan tokens for later notification delivery so plaintext tokens never sit at rest in the database.",
      "name": "Fernet (AES-128-CBC + HMAC-SHA256)",
      "properties": [
        {
          "name": "qscout:composes-from",
          "value": "crypto:algorithm:aes-128-cbc, crypto:algorithm:hmac-sha-256"
        },
        {
          "name": "qscout:post-quantum-status",
          "value": "at-risk-symmetric-128"
        },
        {
          "name": "qscout:role",
          "value": "scan-token-encryption-at-rest"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/utils/security.py:201"
        },
        {
          "name": "qscout:standard",
          "value": "cryptography.fernet (RFC-style)"
        },
        {
          "name": "qscout:oid-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:oid-reason",
          "value": "composite-construction-no-single-algorithm-oid"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:related:fernet-aead\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:algorithm:hmac-sha-256",
      "cryptoProperties": {
        "algorithmProperties": {
          "classicalSecurityLevel": 128,
          "cryptoFunctions": [
            "tag",
            "verify"
          ],
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "nistQuantumSecurityLevel": 0,
          "parameterSetIdentifier": "HMAC-SHA-256",
          "primitive": "mac",
          "algorithmFamily": "HMAC"
        },
        "assetType": "algorithm",
        "oid": "1.2.840.113549.2.9"
      },
      "description": "Keyed-hash message authentication code (HMAC) built on SHA-256 (NIST FIPS 198-1). Used to sign canary proof artifacts and health snapshot sidecars.",
      "name": "HMAC-SHA256",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "at-risk-128-bit-quantum"
        },
        {
          "name": "qscout:role",
          "value": "canary-proof-signature,health-snapshot-signature"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/routes/health.py:524"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/scan_canary_state.py:80"
        },
        {
          "name": "qscout:standard",
          "value": "NIST FIPS 198-1"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:algorithm:hmac-sha-256\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:algorithm:md5",
      "cryptoProperties": {
        "algorithmProperties": {
          "classicalSecurityLevel": 0,
          "cryptoFunctions": [
            "digest"
          ],
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "nistQuantumSecurityLevel": 0,
          "parameterSetIdentifier": "128",
          "primitive": "hash",
          "algorithmFamily": "MD5"
        },
        "assetType": "algorithm",
        "oid": "1.2.840.113549.2.5"
      },
      "description": "MD5 hash function. Used in QScout-API only as a non-security identifier (cache keys, SARIF rule-ids, email hashes, favicon fingerprints, JA3). ``usedforsecurity=False`` flag is set on the cache path; other sites omit the flag because they predate Python 3.9 hashlib.md5 keyword support. Never used for authentication or integrity.",
      "name": "MD5",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "not-applicable-broken-classical"
        },
        {
          "name": "qscout:role",
          "value": "non-security-identifier-only"
        },
        {
          "name": "qscout:security-flag",
          "value": "usedforsecurity=False (cache path only); omitted on legacy SARIF/email/favicon paths"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/cache/api_cache.py:294"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/level0/favicon_fingerprint.py:279"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/modules/tls_pqc_scanner.py:333"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/reporting/sarif_export.py:43"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/vi_email_patterns.py:244"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:algorithm:md5\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:algorithm:ml-dsa-65",
      "cryptoProperties": {
        "algorithmProperties": {
          "classicalSecurityLevel": 192,
          "cryptoFunctions": [
            "keygen",
            "sign",
            "verify"
          ],
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "nistQuantumSecurityLevel": 3,
          "parameterSetIdentifier": "ML-DSA-65",
          "primitive": "signature",
          "algorithmFamily": "ML-DSA"
        },
        "assetType": "algorithm",
        "oid": "2.16.840.1.101.3.4.3.18"
      },
      "description": "Module-Lattice-Based Digital Signature Algorithm at security category 3 (NIST FIPS 204). Primary post-quantum signature algorithm for QScout artifact signing; verification key is published at ``/public/verification-key``.",
      "name": "ML-DSA-65",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "post-quantum-ready"
        },
        {
          "name": "qscout:role",
          "value": "post-quantum-artifact-signature"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/routes/public_verification_key.py:48"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/truth_contract.py:234"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/utils/ml_dsa_signer.py:84"
        },
        {
          "name": "qscout:standard",
          "value": "NIST FIPS 204"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:algorithm:ml-dsa-65\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:protocol:openpgp",
      "cryptoProperties": {
        "assetType": "protocol",
        "protocolProperties": {
          "type": "other",
          "version": "RFC-4880"
        },
        "algorithmProperties": {}
      },
      "description": "OpenPGP (RFC 4880) signature framework used as a fallback report-signing path when ML-DSA-65 keys are not provisioned. Underlying key types and digest algorithms are controlled by operator GPG key selection.",
      "name": "OpenPGP",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "depends-on-underlying-key-type"
        },
        {
          "name": "qscout:role",
          "value": "fallback-report-signature"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/reporting/report_signer.py:103"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/truth_contract.py:80"
        },
        {
          "name": "qscout:standard",
          "value": "IETF RFC 4880"
        },
        {
          "name": "qscout:oid-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:oid-reason",
          "value": "protocol-surface-no-single-algorithm-oid"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:protocol:openpgp\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:algorithmFamily-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:related:openssl-runtime",
      "cryptoProperties": {
        "assetType": "related-crypto-material",
        "relatedCryptoMaterialProperties": {
          "type": "other"
        },
        "algorithmProperties": {}
      },
      "description": "OpenSSL is the system-level cryptographic library used by Python's ``hashlib``, ``hmac``, and the ``cryptography`` package (pyca/cryptography 46.0.7) for the primitives above.",
      "name": "OpenSSL",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "depends-on-algorithm-selection"
        },
        {
          "name": "qscout:role",
          "value": "primitive-implementation-runtime"
        },
        {
          "name": "qscout:source",
          "value": "requirements.lock.txt:cryptography==46.0.7"
        },
        {
          "name": "qscout:oid-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:oid-reason",
          "value": "runtime-library-not-a-single-algorithm"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:related:openssl-runtime\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:algorithmFamily-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:algorithm:rs256",
      "cryptoProperties": {
        "algorithmProperties": {
          "classicalSecurityLevel": 112,
          "cryptoFunctions": [
            "verify"
          ],
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "nistQuantumSecurityLevel": 0,
          "parameterSetIdentifier": "RSA-2048-SHA-256",
          "primitive": "signature",
          "algorithmFamily": "RSASSA-PKCS1"
        },
        "assetType": "algorithm",
        "oid": "1.2.840.113549.1.1.11"
      },
      "description": "RSASSA-PKCS1-v1_5 signature with SHA-256 digest. QScout is the VERIFIER of RS256-signed JWTs presented by Microsoft Azure Marketplace on webhook auth. RSA key is supplied by Microsoft (JWKS endpoint); QScout does not hold or rotate it.",
      "name": "RS256 (RSASSA-PKCS1-v1_5 + SHA-256)",
      "properties": [
        {
          "name": "qscout:key-custody",
          "value": "microsoft-jwks-not-qscout"
        },
        {
          "name": "qscout:post-quantum-status",
          "value": "at-risk-shor-breaks-rsa"
        },
        {
          "name": "qscout:role",
          "value": "azure-marketplace-webhook-jwt-verify"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/routes/marketplace_landing.py:310"
        },
        {
          "name": "qscout:standard",
          "value": "RFC 8017 PKCS#1 + RFC 7519 JWT + RFC 7518 JWA"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:algorithm:rs256\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:algorithm:sha-256",
      "cryptoProperties": {
        "algorithmProperties": {
          "classicalSecurityLevel": 128,
          "cryptoFunctions": [
            "digest"
          ],
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "nistQuantumSecurityLevel": 0,
          "parameterSetIdentifier": "256",
          "primitive": "hash",
          "algorithmFamily": "SHA-2"
        },
        "assetType": "algorithm",
        "oid": "2.16.840.1.101.3.4.2.1"
      },
      "description": "SHA-256 hash function (NIST FIPS 180-4). Used as the Merkle audit chain genesis hash, the canary proof artifact digest, and the canonical-JSON digest for the truth-contract evidence payload.",
      "name": "SHA-256",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "at-risk-128-bit-quantum"
        },
        {
          "name": "qscout:role",
          "value": "audit-chain-genesis,proof-artifact-digest"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/routes/health.py:515"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/truth_contract.py:136"
        },
        {
          "name": "qscout:standard",
          "value": "NIST FIPS 180-4"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:algorithm:sha-256\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:protocol:tls-1.2",
      "cryptoProperties": {
        "assetType": "protocol",
        "protocolProperties": {
          "type": "tls",
          "version": "1.2"
        },
        "algorithmProperties": {
          "curve": "P-256",
          "algorithmFamily": "ECDSA"
        }
      },
      "description": "Transport Layer Security 1.2 (IETF RFC 5246). Retained as a negotiation fallback by the ``urllib3`` HTTPS adapter; QScout prefers TLS 1.3 when the peer supports it.",
      "name": "TLS 1.2",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "at-risk-classical-handshake"
        },
        {
          "name": "qscout:role",
          "value": "outbound-https-fallback"
        },
        {
          "name": "qscout:source",
          "value": "requirements.lock.txt:urllib3==2.7.0"
        },
        {
          "name": "qscout:standard",
          "value": "IETF RFC 5246"
        },
        {
          "name": "qscout:oid-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:oid-reason",
          "value": "protocol-version-no-single-algorithm-oid"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:protocol:tls-1.2\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:protocol:tls-1.3",
      "cryptoProperties": {
        "assetType": "protocol",
        "protocolProperties": {
          "type": "tls",
          "version": "1.3"
        },
        "algorithmProperties": {
          "curve": "P-256",
          "algorithmFamily": "ECDSA"
        }
      },
      "description": "Transport Layer Security 1.3 (IETF RFC 8446). Used for outbound HTTPS calls made via the ``requests``/``urllib3`` stack and for inbound HTTPS at the reverse-proxy edge.",
      "name": "TLS 1.3",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "at-risk-classical-handshake"
        },
        {
          "name": "qscout:role",
          "value": "outbound-https,inbound-edge"
        },
        {
          "name": "qscout:source",
          "value": "requirements.lock.txt:requests==2.33.1"
        },
        {
          "name": "qscout:source",
          "value": "requirements.lock.txt:urllib3==2.7.0"
        },
        {
          "name": "qscout:standard",
          "value": "IETF RFC 8446"
        },
        {
          "name": "qscout:oid-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:oid-reason",
          "value": "protocol-version-no-single-algorithm-oid"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:protocol:tls-1.3\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    },
    {
      "bom-ref": "crypto:related:constant-time-compare",
      "cryptoProperties": {
        "assetType": "related-crypto-material",
        "relatedCryptoMaterialProperties": {
          "type": "other"
        },
        "algorithmProperties": {}
      },
      "description": "Constant-time byte-string comparison primitive. Used everywhere QScout-API verifies a MAC, signature header, or shared secret to defeat timing side-channels.",
      "name": "hmac.compare_digest",
      "properties": [
        {
          "name": "qscout:post-quantum-status",
          "value": "not-applicable-primitive"
        },
        {
          "name": "qscout:role",
          "value": "timing-safe-mac-comparison"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/routes/health.py:521"
        },
        {
          "name": "qscout:source",
          "value": "src/qscout/web_api/services/scan_canary_state.py:81"
        },
        {
          "name": "qscout:oid-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:oid-reason",
          "value": "implementation-technique-no-algorithm-oid"
        },
        {
          "name": "qscout:Citations",
          "value": "[{\"url\":\"https://api.qtonicquantum.com/public/trust/cbom\",\"module\":\"qscout.web_api.routes.public_trust_cbom\",\"note\":\"internal crypto surface of qscout-api, not a customer estate CBOM\"}]"
        },
        {
          "name": "qscout:attributedTo",
          "value": "{\"module_id\":\"crypto:related:constant-time-compare\",\"producer\":\"qscout-api\",\"git_sha\":\"4.0.0\",\"target\":\"qscout-api-internal\"}"
        },
        {
          "name": "qscout:algorithmFamily-status",
          "value": "not-applicable"
        },
        {
          "name": "qscout:curve-status",
          "value": "not-applicable"
        }
      ],
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "cryptographic-asset"
    }
  ],
  "dependencies": [
    {
      "ref": "crypto:algorithm:aes-128-cbc"
    },
    {
      "ref": "crypto:algorithm:aes-256-gcm"
    },
    {
      "ref": "crypto:algorithm:hmac-sha-256"
    },
    {
      "ref": "crypto:algorithm:md5"
    },
    {
      "ref": "crypto:algorithm:ml-dsa-65"
    },
    {
      "ref": "crypto:algorithm:rs256"
    },
    {
      "ref": "crypto:algorithm:sha-256"
    },
    {
      "ref": "crypto:protocol:openpgp"
    },
    {
      "ref": "crypto:protocol:tls-1.2"
    },
    {
      "ref": "crypto:protocol:tls-1.3"
    },
    {
      "ref": "crypto:related:constant-time-compare"
    },
    {
      "ref": "crypto:related:fernet-aead"
    },
    {
      "ref": "crypto:related:openssl-runtime"
    },
    {
      "dependsOn": [
        "crypto:algorithm:aes-128-cbc",
        "crypto:algorithm:aes-256-gcm",
        "crypto:algorithm:hmac-sha-256",
        "crypto:algorithm:md5",
        "crypto:algorithm:ml-dsa-65",
        "crypto:algorithm:rs256",
        "crypto:algorithm:sha-256",
        "crypto:protocol:openpgp",
        "crypto:protocol:tls-1.2",
        "crypto:protocol:tls-1.3",
        "crypto:related:constant-time-compare",
        "crypto:related:fernet-aead",
        "crypto:related:openssl-runtime"
      ],
      "ref": "qscout-api"
    }
  ],
  "metadata": {
    "component": {
      "bom-ref": "qscout-api",
      "description": "QScout cryptographic intelligence platform -- internal crypto surface (algorithms, protocols, and related material that the service itself implements).",
      "name": "qscout-api",
      "supplier": {
        "name": "Qtonic Quantum Corp",
        "url": [
          "https://qtonicquantum.com"
        ]
      },
      "type": "application",
      "version": "4.0.0"
    },
    "supplier": {
      "name": "Qtonic Quantum Corp",
      "url": [
        "https://qtonicquantum.com"
      ]
    },
    "timestamp": "2026-09-30T06:26:00.625165+00:00",
    "properties": [
      {
        "name": "qscout:predecessor",
        "value": "6c86d596aa8c348daf36de5c9e36fde0d7c5a64ff810450de2b0704b527be4ee"
      },
      {
        "name": "qscout:sample-not-estate-cbom",
        "value": "true"
      },
      {
        "name": "qscout:not",
        "value": "estate-scale Gold CBOM"
      }
    ]
  },
  "serialNumber": "urn:uuid:707f14e8-5815-4548-aedc-f0ffc7f6fd54",
  "version": 1,
  "$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.7"
}