{
  "schema": "pqc-discovery-claim-ledger-v1",
  "version": "2026-10-01.1",
  "edition": "2026.7",
  "scope": "Non-scoring provenance overlay; frozen rank, scores, weights and historical evidence files unchanged",
  "publisher": "Qtonic Quantum Corp",
  "internal_semantic_review": {
    "path": "/research/2026-10-01/semantic-review-v1.json",
    "published_review_sha256": "a431ce8d4f88900d93b8ef0749c6496d4dec0412d5c67b772ad301ee625e5d3a",
    "original_review_sha256": "ecff0ca3ff7a64f59c77487f25efdcc66206723fc5492195d7ab5ced2722ae97",
    "reviewed_utc": "2026-10-01T02:23:35.284402+00:00",
    "counts": {
      "artifact_tested_narrow": 1,
      "documented_feature": 24,
      "qualified_or_partial_anchor": 53,
      "unverified_anchor": 20
    },
    "authenticated_quote_reproductions": 77,
    "warning": "This is internal source-to-anchor triage using authenticated 1 October refetches and archived assessments, not 98 validated numeric scores, executable peer tests, or outside review. Historical scores remain unchanged."
  },
  "evidence_classes": {
    "archived_vendor_claim": "The archived assessment cites a vendor claim. Current access and exact anchor support depend on source_entailment and fresh_verified_tls; this class alone confirms neither the feature nor its numeric score.",
    "external_paper_not_product": "A research paper is not product execution for the scored unit.",
    "artifact_tested_public_own_api_sample": "The public own-API sample was schema/signature/tamper checked within a narrow scope.",
    "production_observed_vendor_dogfood_log": "A vendor-controlled dogfood log exists; deployment/source identity and independent production behavior were not attested.",
    "artifact_recomputed_vendor_labeled_corpus": "Arithmetic on a vendor-labeled corpus was recomputed; label independence and field performance remain unverified.",
    "artifact_tested_fixture_not_live_tenant": "A fixture was exercised, not a customer tenant or live closure.",
    "artifact-tested": "An exact named artifact was checked within its stated scope.",
    "production-observed": "A deployed build with exact source custody and observed behavior was checked.",
    "externally-reviewed": "An outside assessor independently executed or adjudicated the claim."
  },
  "cells": [
    {
      "id": "appviewx-quantum-trust-hub/C1",
      "product": "AppViewX Quantum Trust Hub",
      "slug": "appviewx-quantum-trust-hub",
      "criterion": "C1",
      "final_score": 8.5,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "All five vendor documentation URLs returned 403; surface-count/depth cannot be independently checked.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 0,
        "total_cited_urls": 5,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "c70a8b17d511f8816a67f567bac85be3272d9a85b5602ed62c794bf42d401266",
            "checked_utc": "2026-10-01T02:20:07.577323+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "e25c61dd183c07fd549186c2f8b7446006331543a456800fb1dfbe7dae5e6eff",
            "checked_utc": "2026-10-01T02:20:07.505758+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "997bc84ff80e3900075eb8065a96eef2959bd3f19b47073e67827b34c0c51c59",
            "checked_utc": "2026-10-01T02:20:07.475946+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "b7394707fcc4fbc3737c855b3bd38ba97eb87eeefd414ed171aab5f1d641ee28",
            "checked_utc": "2026-10-01T02:20:07.526637+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "9548aa11e119d74480d53ec7363df5290d82d958ef9b1badf2eb2a9001c43fb8",
            "checked_utc": "2026-10-01T02:20:07.573633+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/appviewx-quantum-trust-hub.json",
      "original_cell_score": 8.5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "unavailable",
      "cited_sources": [
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "appviewx-quantum-trust-hub/C2",
      "product": "AppViewX Quantum Trust Hub",
      "slug": "appviewx-quantum-trust-hub",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor blog/docs/datasheet returned 403; CycloneDX/CSV export claim remains unverified here.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 0,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
            "status": "403",
            "final": "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "b57159c6e421e86c5b0b964d54b46ffb39a4c41f39e0d49ac6155547f6282e2b",
            "checked_utc": "2026-10-01T02:20:15.650358+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "11ea673870ec99d222313a81f4a5049127f9b8c234a7125828de06fd6297439b",
            "checked_utc": "2026-10-01T02:20:07.623356+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "status": "403",
            "final": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "6bacb3edf5b150dcc5112896bf4b315549782cde5dfb1f0b74d94e19979e7fc7",
            "checked_utc": "2026-10-01T02:20:15.718686+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/appviewx-quantum-trust-hub.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "unavailable",
      "cited_sources": [
        {
          "url": "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "appviewx-quantum-trust-hub/C3",
      "product": "AppViewX Quantum Trust Hub",
      "slug": "appviewx-quantum-trust-hub",
      "criterion": "C3",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Scheduling/drift docs returned 403; archived scheduling quote does not prove diff reporting.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 0,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/scheduled_discovery.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/scheduled_discovery.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "e200a682709ce94c704d3f52359afd795f4861108307dc4b37438cc47ea2120b",
            "checked_utc": "2026-10-01T02:20:07.590990+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/monitoring_pqc_logs.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/monitoring_pqc_logs.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "6d5798696de31a3ae3d30fa978b81ae65a74c2cfbf267a2aaad09eef74d0cf40",
            "checked_utc": "2026-10-01T02:20:07.548936+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "c70a8b17d511f8816a67f567bac85be3272d9a85b5602ed62c794bf42d401266",
            "checked_utc": "2026-10-01T02:20:07.577323+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
            "status": "403",
            "final": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "c772314db82dfa438edbe08dae6487ff9591c9995bee464acbc34063add83648",
            "checked_utc": "2026-10-01T02:20:15.677549+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/appviewx-quantum-trust-hub.json",
      "original_cell_score": 5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "unavailable",
      "cited_sources": [
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/scheduled_discovery.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/monitoring_pqc_logs.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "appviewx-quantum-trust-hub/C4",
      "product": "AppViewX Quantum Trust Hub",
      "slug": "appviewx-quantum-trust-hub",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Risk pages returned 403; archived readiness score does not establish the exact asset-risk anchor.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 0,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "11ea673870ec99d222313a81f4a5049127f9b8c234a7125828de06fd6297439b",
            "checked_utc": "2026-10-01T02:20:07.623356+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "b7394707fcc4fbc3737c855b3bd38ba97eb87eeefd414ed171aab5f1d641ee28",
            "checked_utc": "2026-10-01T02:20:07.526637+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "35434fdef9461cc7e7257b8b6e8f4ab2ec091d75f8b7c9aa6a34ceb177372e73",
            "checked_utc": "2026-10-01T02:20:07.535579+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/understanding_pqc.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/understanding_pqc.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "59f5fe558ae220384f27d8448ea1f917d73fa40dc8dfd1a4aa6fc2b6491e049d",
            "checked_utc": "2026-10-01T02:20:07.617120+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/appviewx-quantum-trust-hub.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "unavailable",
      "cited_sources": [
        {
          "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/understanding_pqc.html",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "appviewx-quantum-trust-hub/C5",
      "product": "AppViewX Quantum Trust Hub",
      "slug": "appviewx-quantum-trust-hub",
      "criterion": "C5",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Zero reflects no documented metric in a 403-constrained search, not evidence of no accuracy work.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 0,
        "total_cited_urls": 10,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "11ea673870ec99d222313a81f4a5049127f9b8c234a7125828de06fd6297439b",
            "checked_utc": "2026-10-01T02:20:07.623356+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "e25c61dd183c07fd549186c2f8b7446006331543a456800fb1dfbe7dae5e6eff",
            "checked_utc": "2026-10-01T02:20:07.505758+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "997bc84ff80e3900075eb8065a96eef2959bd3f19b47073e67827b34c0c51c59",
            "checked_utc": "2026-10-01T02:20:07.475946+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "9548aa11e119d74480d53ec7363df5290d82d958ef9b1badf2eb2a9001c43fb8",
            "checked_utc": "2026-10-01T02:20:07.573633+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "b7394707fcc4fbc3737c855b3bd38ba97eb87eeefd414ed171aab5f1d641ee28",
            "checked_utc": "2026-10-01T02:20:07.526637+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "c70a8b17d511f8816a67f567bac85be3272d9a85b5602ed62c794bf42d401266",
            "checked_utc": "2026-10-01T02:20:07.577323+00:00",
            "error": ""
          },
          {
            "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "35434fdef9461cc7e7257b8b6e8f4ab2ec091d75f8b7c9aa6a34ceb177372e73",
            "checked_utc": "2026-10-01T02:20:07.535579+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
            "status": "403",
            "final": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "c772314db82dfa438edbe08dae6487ff9591c9995bee464acbc34063add83648",
            "checked_utc": "2026-10-01T02:20:15.677549+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
            "status": "403",
            "final": "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "b57159c6e421e86c5b0b964d54b46ffb39a4c41f39e0d49ac6155547f6282e2b",
            "checked_utc": "2026-10-01T02:20:15.650358+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "status": "403",
            "final": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "6bacb3edf5b150dcc5112896bf4b315549782cde5dfb1f0b74d94e19979e7fc7",
            "checked_utc": "2026-10-01T02:20:15.718686+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/appviewx-quantum-trust-hub.json",
      "original_cell_score": 0,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_C.json",
          "before": 0,
          "after": 4,
          "reason": "This is a documented product rule for accuracy handling. The product labels indeterminate detections Unknown instead of misclassifying them, which meets anchor 4 ('accuracy or false-positive handling described, no metric'), the same bar as the DigiCert and Keyfactor C5=4 precedents. No metric was found, so the published 6 is not restored. This is the weakest raise in this QC pass.",
          "evidence": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html ('If the cryptographic algorithm is referenced from a constant, variable, configuration, or resolved at runtime and cannot be determined through static analysis, the algorithm cannot be determined and will be marked as Unknown')"
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "unavailable",
      "cited_sources": [
        {
          "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agentless_scans.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/agent_based_scans.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_code_scan.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/certificate_scan_report.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/quantum_trust_hub_configuration_scan.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.appviewx.com/2026.2.0/oxy_ex/code_scanning_solution.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/blogs/appviewx-avx-one-pqc-assessment-tool-kickstart-your-pqc-readiness-journey-with-complete-cryptographic-visibility/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "appviewx-quantum-trust-hub/C6",
      "product": "AppViewX Quantum Trust Hub",
      "slug": "appviewx-quantum-trust-hub",
      "criterion": "C6",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor pages returned 403; archived CLM action may be adjacent-platform rather than Quantum Trust Hub behavior.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 0,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://docs.appviewx.com/2026.3.0/quantum_trust_hub.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.3.0/quantum_trust_hub.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "907ee72986b8f81e413bbc136ede695f5997f4fba37d4d2fe57c6f21c32d65ec",
            "checked_utc": "2026-10-01T02:20:07.633626+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/blogs/streamline-certificate-lifecycle-management-with-appviewx-avx-one-clm-and-servicenow/",
            "status": "403",
            "final": "https://www.appviewx.com/blogs/streamline-certificate-lifecycle-management-with-appviewx-avx-one-clm-and-servicenow/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "ddd5dd6c89da018dee2f8b4602e34146c59d54866d5c62ae724e1c57fa330c28",
            "checked_utc": "2026-10-01T02:20:15.692508+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "status": "403",
            "final": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "6bacb3edf5b150dcc5112896bf4b315549782cde5dfb1f0b74d94e19979e7fc7",
            "checked_utc": "2026-10-01T02:20:15.718686+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/appviewx-quantum-trust-hub.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "unavailable",
      "cited_sources": [
        {
          "url": "https://docs.appviewx.com/2026.3.0/quantum_trust_hub.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/blogs/streamline-certificate-lifecycle-management-with-appviewx-avx-one-clm-and-servicenow/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "appviewx-quantum-trust-hub/C7",
      "product": "AppViewX Quantum Trust Hub",
      "slug": "appviewx-quantum-trust-hub",
      "criterion": "C7",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor report sources returned 403; report and framework scope cannot be independently checked.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 0,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "status": "403",
            "final": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "11ea673870ec99d222313a81f4a5049127f9b8c234a7125828de06fd6297439b",
            "checked_utc": "2026-10-01T02:20:07.623356+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
            "status": "403",
            "final": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "c772314db82dfa438edbe08dae6487ff9591c9995bee464acbc34063add83648",
            "checked_utc": "2026-10-01T02:20:15.677549+00:00",
            "error": ""
          },
          {
            "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "status": "403",
            "final": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "6bacb3edf5b150dcc5112896bf4b315549782cde5dfb1f0b74d94e19979e7fc7",
            "checked_utc": "2026-10-01T02:20:15.718686+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/appviewx-quantum-trust-hub.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "unavailable",
      "cited_sources": [
        {
          "url": "https://docs.appviewx.com/2026.2.0/quantum_trust_hub.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/blogs/appviewx-quantum-trust-hub-release/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.appviewx.com/datasheets/accelerate-pqc-readiness-with-quantum-trust-hub/",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cbom-secure/C1",
      "product": "CBOM Secure",
      "slug": "cbom-secure",
      "criterion": "C1",
      "final_score": 10,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor quote enumerates many surfaces; parameter depth and hybrid detection rely on an inaccessible datasheet and remain documentation-only.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/"
        ],
        "sources": [
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f01dd9bfbc6ccdb0a1a820d9bdf94f867d67ded6729684c482dd97f946bf2b14",
            "checked_utc": "2026-10-01T02:20:17.374390+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "status": "406",
            "final": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "content_type": "text/html; charset=iso-8859-1",
            "method": "curl_verified_tls",
            "sha256": "8970d3ea6059606600e849b7d48adcae7d56b01a70cc5fa34b558cab199eb021",
            "checked_utc": "2026-10-01T02:20:17.428034+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "fec92c1e70f1549e7251b20c4fd270f254d4e4c6ac0d97fa6044e4e528d1d893",
            "checked_utc": "2026-10-01T02:20:17.371524+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cbom-secure.json",
      "original_cell_score": 10,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cbom-secure/C2",
      "product": "CBOM Secure",
      "slug": "cbom-secure",
      "criterion": "C2",
      "final_score": 7,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Accessible vendor page documents CycloneDX 1.6/1.7 export; it does not document a signature on the exported CBOM.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/"
        ],
        "sources": [
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f01dd9bfbc6ccdb0a1a820d9bdf94f867d67ded6729684c482dd97f946bf2b14",
            "checked_utc": "2026-10-01T02:20:17.374390+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "fec92c1e70f1549e7251b20c4fd270f254d4e4c6ac0d97fa6044e4e528d1d893",
            "checked_utc": "2026-10-01T02:20:17.371524+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "status": "406",
            "final": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "content_type": "text/html; charset=iso-8859-1",
            "method": "curl_verified_tls",
            "sha256": "8970d3ea6059606600e849b7d48adcae7d56b01a70cc5fa34b558cab199eb021",
            "checked_utc": "2026-10-01T02:20:17.428034+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cbom-secure.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cbom-secure/C3",
      "product": "CBOM Secure",
      "slug": "cbom-secure",
      "criterion": "C3",
      "final_score": 8,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor documents monitoring, alerts and a tamper-proof audit trail, but publishes no log mechanism or independent verification.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.encryptionconsulting.com/cryptographic-posture-management/"
        ],
        "sources": [
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "fec92c1e70f1549e7251b20c4fd270f254d4e4c6ac0d97fa6044e4e528d1d893",
            "checked_utc": "2026-10-01T02:20:17.371524+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15cab611eee5ce893a988dd6e6af3b840f72413f0e56d30c9256556ba75e53eb",
            "checked_utc": "2026-10-01T02:20:17.323055+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "bb4e7a268bd0375650d16755e20921bd9df36762594979795149851a0fe5ed9e",
            "checked_utc": "2026-10-01T02:20:17.297539+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cbom-secure.json",
      "original_cell_score": 8,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cbom-secure/C4",
      "product": "CBOM Secure",
      "slug": "cbom-secure",
      "criterion": "C4",
      "final_score": 7,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Accessible V1.1 page confirms 0-100 score and named factors; exact archived datasheet quote was inaccessible (406), and lifetime/HNDL is absent.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "status": "406",
            "final": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "content_type": "text/html; charset=iso-8859-1",
            "method": "curl_verified_tls",
            "sha256": "8970d3ea6059606600e849b7d48adcae7d56b01a70cc5fa34b558cab199eb021",
            "checked_utc": "2026-10-01T02:20:17.428034+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "bb4e7a268bd0375650d16755e20921bd9df36762594979795149851a0fe5ed9e",
            "checked_utc": "2026-10-01T02:20:17.297539+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cbom-inventory-to-intelligence/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cbom-inventory-to-intelligence/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "8e26fc865d91abf0b2b4ea64d2cfa15308c82799ac54d35d84c64f0de685cbdd",
            "checked_utc": "2026-10-01T02:20:17.217521+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cbom-secure.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/cbom-inventory-to-intelligence/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cbom-secure/C5",
      "product": "CBOM Secure",
      "slug": "cbom-secure",
      "criterion": "C5",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor says false positives are eliminated but gives no method or precision/recall metric; anchor is only a documented claim.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/"
        ],
        "sources": [
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f01dd9bfbc6ccdb0a1a820d9bdf94f867d67ded6729684c482dd97f946bf2b14",
            "checked_utc": "2026-10-01T02:20:17.374390+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "bb4e7a268bd0375650d16755e20921bd9df36762594979795149851a0fe5ed9e",
            "checked_utc": "2026-10-01T02:20:17.297539+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "status": "406",
            "final": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "content_type": "text/html; charset=iso-8859-1",
            "method": "curl_verified_tls",
            "sha256": "8970d3ea6059606600e849b7d48adcae7d56b01a70cc5fa34b558cab199eb021",
            "checked_utc": "2026-10-01T02:20:17.428034+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cbom-secure.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cbom-secure/C6",
      "product": "CBOM Secure",
      "slug": "cbom-secure",
      "criterion": "C6",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "CycloneDX export and remediation guidance support final six; named Jira/ServiceNow integration belongs to CertSecure Manager, not this product.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/"
        ],
        "sources": [
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15cab611eee5ce893a988dd6e6af3b840f72413f0e56d30c9256556ba75e53eb",
            "checked_utc": "2026-10-01T02:20:17.323055+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "fec92c1e70f1549e7251b20c4fd270f254d4e4c6ac0d97fa6044e4e528d1d893",
            "checked_utc": "2026-10-01T02:20:17.371524+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "status": "406",
            "final": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "content_type": "text/html; charset=iso-8859-1",
            "method": "curl_verified_tls",
            "sha256": "8970d3ea6059606600e849b7d48adcae7d56b01a70cc5fa34b558cab199eb021",
            "checked_utc": "2026-10-01T02:20:17.428034+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cbom-secure.json",
      "original_cell_score": 5,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_B.json",
          "before": 5,
          "after": 6,
          "reason": "The 6 anchor reads 'one-way ticket/EXPORT plus guidance'. A CycloneDX export plus concrete remediation guidance meets it on its face. The researcher gave QCecuring 6 on exactly this pattern (JSON export plus an 'Action Required' field), so leaving CBOM Secure at 5 was an inconsistency against the #2 product. The raise stops at 6 because the named Jira/ServiceNow ticketing belongs to a different product (CertSecure Manager) and no automated remediation is documented for CBOM Secure. Row total rises 7.37 -> 7.47 (142/19).",
          "evidence": "/cryptographic-discovery-inventory/: 'Audit artifacts generated in CycloneDX 1.6 and 1.7.' and 'Drive phased remediation across mapped dependencies.' Functionalities page: 'Integrate with SIEM, GRC, and ticketing platforms to streamline remediation workflows.' and 'Plan migration with crypto agility scoring and dependency analysis. Replace weak, deprecated, and quantum vulnerable cryptography first.' V1.1 page: 'so analysts know what to fix'. On /integration/, the ServiceNow ('Automate Certificate Issue Tracking...') and Jira ('Raises and syncs Jira tickets...') entries are tagged 'Certsecure Manager', not CBOM Secure."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cbom-secure/C7",
      "product": "CBOM Secure",
      "slug": "cbom-secure",
      "criterion": "C7",
      "final_score": 8,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor lists dashboards, KPIs and framework mapping, but no public sample report or assessed mapping accuracy.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.encryptionconsulting.com/cryptographic-posture-management/"
        ],
        "sources": [
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "fec92c1e70f1549e7251b20c4fd270f254d4e4c6ac0d97fa6044e4e528d1d893",
            "checked_utc": "2026-10-01T02:20:17.371524+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "status": "406",
            "final": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
            "content_type": "text/html; charset=iso-8859-1",
            "method": "curl_verified_tls",
            "sha256": "8970d3ea6059606600e849b7d48adcae7d56b01a70cc5fa34b558cab199eb021",
            "checked_utc": "2026-10-01T02:20:17.428034+00:00",
            "error": ""
          },
          {
            "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "status": "200",
            "final": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f01dd9bfbc6ccdb0a1a820d9bdf94f867d67ded6729684c482dd97f946bf2b14",
            "checked_utc": "2026-10-01T02:20:17.374390+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cbom-secure.json",
      "original_cell_score": 8,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-posture-management/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cryptonext-compass/C1",
      "product": "CryptoNext COMPASS",
      "slug": "cryptonext-compass",
      "criterion": "C1",
      "final_score": 6,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Primary Network Probe PDF confirms TLS/SSH/ISAKMP and parameters; archived longer protocol list and cross-surface count need further corroboration.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "status": "200",
            "final": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "fe57a8e52e7b802e5a9abf4c4b0cc50bc4d76d775b962002d89d8aee4d40a3ba",
            "checked_utc": "2026-10-01T02:20:11.960500+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "status": "200",
            "final": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "3c761a1eaa6ce8231f5c9f3ff3f88bd1aa0523998101bdca77ac41c605fc85f4",
            "checked_utc": "2026-10-01T02:20:16.894569+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "464241f9f9123c9344c5ed434014e9a704e507f23545e69b8d8ab4655763b14c",
            "checked_utc": "2026-10-01T02:20:17.253749+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "06a55bbf416bdfbf2921f164df35229400ec5e086bf90507df6c0010cc1cb2f5",
            "checked_utc": "2026-10-01T02:20:17.215863+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cryptonext-compass.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cryptonext-compass/C2",
      "product": "CryptoNext COMPASS",
      "slug": "cryptonext-compass",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Primary Network Probe PDF states CBOM files based on OWASP CycloneDX; PDF text extraction splits the standard name.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 1,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "status": "200",
            "final": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "fe57a8e52e7b802e5a9abf4c4b0cc50bc4d76d775b962002d89d8aee4d40a3ba",
            "checked_utc": "2026-10-01T02:20:11.960500+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cryptonext-compass.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cryptonext-compass/C3",
      "product": "CryptoNext COMPASS",
      "slug": "cryptonext-compass",
      "criterion": "C3",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Primary PDF explicitly describes passive continuous traffic monitoring; no diff/drift reporting or alert timing shown, making midpoint discretionary.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf"
        ],
        "sources": [
          {
            "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "status": "200",
            "final": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "fe57a8e52e7b802e5a9abf4c4b0cc50bc4d76d775b962002d89d8aee4d40a3ba",
            "checked_utc": "2026-10-01T02:20:11.960500+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "464241f9f9123c9344c5ed434014e9a704e507f23545e69b8d8ab4655763b14c",
            "checked_utc": "2026-10-01T02:20:17.253749+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cryptonext-compass.json",
      "original_cell_score": 5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cryptonext-compass/C4",
      "product": "CryptoNext COMPASS",
      "slug": "cryptonext-compass",
      "criterion": "C4",
      "final_score": 4,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Data sensitivity/criticality linkage is vendor-documented; formula and per-asset risk behavior are not verified.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/"
        ],
        "sources": [
          {
            "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "464241f9f9123c9344c5ed434014e9a704e507f23545e69b8d8ab4655763b14c",
            "checked_utc": "2026-10-01T02:20:17.253749+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "06a55bbf416bdfbf2921f164df35229400ec5e086bf90507df6c0010cc1cb2f5",
            "checked_utc": "2026-10-01T02:20:17.215863+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cryptonext-compass.json",
      "original_cell_score": 5,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_C.json",
          "before": 5,
          "after": 4,
          "reason": "The only documented output is a weak or non-compliant flag, which is anchor 4. The sensitivity and criticality linkage is a marketing sentence with no categories, score or mechanism. The researcher cited rubric line 19 but put the score above the cap that line sets, so it snaps to 4.",
          "evidence": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/ ('Quickly identify weak, obsolete, or non-compliant cryptographic algorithms'); https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/ ('Connect each cryptographic asset to the data it protects and its business criticality')"
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cryptonext-compass/C5",
      "product": "CryptoNext COMPASS",
      "slug": "cryptonext-compass",
      "criterion": "C5",
      "final_score": 0,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Zero is a bounded absence of published accuracy evidence, not measured error rate; archived no-hit search was not reproduced.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 5,
        "total_cited_urls": 5,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "status": "200",
            "final": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "fe57a8e52e7b802e5a9abf4c4b0cc50bc4d76d775b962002d89d8aee4d40a3ba",
            "checked_utc": "2026-10-01T02:20:11.960500+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "status": "200",
            "final": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "3c761a1eaa6ce8231f5c9f3ff3f88bd1aa0523998101bdca77ac41c605fc85f4",
            "checked_utc": "2026-10-01T02:20:16.894569+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "464241f9f9123c9344c5ed434014e9a704e507f23545e69b8d8ab4655763b14c",
            "checked_utc": "2026-10-01T02:20:17.253749+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "06a55bbf416bdfbf2921f164df35229400ec5e086bf90507df6c0010cc1cb2f5",
            "checked_utc": "2026-10-01T02:20:17.215863+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/blog/cryptonext-security-launches-cryptonext-compass-discovery-the-first-truly-open-cryptographic-assets-discovery-and-analysis-solution/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/blog/cryptonext-security-launches-cryptonext-compass-discovery-the-first-truly-open-cryptographic-assets-discovery-and-analysis-solution/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "43e0d8ddf368ee0a0d0f001e13dbe10ef3f457cb4e2252761a96f2ccf2c0e391",
            "checked_utc": "2026-10-01T02:20:17.258086+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cryptonext-compass.json",
      "original_cell_score": 0,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/en/blog/cryptonext-security-launches-cryptonext-compass-discovery-the-first-truly-open-cryptographic-assets-discovery-and-analysis-solution/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "web search 2026-09-26: site:cryptonext-security.com COMPASS \"false positive\" OR accuracy OR precision OR benchmark (no vendor hits)",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cryptonext-compass/C6",
      "product": "CryptoNext COMPASS",
      "slug": "cryptonext-compass",
      "criterion": "C6",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "API/CMDB integration is vendor-documented; ticket creation or closure is not demonstrated, consistent with guidance-only cap.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf"
        ],
        "sources": [
          {
            "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "status": "200",
            "final": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "3c761a1eaa6ce8231f5c9f3ff3f88bd1aa0523998101bdca77ac41c605fc85f4",
            "checked_utc": "2026-10-01T02:20:16.894569+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "464241f9f9123c9344c5ed434014e9a704e507f23545e69b8d8ab4655763b14c",
            "checked_utc": "2026-10-01T02:20:17.253749+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cryptonext-compass.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "cryptonext-compass/C7",
      "product": "CryptoNext COMPASS",
      "slug": "cryptonext-compass",
      "criterion": "C7",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Compliance reports are named; actual standards-to-finding mapping and report output are not independently examined.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/"
        ],
        "sources": [
          {
            "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "464241f9f9123c9344c5ed434014e9a704e507f23545e69b8d8ab4655763b14c",
            "checked_utc": "2026-10-01T02:20:17.253749+00:00",
            "error": ""
          },
          {
            "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "status": "200",
            "final": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "3c761a1eaa6ce8231f5c9f3ff3f88bd1aa0523998101bdca77ac41c605fc85f4",
            "checked_utc": "2026-10-01T02:20:16.894569+00:00",
            "error": ""
          },
          {
            "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "status": "200",
            "final": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "fe57a8e52e7b802e5a9abf4c4b0cc50bc4d76d775b962002d89d8aee4d40a3ba",
            "checked_utc": "2026-10-01T02:20:11.960500+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/cryptonext-compass.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.cryptonext-security.com/wp-content/uploads/2025/05/67eb83aa28108c0a38990ee7_20250401-CryptoNext-PR-COMPASS-Discovery-Launch-Announcement-VDEF.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://info.cryptonext-security.com/hubfs/Datasheet%20CryptoNext%20COMPASS%20Network%20Probe.pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "digicert-quantum-central/C1",
      "product": "DigiCert Quantum Central",
      "slug": "digicert-quantum-central",
      "criterion": "C1",
      "final_score": 6,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Hybrid group support is documented; the single quote does not itself prove the scored number of discovery surfaces.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 5,
        "total_cited_urls": 5,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html"
        ],
        "sources": [
          {
            "url": "https://docs.digicert.com/en/quantum-central/build-your-inventory/scan-public-endpoints.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/build-your-inventory/scan-public-endpoints.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "58a3dacaae29831bc39bf772739039ce34e76b662fd507892cfd249f6ded52c0",
            "checked_utc": "2026-10-01T02:20:08.943639+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-certificates.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-certificates.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "7206798df4f123c652841c1c1f1ea411ccba9c104a1348cd2de3311d301ad5da",
            "checked_utc": "2026-10-01T02:20:08.924931+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-keys.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-keys.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "a08ace78e7741aec09a9d7f35483df9e114ef96a6c116d88609605a4fdcf8176",
            "checked_utc": "2026-10-01T02:20:08.884213+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5e248769372bd4b537d9746e511916a25dccc6b66099ba7a20e608bc984e79d7",
            "checked_utc": "2026-10-01T02:20:09.000702+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-your-inventory.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-your-inventory.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "952497e2ededdd81834098882389872acfdc454694a64b7283c62cd1c2f6a92f",
            "checked_utc": "2026-10-01T02:20:09.033162+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/digicert-quantum-central.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.digicert.com/en/quantum-central/build-your-inventory/scan-public-endpoints.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-certificates.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-keys.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-your-inventory.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "digicert-quantum-central/C2",
      "product": "DigiCert Quantum Central",
      "slug": "digicert-quantum-central",
      "criterion": "C2",
      "final_score": 4,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents export for offline use, without a standard-schema CBOM or integrity mechanism in cited material.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html"
        ],
        "sources": [
          {
            "url": "https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2fbfff1cb38d676213ba6163e767a70c0fe6aa77ab5a5717654d95d83a5631f5",
            "checked_utc": "2026-10-01T02:20:09.168370+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/get-ai-powered-insights-about-your-assets.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/get-ai-powered-insights-about-your-assets.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "f5531c4ba12beb2f10250cec7e079127be82a1a911f3e86e1c923d2a6b9f08e7",
            "checked_utc": "2026-10-01T02:20:08.964416+00:00",
            "error": ""
          },
          {
            "url": "https://www.digicert.com/quantum-central",
            "status": "200",
            "final": "https://www.digicert.com/system/probes/health",
            "content_type": "application/json",
            "method": "curl_verified_tls",
            "sha256": "12987d1c5b40b413a561558eae5b6d3ffdac490a4a5afa22cc0f02d9525596af",
            "checked_utc": "2026-10-01T02:20:17.092467+00:00",
            "error": ""
          },
          {
            "url": "https://www.digicert.com/news/digicert-quantum-central-now-available-to-help-organizations-turn-pqc-plans-into-action",
            "status": "200",
            "final": "https://www.digicert.com/system/probes/health",
            "content_type": "application/json",
            "method": "curl_verified_tls",
            "sha256": "12987d1c5b40b413a561558eae5b6d3ffdac490a4a5afa22cc0f02d9525596af",
            "checked_utc": "2026-10-01T02:20:16.987681+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/digicert-quantum-central.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/get-ai-powered-insights-about-your-assets.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.digicert.com/quantum-central",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.digicert.com/news/digicert-quantum-central-now-available-to-help-organizations-turn-pqc-plans-into-action",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "digicert-quantum-central/C3",
      "product": "DigiCert Quantum Central",
      "slug": "digicert-quantum-central",
      "criterion": "C3",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor states imports after stale sync; automatic import is not the same as verified cryptographic diff detection.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-trust-lifecycle-manager.html"
        ],
        "sources": [
          {
            "url": "https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-trust-lifecycle-manager.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-trust-lifecycle-manager.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "07d0774b31cc644cadde4c4c956cfa8eca72107c1cd56ce5d78002ac9bcf833d",
            "checked_utc": "2026-10-01T02:20:09.168967+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "19f463f829185519868fe5bd8d44d7d808ffc32405050eaec19d781f87205a42",
            "checked_utc": "2026-10-01T02:20:09.135661+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1900ed65a671d26f58dbda3cfb08371b1995796bebd06e57274261649c082d34",
            "checked_utc": "2026-10-01T02:20:09.099762+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/digicert-quantum-central.json",
      "original_cell_score": 5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-trust-lifecycle-manager.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "digicert-quantum-central/C4",
      "product": "DigiCert Quantum Central",
      "slug": "digicert-quantum-central",
      "criterion": "C4",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Policy severity is documented; exact per-asset contextual risk scoring remains a rubric interpolation.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html"
        ],
        "sources": [
          {
            "url": "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "19f463f829185519868fe5bd8d44d7d808ffc32405050eaec19d781f87205a42",
            "checked_utc": "2026-10-01T02:20:09.135661+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5cdbde43ffbd88497b680dfd776cce158d7c82d006787a48d7ad3a093803992d",
            "checked_utc": "2026-10-01T02:20:09.049784+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5e248769372bd4b537d9746e511916a25dccc6b66099ba7a20e608bc984e79d7",
            "checked_utc": "2026-10-01T02:20:09.000702+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/digicert-quantum-central.json",
      "original_cell_score": 5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "digicert-quantum-central/C5",
      "product": "DigiCert Quantum Central",
      "slug": "digicert-quantum-central",
      "criterion": "C5",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents manual handling for false positives, without a published accuracy metric.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html"
        ],
        "sources": [
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5cdbde43ffbd88497b680dfd776cce158d7c82d006787a48d7ad3a093803992d",
            "checked_utc": "2026-10-01T02:20:09.049784+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5e248769372bd4b537d9746e511916a25dccc6b66099ba7a20e608bc984e79d7",
            "checked_utc": "2026-10-01T02:20:09.000702+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/digicert-quantum-central.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "digicert-quantum-central/C6",
      "product": "DigiCert Quantum Central",
      "slug": "digicert-quantum-central",
      "criterion": "C6",
      "final_score": 8,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor describes external task status readback, but a comparative live workflow test is absent.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.digicert.com/en/quantum-central/track-and-prioritize-crypto-remediation-tasks/track-crypto-remediation-tasks.html"
        ],
        "sources": [
          {
            "url": "https://docs.digicert.com/en/quantum-central/track-and-prioritize-crypto-remediation-tasks/track-crypto-remediation-tasks.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/track-and-prioritize-crypto-remediation-tasks/track-crypto-remediation-tasks.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "c82f53e01083d091e00229eee3e572dbebed364459b6d132caf59a61719c61d1",
            "checked_utc": "2026-10-01T02:20:09.222911+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5cdbde43ffbd88497b680dfd776cce158d7c82d006787a48d7ad3a093803992d",
            "checked_utc": "2026-10-01T02:20:09.049784+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1900ed65a671d26f58dbda3cfb08371b1995796bebd06e57274261649c082d34",
            "checked_utc": "2026-10-01T02:20:09.099762+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/digicert-quantum-central.json",
      "original_cell_score": 8,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.digicert.com/en/quantum-central/track-and-prioritize-crypto-remediation-tasks/track-crypto-remediation-tasks.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "digicert-quantum-central/C7",
      "product": "DigiCert Quantum Central",
      "slug": "digicert-quantum-central",
      "criterion": "C7",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents filtered dashboard/inventory export; no stronger report behavior is inferred.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html"
        ],
        "sources": [
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5e248769372bd4b537d9746e511916a25dccc6b66099ba7a20e608bc984e79d7",
            "checked_utc": "2026-10-01T02:20:09.000702+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5cdbde43ffbd88497b680dfd776cce158d7c82d006787a48d7ad3a093803992d",
            "checked_utc": "2026-10-01T02:20:09.049784+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1900ed65a671d26f58dbda3cfb08371b1995796bebd06e57274261649c082d34",
            "checked_utc": "2026-10-01T02:20:09.099762+00:00",
            "error": ""
          },
          {
            "url": "https://docs.digicert.com/en/quantum-central/frequently-asked-questions/what-are-the-pqc-dates-and-milestones-for-my-country-or-the-standards-body-that-i-work-with-.html",
            "status": "200",
            "final": "https://docs.digicert.com/en/quantum-central/frequently-asked-questions/what-are-the-pqc-dates-and-milestones-for-my-country-or-the-standards-body-that-i-work-with-.html",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1b1157198ceaf13824714f5066d6e20e8895964a58d23d9b4d473f6d402b8245",
            "checked_utc": "2026-10-01T02:20:09.089560+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/digicert-quantum-central.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.digicert.com/en/quantum-central/frequently-asked-questions/what-are-the-pqc-dates-and-milestones-for-my-country-or-the-standards-body-that-i-work-with-.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "fortanix-key-insight-pqc-central/C1",
      "product": "Fortanix Key Insight / PQC Central",
      "slug": "fortanix-key-insight-pqc-central",
      "criterion": "C1",
      "final_score": 9,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor documents multiple connector/surface types; cited Zeek quote alone is not a complete depth/hybrid proof.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 6,
        "total_cited_urls": 6,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://support.fortanix.com/docs/fortanix-key-insight-for-on-premises-concepts"
        ],
        "sources": [
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "787178c5674c6d1dcb5ea892ca3b3d3594367379b741f15f7cd3755ab6f0e389",
            "checked_utc": "2026-10-01T02:20:15.212415+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-for-on-premises-concepts",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-on-premises-connection-concepts",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "26ea38cb4eab832a98172370722e7e105cef011dc3ccdf02ec7188d0641f7c26",
            "checked_utc": "2026-10-01T02:20:14.940391+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-concepts-for-all-connections",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2e743f701f814b4345db2b4b00d3c39fcbae5675ca9d3ba02d48ef8a87c40e2f",
            "checked_utc": "2026-10-01T02:20:14.391408+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-on-premises-source-code",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-on-premises-source-code",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "a42a43734454cb20b0cf15f598c7769fc5c70f4d8a38428aa91c3b769b8b3934",
            "checked_utc": "2026-10-01T02:20:14.863862+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "87fda3bb41778dce9f8bb70f6b804a3093abccf08af7205267c42935a4ca1c4f",
            "checked_utc": "2026-10-01T02:20:15.777865+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/26-05-ki-may-15-2026.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/26-05-ki-may-15-2026.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "e4b8f30175e7f600f3a9eed3d1df2430a7312e6029842520254a2744b3452f79",
            "checked_utc": "2026-10-01T02:20:13.802921+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/fortanix-key-insight-pqc-central.json",
      "original_cell_score": 9,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-for-on-premises-concepts",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-on-premises-source-code",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/26-05-ki-may-15-2026.md",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "fortanix-key-insight-pqc-central/C2",
      "product": "Fortanix Key Insight / PQC Central",
      "slug": "fortanix-key-insight-pqc-central",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor explicitly documents CycloneDX CBOM JSON export across named environments; no signed-export mechanism.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://support.fortanix.com/docs/25-07-ki-july-16-2025.md"
        ],
        "sources": [
          {
            "url": "https://support.fortanix.com/docs/25-07-ki-july-16-2025.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/25-07-ki-july-16-2025.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "47f3c0a4fbd4d9591845245eb8d795e4b27738696cb1f473ef89b4508b53d87c",
            "checked_utc": "2026-10-01T02:20:13.703730+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-concepts-for-all-connections",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2e743f701f814b4345db2b4b00d3c39fcbae5675ca9d3ba02d48ef8a87c40e2f",
            "checked_utc": "2026-10-01T02:20:14.391408+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1843501fa6666441b14cd5de03da2c9e1db48cf308964eb5f473d2957af38ece",
            "checked_utc": "2026-10-01T02:20:15.385750+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/fortanix-key-insight-pqc-central.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://support.fortanix.com/docs/25-07-ki-july-16-2025.md",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "fortanix-key-insight-pqc-central/C3",
      "product": "Fortanix Key Insight / PQC Central",
      "slug": "fortanix-key-insight-pqc-central",
      "criterion": "C3",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor documents manual RESCAN and asset updates; scheduled diff/drift automation needed for higher anchor is absent.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md"
        ],
        "sources": [
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1843501fa6666441b14cd5de03da2c9e1db48cf308964eb5f473d2957af38ece",
            "checked_utc": "2026-10-01T02:20:15.385750+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-file-system-and-network-scanner-agent-configuration-linux",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-file-system-and-network-scanner-agent-configuration-linux",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "669c5cf04239eaa9973598c080c894fce8eb1cb239e40ed1f7dad71b7e4b6d79",
            "checked_utc": "2026-10-01T02:20:14.773857+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "042f3f1cfbe0ea45328880c4705654cb04c435d9b0053e3e673550fcdff258df",
            "checked_utc": "2026-10-01T02:20:15.167719+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/fortanix-key-insight-pqc-central.json",
      "original_cell_score": 5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-file-system-and-network-scanner-agent-configuration-linux",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "fortanix-key-insight-pqc-central/C4",
      "product": "Fortanix Key Insight / PQC Central",
      "slug": "fortanix-key-insight-pqc-central",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor documents categorical risk counts with context; scoring details and validation are not published.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md"
        ],
        "sources": [
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1843501fa6666441b14cd5de03da2c9e1db48cf308964eb5f473d2957af38ece",
            "checked_utc": "2026-10-01T02:20:15.385750+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "87fda3bb41778dce9f8bb70f6b804a3093abccf08af7205267c42935a4ca1c4f",
            "checked_utc": "2026-10-01T02:20:15.777865+00:00",
            "error": ""
          },
          {
            "url": "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness",
            "status": "200",
            "final": "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "d181f896a79129656474fdaf2cb10b081d5aae1e0aaeabee1268978165a97db6",
            "checked_utc": "2026-10-01T02:20:17.762501+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/fortanix-key-insight-pqc-central.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "fortanix-key-insight-pqc-central/C5",
      "product": "Fortanix Key Insight / PQC Central",
      "slug": "fortanix-key-insight-pqc-central",
      "criterion": "C5",
      "final_score": 0,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Zero reflects no metric in bounded accessible docs, not an observed correctness result.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 7,
        "total_cited_urls": 7,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-concepts-for-all-connections",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2e743f701f814b4345db2b4b00d3c39fcbae5675ca9d3ba02d48ef8a87c40e2f",
            "checked_utc": "2026-10-01T02:20:14.391408+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "787178c5674c6d1dcb5ea892ca3b3d3594367379b741f15f7cd3755ab6f0e389",
            "checked_utc": "2026-10-01T02:20:15.212415+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "87fda3bb41778dce9f8bb70f6b804a3093abccf08af7205267c42935a4ca1c4f",
            "checked_utc": "2026-10-01T02:20:15.777865+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-for-on-premises-concepts",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-on-premises-connection-concepts",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "26ea38cb4eab832a98172370722e7e105cef011dc3ccdf02ec7188d0641f7c26",
            "checked_utc": "2026-10-01T02:20:14.940391+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "042f3f1cfbe0ea45328880c4705654cb04c435d9b0053e3e673550fcdff258df",
            "checked_utc": "2026-10-01T02:20:15.167719+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/key-insight-release-notes.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/key-insight-release-notes.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "89e7b76317bdf2213a6be2f9b6a6c001612b52fc2ec22095f93ae05f1dcc59fb",
            "checked_utc": "2026-10-01T02:20:15.485698+00:00",
            "error": ""
          },
          {
            "url": "https://www.fortanix.com/platform/key-insight",
            "status": "200",
            "final": "https://www.fortanix.com/platform/key-insight",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "8d73bd9a889ffe0975e4af99691afa84811bc5ab72760ce0984eb3b929fd4685",
            "checked_utc": "2026-10-01T02:20:17.794110+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/fortanix-key-insight-pqc-central.json",
      "original_cell_score": 0,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-concepts",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-pqc-central-concepts",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-pqc-central",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-for-on-premises-concepts",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/key-insight-release-notes.md",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.fortanix.com/platform/key-insight",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "web search 2026-09-26: site:support.fortanix.com \"Key Insight\" \"false positive\" OR accuracy OR precision (no correctness content)",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "fortanix-key-insight-pqc-central/C6",
      "product": "Fortanix Key Insight / PQC Central",
      "slug": "fortanix-key-insight-pqc-central",
      "criterion": "C6",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor says corrective actions can occur in platform but gives no reproducible ticket/action mechanism.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://support.fortanix.com/docs/fortanix-key-insight-overview"
        ],
        "sources": [
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1843501fa6666441b14cd5de03da2c9e1db48cf308964eb5f473d2957af38ece",
            "checked_utc": "2026-10-01T02:20:15.385750+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "042f3f1cfbe0ea45328880c4705654cb04c435d9b0053e3e673550fcdff258df",
            "checked_utc": "2026-10-01T02:20:15.167719+00:00",
            "error": ""
          },
          {
            "url": "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness",
            "status": "200",
            "final": "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "d181f896a79129656474fdaf2cb10b081d5aae1e0aaeabee1268978165a97db6",
            "checked_utc": "2026-10-01T02:20:17.762501+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/fortanix-key-insight-pqc-central.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-overview",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.fortanix.com/company/pr/2025/06/fortanix-announces-pqc-central-to-accelerate-post-quantum-readiness",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "fortanix-key-insight-pqc-central/C7",
      "product": "Fortanix Key Insight / PQC Central",
      "slug": "fortanix-key-insight-pqc-central",
      "criterion": "C7",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "PDF assessment report is documented; archived excerpt not reproduced and framework-to-report mapping remains unverified.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1843501fa6666441b14cd5de03da2c9e1db48cf308964eb5f473d2957af38ece",
            "checked_utc": "2026-10-01T02:20:15.385750+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/fortanix-key-insight-cryptographic-policy-management",
            "status": "200",
            "final": "https://support.fortanix.com/docs/fortanix-key-insight-cryptographic-policy-management",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "26a4aa4cdade1ddba1a8b8d287d4ffe1423fd35f29bc7cf7f92988466d3e676c",
            "checked_utc": "2026-10-01T02:20:14.495507+00:00",
            "error": ""
          },
          {
            "url": "https://support.fortanix.com/docs/programmatic-access-to-fortanix-key-insight-apis",
            "status": "200",
            "final": "https://support.fortanix.com/docs/programmatic-access-to-fortanix-key-insight-apis",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "0c306869669cbee13019e7765678d0e0517c286ec4e013d3e2f85bc13491ce85",
            "checked_utc": "2026-10-01T02:20:15.890494+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/fortanix-key-insight-pqc-central.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-user-interface-components-aws.md",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/fortanix-key-insight-cryptographic-policy-management",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://support.fortanix.com/docs/programmatic-access-to-fortanix-key-insight-apis",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "ibm-guardium-quantum-safe/C1",
      "product": "IBM Guardium + Quantum Safe",
      "slug": "ibm-guardium-quantum-safe",
      "criterion": "C1",
      "final_score": 8,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "IBM lists source-code languages; the 5-6-surface count relies on additional product documents and no common runtime test.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 5,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview"
        ],
        "sources": [
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/discovery/gcm_discovering_db_and_app.html",
            "status": "302",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=objects-creating-discovery-profile",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": null,
            "checked_utc": "2026-10-01T02:20:29.677562+00:00",
            "error": "curl: (28) Operation timed out after 2001 milliseconds with 0 bytes received"
          },
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/Plug-ins/available-plug-ins.html",
            "status": "302",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=ins-available-plug",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": null,
            "checked_utc": "2026-10-01T02:20:29.740649+00:00",
            "error": "curl: (28) Operation timed out after 2001 milliseconds with 0 bytes received"
          },
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/inventory/Inventory_overview/cryptographic-object-overview.html",
            "status": "302",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=inventory-cryptographic-object-overview",
            "content_type": "text/plain; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": null,
            "checked_utc": "2026-10-01T02:20:30.178693+00:00",
            "error": "curl: (28) Operation timed out after 2001 milliseconds with 0 bytes received"
          },
          {
            "url": "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "04218ef29b37e49f5b75b84c4034f1903c66c5d560ded14e569a07c275c5a6c9",
            "checked_utc": "2026-10-01T02:20:38.017825+00:00",
            "error": ""
          },
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/post_quantum_cryptography/post_quantum_cryptography.html",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=post-quantum-cryptography-readiness",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "a25bf527c570503025063de0ee97578ccb15019df211e799a27e30afeee3b2ed",
            "checked_utc": "2026-10-01T02:20:28.012236+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/ibm-guardium-quantum-safe.json",
      "original_cell_score": 8,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/discovery/gcm_discovering_db_and_app.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/Plug-ins/available-plug-ins.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/inventory/Inventory_overview/cryptographic-object-overview.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/post_quantum_cryptography/post_quantum_cryptography.html",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "ibm-guardium-quantum-safe/C2",
      "product": "IBM Guardium + Quantum Safe",
      "slug": "ibm-guardium-quantum-safe",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "IBM documentation describes CBOM/CSV/Findings.JSON output; no signature/integrity method cited.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview"
        ],
        "sources": [
          {
            "url": "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "04218ef29b37e49f5b75b84c4034f1903c66c5d560ded14e569a07c275c5a6c9",
            "checked_utc": "2026-10-01T02:20:38.017825+00:00",
            "error": ""
          },
          {
            "url": "https://research.ibm.com/blog/quantum-safe-cbomkit",
            "status": "200",
            "final": "https://research.ibm.com/blog/quantum-safe-cbomkit",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "05d55b49b9354ff23de662436941d0f977b5ce4cb37107fdf43a9bfdbb0f91f0",
            "checked_utc": "2026-10-01T02:20:14.079102+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/cbomkit/cbomkit",
            "status": "200",
            "final": "https://github.com/cbomkit/cbomkit",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "dd3047d5d12a521778b78970f868c84490a27108b25bbbfb760a288fcb4d7034",
            "checked_utc": "2026-10-01T02:20:10.901451+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/ibm-guardium-quantum-safe.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://research.ibm.com/blog/quantum-safe-cbomkit",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/cbomkit/cbomkit",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "ibm-guardium-quantum-safe/C3",
      "product": "IBM Guardium + Quantum Safe",
      "slug": "ibm-guardium-quantum-safe",
      "criterion": "C3",
      "final_score": 4,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor alert/policy wording does not establish crypto-level drift history; final point-in-time cap is conservative.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.ibm.com/docs/en/gdsc/3.x?topic=guardium-quantum-safe"
        ],
        "sources": [
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/discovery/gcm_managing_discovery.html",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=objects-managing-discovery-profiles",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1f08f0d41c66afeb3a8c04f92d4c18674001f0cbf4ea225cd4c9cfb3d5f91eeb",
            "checked_utc": "2026-10-01T02:20:27.382572+00:00",
            "error": ""
          },
          {
            "url": "https://www.ibm.com/docs/en/gdsc/3.x?topic=guardium-quantum-safe",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/gdsc/3.x?topic=guardium-quantum-safe",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "7cf7f3ccf8b463487c18e19551eaf3b6a3aa29909cc21c12fe65b42b5eb080aa",
            "checked_utc": "2026-10-01T02:20:30.006023+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/ibm-guardium-quantum-safe.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/discovery/gcm_managing_discovery.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.ibm.com/docs/en/gdsc/3.x?topic=guardium-quantum-safe",
          "accessibility": true,
          "excerpt_reproduced": true
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "ibm-guardium-quantum-safe/C4",
      "product": "IBM Guardium + Quantum Safe",
      "slug": "ibm-guardium-quantum-safe",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Verified-TLS IBM product documentation reproduces CVSS-style PQC violation wording, but asset-score calibration and current product-suite attribution remain untested.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.ibm.com/docs/en/SSQQH4_2.0.0/post_quantum_cryptography/post_quantum_cryptography.html"
        ],
        "sources": [
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/post_quantum_cryptography/post_quantum_cryptography.html",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=post-quantum-cryptography-readiness",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "a25bf527c570503025063de0ee97578ccb15019df211e799a27e30afeee3b2ed",
            "checked_utc": "2026-10-01T02:20:28.012236+00:00",
            "error": ""
          },
          {
            "url": "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=violations-types-policy-in-guardium-cryptography-manager",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=violations-types-policy-in-guardium-cryptography-manager",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5180769c87467a20e3b60c57fa7fc03816493cd603f8e99939dcccac1d88ed5c",
            "checked_utc": "2026-10-01T02:20:30.526850+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/ibm-guardium-quantum-safe.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/post_quantum_cryptography/post_quantum_cryptography.html",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=violations-types-policy-in-guardium-cryptography-manager",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "ibm-guardium-quantum-safe/C5",
      "product": "IBM Guardium + Quantum Safe",
      "slug": "ibm-guardium-quantum-safe",
      "criterion": "C5",
      "final_score": 0,
      "weight_numerator": 2,
      "evidence_class": "external_paper_not_product",
      "source_review_evidence_class": "external_paper_not_product",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Final zero correctly excludes a CBOMkit benchmark not tied to Guardium/Quantum Safe; absence of IBM-specific metric is bounded.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://arxiv.org/html/2608.04857"
        ],
        "sources": [
          {
            "url": "https://arxiv.org/abs/2608.04857v1",
            "status": "200",
            "final": "https://arxiv.org/abs/2608.04857v1",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "354d577341f3d672f031640dc0d9f6621daa5d6295a405e193381a8fb57d648a",
            "checked_utc": "2026-10-01T02:20:07.611359+00:00",
            "error": ""
          },
          {
            "url": "https://arxiv.org/html/2608.04857",
            "status": "200",
            "final": "https://arxiv.org/html/2608.04857",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d148f4315a952802aac8545cd2118152d24e776264eefa3570a897853201db6",
            "checked_utc": "2026-10-01T02:20:07.484184+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/ibm-guardium-quantum-safe.json",
      "original_cell_score": 6,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_B.json",
          "before": 6,
          "after": 0,
          "reason": "The re-score says the CBOMkit footing is 'consistent with C1 and C2', but that does not hold: the C1 rationale uses no CBOMkit evidence, and the C2 quote comes from the QSE overview (the cbomkit README adds nothing). CBOMkit therefore carries weight in C5 only. The metric measures an Apache-2.0 community tool that the paper credits to PQCA and that is now governed outside IBM. No IBM product doc (GQS 3.x, GCM 2.0.x, QSE 2.x) says it uses that engine. No metric or false-positive handling was found in the Guardium/QSE docs searched, so anchor 0 applies. What would restore 6 (and only 6, because n=70 < 100 and there is no dual annotation): an IBM doc stating that GQS, GCM or QSE uses the sonar-cryptography/CBOMkit-hyperion engine. Row total falls 6.21 -> 5.58 (106/19). Anchor 8, which the published 15 Aug correction used, fails on every axis whatever the scope.",
          "evidence": "arXiv 2608.04857v1 HTML: 'we ran CBOMkit-hyperion (the PQCA sonar-cryptography plugin, v1.6.1) on the Go-invocation subset of Cryben'; Table 2 'All Go CBOMkit 70 38 7 32 0.84 0.54 0.66'. The paper contains zero occurrences of 'IBM' or 'Guardium'. github.com/IBM/sonar-cryptography and github.com/IBM/cbomkit return 301 to github.com/cbomkit/*; GitHub API: cbomkit/cbomkit license Apache-2.0, owner 'cbomkit'. research.ibm.com/blog/quantum-safe-cbomkit: 'IBM Research has developed and open-sourced CBOMkit' and 'IBM is donating its CBOM toolset to the Linux Foundation'; the blog links CBOMkit to no Guardium, GCM or QSE product. The QSE 2.x overview (WebFetch) mentions no sonar-cryptography, CBOMkit, hyperion or SonarQube, and has no accuracy, precision, recall or false-positive statement. A web search for Guardium Cryptography Manager / Guardium Quantum Safe together with CBOMkit / sonar-cryptography returned no link. A third party, QCecuring's import docs (docs.qcecuring.com/cbom/platform/import-export), lists 'cbomkit-theia — IBM's open-source CBOM scanner' and 'IBM Quantum Safe Explorer' as SEPARATE sources."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://arxiv.org/abs/2608.04857v1",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://arxiv.org/html/2608.04857",
          "accessibility": true,
          "excerpt_reproduced": true
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "ibm-guardium-quantum-safe/C6",
      "product": "IBM Guardium + Quantum Safe",
      "slug": "ibm-guardium-quantum-safe",
      "criterion": "C6",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Jira/ServiceNow ticket creation is documented; automated remediation action beyond a ticket is not tested.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.ibm.com/docs/en/SSQQH4_2.0.0/remediation/creating_tickets.html"
        ],
        "sources": [
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/remediation/creating_tickets.html",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=violations-creating-ticket",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "769eeb3458340008e905a5e028912675a69e26b6bc53fce2c86f9faa21767faa",
            "checked_utc": "2026-10-01T02:20:37.615956+00:00",
            "error": ""
          },
          {
            "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/remediation/gcm_ai_enabled_remediation.html",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=violations-ai-enabled-violation-management",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "e4d719aaea60621eff64ef0aca24b6c20687b18169e15574c2e38282f8dc2ae4",
            "checked_utc": "2026-10-01T02:20:39.735469+00:00",
            "error": ""
          },
          {
            "url": "https://www.ibm.com/products/guardium-cryptography-manager",
            "status": "200",
            "final": "https://www.ibm.com/products/guardium-cryptography-manager",
            "content_type": "text/html;charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1ce6ef5312223fe2930989537940d718abd95839adf932cb7c18aa1d5257dadb",
            "checked_utc": "2026-10-01T02:20:39.589110+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/ibm-guardium-quantum-safe.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/remediation/creating_tickets.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.ibm.com/docs/en/SSQQH4_2.0.0/remediation/gcm_ai_enabled_remediation.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.ibm.com/products/guardium-cryptography-manager",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "ibm-guardium-quantum-safe/C7",
      "product": "IBM Guardium + Quantum Safe",
      "slug": "ibm-guardium-quantum-safe",
      "criterion": "C7",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "IBM documents PDF dashboard export, no stronger report claim inferred.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=dashboards-cryptographic-posture-management"
        ],
        "sources": [
          {
            "url": "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=dashboards-cryptographic-posture-management",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=dashboards-cryptographic-posture-management",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "b94981d0c93ff3e8dc151e52bd966ac89f15f0377b280e4a3207c7451b141c22",
            "checked_utc": "2026-10-01T02:20:38.308489+00:00",
            "error": ""
          },
          {
            "url": "https://www.ibm.com/products/guardium-cryptography-manager",
            "status": "200",
            "final": "https://www.ibm.com/products/guardium-cryptography-manager",
            "content_type": "text/html;charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1ce6ef5312223fe2930989537940d718abd95839adf932cb7c18aa1d5257dadb",
            "checked_utc": "2026-10-01T02:20:39.589110+00:00",
            "error": ""
          },
          {
            "url": "https://www.ibm.com/docs/en/guardium-cm/2.0.0",
            "status": "200",
            "final": "https://www.ibm.com/docs/en/guardium-cm/2.0.x",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "dcd91c399b17f83c15464905d17152852fd1d4849c2faac7217888d4ea0d09c6",
            "checked_utc": "2026-10-01T02:20:39.892011+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/ibm-guardium-quantum-safe.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=dashboards-cryptographic-posture-management",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.ibm.com/products/guardium-cryptography-manager",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.ibm.com/docs/en/guardium-cm/2.0.0",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "isara-advance/C1",
      "product": "ISARA Advance",
      "slug": "isara-advance",
      "criterion": "C1",
      "final_score": 8,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor lists many surfaces broadly; independently checked detail is insufficient for exact 5-6-surface depth anchor.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.isara.com/"
        ],
        "sources": [
          {
            "url": "https://www.isara.com/",
            "status": "200",
            "final": "https://www.isara.com/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "3ceb785a9f78acabbccc14a0afda5e4900ba9d8629158d1d46561be2bbfeda4d",
            "checked_utc": "2026-10-01T02:20:38.695991+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "status": "200",
            "final": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "ff401cabb78157f2310170b591556ffd09703adb450da30b74d640dcba2acbf9",
            "checked_utc": "2026-10-01T02:20:39.990779+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/partner-msazure.html",
            "status": "200",
            "final": "https://www.isara.com/partner-msazure.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f75f888a74756622e90caf09959f2826a5e57247282bd5a6a7bdb0fa4094a77a",
            "checked_utc": "2026-10-01T02:20:39.810114+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "status": "200",
            "final": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "98f61d78b6ad6c20f7a31689d3c941a1b5c7cb8ca642494f53fea733c1a53dd6",
            "checked_utc": "2026-10-01T02:20:39.070552+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/isara-advance.json",
      "original_cell_score": 8,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.isara.com/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/partner-msazure.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "isara-advance/C2",
      "product": "ISARA Advance",
      "slug": "isara-advance",
      "criterion": "C2",
      "final_score": 3,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Primary Azure whitepaper documents dashboards/APIs but no explicit standard/proprietary export; midpoint three is discretionary.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf"
        ],
        "sources": [
          {
            "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "status": "200",
            "final": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "98f61d78b6ad6c20f7a31689d3c941a1b5c7cb8ca642494f53fea733c1a53dd6",
            "checked_utc": "2026-10-01T02:20:39.070552+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/",
            "status": "200",
            "final": "https://www.isara.com/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "3ceb785a9f78acabbccc14a0afda5e4900ba9d8629158d1d46561be2bbfeda4d",
            "checked_utc": "2026-10-01T02:20:38.695991+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "status": "200",
            "final": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "ff401cabb78157f2310170b591556ffd09703adb450da30b74d640dcba2acbf9",
            "checked_utc": "2026-10-01T02:20:39.990779+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/blog-posts/beyond-the-cbom-hype-setting-the-record-straight.html",
            "status": "200",
            "final": "https://www.isara.com/blog-posts/beyond-the-cbom-hype-setting-the-record-straight.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "2c2967f6184feccfd43cba9119b986cef8e4bd4b6d57dbf534816a6660ceb27a",
            "checked_utc": "2026-10-01T02:20:39.417501+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/isara-advance.json",
      "original_cell_score": 3,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/blog-posts/beyond-the-cbom-hype-setting-the-record-straight.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "isara-advance/C3",
      "product": "ISARA Advance",
      "slug": "isara-advance",
      "criterion": "C3",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Primary Azure whitepaper documents continuous monitoring and historical trends; no tamper-evident mechanism shown.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf"
        ],
        "sources": [
          {
            "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "status": "200",
            "final": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "98f61d78b6ad6c20f7a31689d3c941a1b5c7cb8ca642494f53fea733c1a53dd6",
            "checked_utc": "2026-10-01T02:20:39.070552+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/partner-msazure.html",
            "status": "200",
            "final": "https://www.isara.com/partner-msazure.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f75f888a74756622e90caf09959f2826a5e57247282bd5a6a7bdb0fa4094a77a",
            "checked_utc": "2026-10-01T02:20:39.810114+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/solutions.html",
            "status": "200",
            "final": "https://www.isara.com/solutions.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "30a3ad785e9e0814b367a16d465673e52963f2f21f3c9b0b84907426e559483f",
            "checked_utc": "2026-10-01T02:20:40.186575+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/isara-advance.json",
      "original_cell_score": 6,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_C.json",
          "before": 6,
          "after": 5,
          "reason": "The researcher's 6 depended on change tracking. On the fetched whitepaper, the 'track changes' line sits in a generic principles list, not in the ISARA Advance capability list. What ISARA Advance itself documents is continuous monitoring plus trend and history views, with no diff or drift output. Under the rule applied to O3 and Fortanix, that is 5. The published 8 was carried_thin, and nothing restores it.",
          "evidence": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf (product section: 'Supports continuous monitoring and historical analysis of cryptographic trends'; 'Continuously track changes' appears only under generic 'Key Principles'); https://www.isara.com/partner-msazure.html ('snapshots, trend views, and burn-down reporting')"
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/partner-msazure.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/solutions.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "isara-advance/C4",
      "product": "ISARA Advance",
      "slug": "isara-advance",
      "criterion": "C4",
      "final_score": 7,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Primary whitepaper names algorithm strength, key size and usage context risk scores; no lifetime/HNDL or ranking formula.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf"
        ],
        "sources": [
          {
            "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "status": "200",
            "final": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
            "content_type": "application/pdf",
            "method": "curl_verified_tls",
            "sha256": "98f61d78b6ad6c20f7a31689d3c941a1b5c7cb8ca642494f53fea733c1a53dd6",
            "checked_utc": "2026-10-01T02:20:39.070552+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/solutions.html",
            "status": "200",
            "final": "https://www.isara.com/solutions.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "30a3ad785e9e0814b367a16d465673e52963f2f21f3c9b0b84907426e559483f",
            "checked_utc": "2026-10-01T02:20:40.186575+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "status": "200",
            "final": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "ff401cabb78157f2310170b591556ffd09703adb450da30b74d640dcba2acbf9",
            "checked_utc": "2026-10-01T02:20:39.990779+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/isara-advance.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/solutions.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "isara-advance/C5",
      "product": "ISARA Advance",
      "slug": "isara-advance",
      "criterion": "C5",
      "final_score": 0,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Zero is a bounded lack of public accuracy metric; source marketing claim is not a benchmark.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 5,
        "total_cited_urls": 5,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.isara.com/partner-msazure.html"
        ],
        "sources": [
          {
            "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "status": "200",
            "final": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "ff401cabb78157f2310170b591556ffd09703adb450da30b74d640dcba2acbf9",
            "checked_utc": "2026-10-01T02:20:39.990779+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/partner-msazure.html",
            "status": "200",
            "final": "https://www.isara.com/partner-msazure.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f75f888a74756622e90caf09959f2826a5e57247282bd5a6a7bdb0fa4094a77a",
            "checked_utc": "2026-10-01T02:20:39.810114+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/",
            "status": "200",
            "final": "https://www.isara.com/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "3ceb785a9f78acabbccc14a0afda5e4900ba9d8629158d1d46561be2bbfeda4d",
            "checked_utc": "2026-10-01T02:20:38.695991+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/solutions.html",
            "status": "200",
            "final": "https://www.isara.com/solutions.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "30a3ad785e9e0814b367a16d465673e52963f2f21f3c9b0b84907426e559483f",
            "checked_utc": "2026-10-01T02:20:40.186575+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/resources/index.html",
            "status": "200",
            "final": "https://www.isara.com/resources/index.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15ac8b320fa431ce44e05eaa15dd9164584a23e7d1e9fe8be0b38a238e17204a",
            "checked_utc": "2026-10-01T02:20:40.257012+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/isara-advance.json",
      "original_cell_score": 0,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/partner-msazure.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.isara.com/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/solutions.html",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/resources/index.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "isara-advance/C6",
      "product": "ISARA Advance",
      "slug": "isara-advance",
      "criterion": "C6",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents ticket workflows and CMDB integration, without closure test.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html"
        ],
        "sources": [
          {
            "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "status": "200",
            "final": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "ff401cabb78157f2310170b591556ffd09703adb450da30b74d640dcba2acbf9",
            "checked_utc": "2026-10-01T02:20:39.990779+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/",
            "status": "200",
            "final": "https://www.isara.com/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "3ceb785a9f78acabbccc14a0afda5e4900ba9d8629158d1d46561be2bbfeda4d",
            "checked_utc": "2026-10-01T02:20:38.695991+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/isara-advance.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.isara.com/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "isara-advance/C7",
      "product": "ISARA Advance",
      "slug": "isara-advance",
      "criterion": "C7",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor executive/trend views are documented; exact framework mapping and report artifact not tested.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.isara.com/partner-msazure.html"
        ],
        "sources": [
          {
            "url": "https://www.isara.com/partner-msazure.html",
            "status": "200",
            "final": "https://www.isara.com/partner-msazure.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "f75f888a74756622e90caf09959f2826a5e57247282bd5a6a7bdb0fa4094a77a",
            "checked_utc": "2026-10-01T02:20:39.810114+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/",
            "status": "200",
            "final": "https://www.isara.com/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "3ceb785a9f78acabbccc14a0afda5e4900ba9d8629158d1d46561be2bbfeda4d",
            "checked_utc": "2026-10-01T02:20:38.695991+00:00",
            "error": ""
          },
          {
            "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "status": "200",
            "final": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "ff401cabb78157f2310170b591556ffd09703adb450da30b74d640dcba2acbf9",
            "checked_utc": "2026-10-01T02:20:39.990779+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/isara-advance.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.isara.com/partner-msazure.html",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.isara.com/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.isara.com/products/isara-advance-cryptographic-inventory-and-risk-assessment-tool.html",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "keyfactor-agilesec-command/C1",
      "product": "Keyfactor AgileSec + Command",
      "slug": "keyfactor-agilesec-command",
      "criterion": "C1",
      "final_score": 9,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Hybrid group handling is documented, but full surface count and parameter depth require multi-document reconciliation.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 5,
        "total_cited_urls": 5,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes"
        ],
        "sources": [
          {
            "url": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "a4fafefeb20de58233eda5b7f9737f7907accdd8d3e2281064c414cfe08396d2",
            "checked_utc": "2026-10-01T02:20:09.434066+00:00",
            "error": ""
          },
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/modules",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/modules",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "9bb53b2cb179badd8305f38bf9f58034f495c2a0083b731697cc3a409da8e6cd",
            "checked_utc": "2026-10-01T02:20:09.619650+00:00",
            "error": ""
          },
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/cipher-insights-sensor-user-guide",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/cipher-insights-sensor-user-guide",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "3109b8a62ba8456eee40f73c6b88b4d7da12629bf3953416fdd48763dc8deb18",
            "checked_utc": "2026-10-01T02:20:09.565540+00:00",
            "error": ""
          },
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "041c6d9e610fdfceafc38780f352e3f283778f0e5a69f1f2d2e8331195c295e6",
            "checked_utc": "2026-10-01T02:20:09.414908+00:00",
            "error": ""
          },
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-6-release-notes",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-6-release-notes",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "796536d71bd1460c8aa28b57d00c3cce180b4afefe1099c2f2712f6396e46e6e",
            "checked_utc": "2026-10-01T02:20:09.424988+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/keyfactor-agilesec-command.json",
      "original_cell_score": 9,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/modules",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/cipher-insights-sensor-user-guide",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-6-release-notes",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "keyfactor-agilesec-command/C2",
      "product": "Keyfactor AgileSec + Command",
      "slug": "keyfactor-agilesec-command",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor explicitly documents CycloneDX CBOM 1.6 export per source, without export signature.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes"
        ],
        "sources": [
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "1c5b2ec4651c4bcd394c910e9abfdde96d5c7a9ec37de5ff793bbd007e354754",
            "checked_utc": "2026-10-01T02:20:09.371245+00:00",
            "error": ""
          },
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "041c6d9e610fdfceafc38780f352e3f283778f0e5a69f1f2d2e8331195c295e6",
            "checked_utc": "2026-10-01T02:20:09.414908+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/keyfactor-agilesec-command.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "keyfactor-agilesec-command/C3",
      "product": "Keyfactor AgileSec + Command",
      "slug": "keyfactor-agilesec-command",
      "criterion": "C3",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents findings resolved across full scans, a concrete change-state rule.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview"
        ],
        "sources": [
          {
            "url": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "a4fafefeb20de58233eda5b7f9737f7907accdd8d3e2281064c414cfe08396d2",
            "checked_utc": "2026-10-01T02:20:09.434066+00:00",
            "error": ""
          },
          {
            "url": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
            "status": "200",
            "final": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "191132cc98f15a737cb59e7cf50cd7258349ba986d5ba8eb4b7acf9c352f8a43",
            "checked_utc": "2026-10-01T02:20:40.105206+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/keyfactor-agilesec-command.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "keyfactor-agilesec-command/C4",
      "product": "Keyfactor AgileSec + Command",
      "slug": "keyfactor-agilesec-command",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents compliant/high/medium/low classification; no numerical asset model inferred.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview"
        ],
        "sources": [
          {
            "url": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "a4fafefeb20de58233eda5b7f9737f7907accdd8d3e2281064c414cfe08396d2",
            "checked_utc": "2026-10-01T02:20:09.434066+00:00",
            "error": ""
          },
          {
            "url": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
            "status": "200",
            "final": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "191132cc98f15a737cb59e7cf50cd7258349ba986d5ba8eb4b7acf9c352f8a43",
            "checked_utc": "2026-10-01T02:20:40.105206+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/keyfactor-agilesec-command.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.keyfactor.com/agilesec/3.4/sensors-architecture-and-overview",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "keyfactor-agilesec-command/C5",
      "product": "Keyfactor AgileSec + Command",
      "slug": "keyfactor-agilesec-command",
      "criterion": "C5",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor records false-positive correction for secure key exchange, without published precision/recall.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 1,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes"
        ],
        "sources": [
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "041c6d9e610fdfceafc38780f352e3f283778f0e5a69f1f2d2e8331195c295e6",
            "checked_utc": "2026-10-01T02:20:09.414908+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/keyfactor-agilesec-command.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-5-1-release-notes",
          "accessibility": true,
          "excerpt_reproduced": true
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "keyfactor-agilesec-command/C6",
      "product": "Keyfactor AgileSec + Command",
      "slug": "keyfactor-agilesec-command",
      "criterion": "C6",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Connector API query is documented; ticket creation/automated remediation attribution requires closer source binding.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr"
        ],
        "sources": [
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "4fec73642a421af1880df2fa18855627be44aa94a7085428f20a82960c3e6b00",
            "checked_utc": "2026-10-01T02:20:09.492202+00:00",
            "error": ""
          },
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr-operations",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr-operations",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "7e9a8ef4f17240f83efea43df67403d133dec6664b325ca2ecea91487d70ac03",
            "checked_utc": "2026-10-01T02:20:09.558651+00:00",
            "error": ""
          },
          {
            "url": "https://www.keyfactor.com/servicenow-announcement/",
            "status": "200",
            "final": "https://www.keyfactor.com/servicenow-announcement/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "98e0077606252804cec1d79cd97f0ca1d1100fa29ad557a8336ccfd453fac760",
            "checked_utc": "2026-10-01T02:20:40.607859+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/keyfactor-agilesec-command.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-servicenow-vr-operations",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.keyfactor.com/servicenow-announcement/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "keyfactor-agilesec-command/C7",
      "product": "Keyfactor AgileSec + Command",
      "slug": "keyfactor-agilesec-command",
      "criterion": "C7",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents compliance dashboard/export, not a verified per-framework evidence mapping.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.keyfactor.com/products/cryptographic-discovery-inventory/"
        ],
        "sources": [
          {
            "url": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
            "status": "200",
            "final": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "191132cc98f15a737cb59e7cf50cd7258349ba986d5ba8eb4b7acf9c352f8a43",
            "checked_utc": "2026-10-01T02:20:40.105206+00:00",
            "error": ""
          },
          {
            "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes",
            "status": "200",
            "final": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "1c5b2ec4651c4bcd394c910e9abfdde96d5c7a9ec37de5ff793bbd007e354754",
            "checked_utc": "2026-10-01T02:20:09.371245+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/keyfactor-agilesec-command.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.keyfactor.com/products/cryptographic-discovery-inventory/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.keyfactor.com/agilesec/latest/agilesec-3-4-release-notes",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "o3-security/C1",
      "product": "O3 Security",
      "slug": "o3-security",
      "criterion": "C1",
      "final_score": 7,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor lists code/libraries/binaries/configurations; 5-6 surfaces and algorithm depth are not independently enumerated.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://o3.security/qbom"
        ],
        "sources": [
          {
            "url": "https://o3.security/qbom",
            "status": "200",
            "final": "https://o3.security/qbom",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "ac174e24f94e294596bfa9050e73795023c916c00ee5614929ed3421d1208993",
            "checked_utc": "2026-10-01T02:20:12.669108+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/cryptographic-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/cryptographic-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d065322c6d3f1338487789f26db2de20940f4c77b83e542f52d7eb4bb18c9f7",
            "checked_utc": "2026-10-01T02:20:11.454938+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/o3-security.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://o3.security/qbom",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://o3.security/cryptographic-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "o3-security/C2",
      "product": "O3 Security",
      "slug": "o3-security",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Archived generic industry-format quote does not name CycloneDX; exact standard-schema export support unverified.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://o3.security/cryptographic-bill-of-materials"
        ],
        "sources": [
          {
            "url": "https://o3.security/cryptographic-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/cryptographic-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d065322c6d3f1338487789f26db2de20940f4c77b83e542f52d7eb4bb18c9f7",
            "checked_utc": "2026-10-01T02:20:11.454938+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines",
            "status": "200",
            "final": "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "257f54589b8ac3f575765216290ccd312fa62b7b21d0c0cd6acf83bc3a28d438",
            "checked_utc": "2026-10-01T02:20:11.380860+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/o3-security.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://o3.security/cryptographic-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "o3-security/C3",
      "product": "O3 Security",
      "slug": "o3-security",
      "criterion": "C3",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Versioned CBOM is documented; scheduled re-scan/diff mechanism is not established.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://o3.security/cryptographic-bill-of-materials"
        ],
        "sources": [
          {
            "url": "https://o3.security/cryptographic-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/cryptographic-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d065322c6d3f1338487789f26db2de20940f4c77b83e542f52d7eb4bb18c9f7",
            "checked_utc": "2026-10-01T02:20:11.454938+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/",
            "status": "200",
            "final": "https://o3.security/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "513cae1d5b595aaa24cf8ffd13700f0c668508a0388b4612ebf0cec3c27c52bd",
            "checked_utc": "2026-10-01T02:20:10.983373+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/o3-security.json",
      "original_cell_score": 5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://o3.security/cryptographic-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://o3.security/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "o3-security/C4",
      "product": "O3 Security",
      "slug": "o3-security",
      "criterion": "C4",
      "final_score": 7,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor urgency ranking uses break-year and attack surface; numeric score/data lifetime/weights are not shown.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://o3.security/qbom"
        ],
        "sources": [
          {
            "url": "https://o3.security/qbom",
            "status": "200",
            "final": "https://o3.security/qbom",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "ac174e24f94e294596bfa9050e73795023c916c00ee5614929ed3421d1208993",
            "checked_utc": "2026-10-01T02:20:12.669108+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/cryptographic-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/cryptographic-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d065322c6d3f1338487789f26db2de20940f4c77b83e542f52d7eb4bb18c9f7",
            "checked_utc": "2026-10-01T02:20:11.454938+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/academy/qbom-quantum-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/academy/qbom-quantum-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "429d7ed4e165646d349950f9669e6abd696c2a844cc5d63051730bc02d4a5c28",
            "checked_utc": "2026-10-01T02:20:12.801624+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/o3-security.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://o3.security/qbom",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://o3.security/cryptographic-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://o3.security/academy/qbom-quantum-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "o3-security/C5",
      "product": "O3 Security",
      "slug": "o3-security",
      "criterion": "C5",
      "final_score": 0,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Zero is a bounded no-metric finding; docs portal access limits prevent complete correctness review.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 6,
        "total_cited_urls": 6,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://o3.security/cryptographic-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/cryptographic-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d065322c6d3f1338487789f26db2de20940f4c77b83e542f52d7eb4bb18c9f7",
            "checked_utc": "2026-10-01T02:20:11.454938+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/qbom",
            "status": "200",
            "final": "https://o3.security/qbom",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "ac174e24f94e294596bfa9050e73795023c916c00ee5614929ed3421d1208993",
            "checked_utc": "2026-10-01T02:20:12.669108+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/academy/qbom-quantum-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/academy/qbom-quantum-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "429d7ed4e165646d349950f9669e6abd696c2a844cc5d63051730bc02d4a5c28",
            "checked_utc": "2026-10-01T02:20:12.801624+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/",
            "status": "200",
            "final": "https://o3.security/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "513cae1d5b595aaa24cf8ffd13700f0c668508a0388b4612ebf0cec3c27c52bd",
            "checked_utc": "2026-10-01T02:20:10.983373+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/o3security",
            "status": "200",
            "final": "https://github.com/o3security",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "9c8d860b4a16e0e1f3601d1d57703b428ab8259052b93254edb02b2fa584e08d",
            "checked_utc": "2026-10-01T02:20:10.848721+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines",
            "status": "200",
            "final": "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "257f54589b8ac3f575765216290ccd312fa62b7b21d0c0cd6acf83bc3a28d438",
            "checked_utc": "2026-10-01T02:20:11.380860+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/o3-security.json",
      "original_cell_score": 0,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://o3.security/cryptographic-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://o3.security/qbom",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://o3.security/academy/qbom-quantum-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://o3.security/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/o3security",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://o3.security/compliance/cert-in-sbom-cbom-qbom-aibom-hbom-guidelines",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "web search 2026-09-26: site:o3.security CBOM OR QBOM \"false positive\" OR accuracy OR precision (no hits on correctness)",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "o3-security/C6",
      "product": "O3 Security",
      "slug": "o3-security",
      "criterion": "C6",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Migration report is named, but concrete remedial step quality is not checked.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://o3.security/cryptographic-bill-of-materials"
        ],
        "sources": [
          {
            "url": "https://o3.security/cryptographic-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/cryptographic-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d065322c6d3f1338487789f26db2de20940f4c77b83e542f52d7eb4bb18c9f7",
            "checked_utc": "2026-10-01T02:20:11.454938+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/",
            "status": "200",
            "final": "https://o3.security/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "513cae1d5b595aaa24cf8ffd13700f0c668508a0388b4612ebf0cec3c27c52bd",
            "checked_utc": "2026-10-01T02:20:10.983373+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/o3-security.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://o3.security/cryptographic-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://o3.security/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "o3-security/C7",
      "product": "O3 Security",
      "slug": "o3-security",
      "criterion": "C7",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "CNSA gaps are named; actual framework-to-evidence mapping and executive report unavailable for review.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://o3.security/qbom"
        ],
        "sources": [
          {
            "url": "https://o3.security/qbom",
            "status": "200",
            "final": "https://o3.security/qbom",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "ac174e24f94e294596bfa9050e73795023c916c00ee5614929ed3421d1208993",
            "checked_utc": "2026-10-01T02:20:12.669108+00:00",
            "error": ""
          },
          {
            "url": "https://o3.security/cryptographic-bill-of-materials",
            "status": "200",
            "final": "https://o3.security/cryptographic-bill-of-materials",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6d065322c6d3f1338487789f26db2de20940f4c77b83e542f52d7eb4bb18c9f7",
            "checked_utc": "2026-10-01T02:20:11.454938+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/o3-security.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://o3.security/qbom",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://o3.security/cryptographic-bill-of-materials",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qcecuring-cbom/C1",
      "product": "QCecuring CBOM",
      "slug": "qcecuring-cbom",
      "criterion": "C1",
      "final_score": 9,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Algorithm/key-size quote supports depth, but scored surface count and hybrid handling depend on other pages.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 9,
        "total_cited_urls": 9,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.qcecuring.com/cbom/getting-started/first-scan"
        ],
        "sources": [
          {
            "url": "https://docs.qcecuring.com/cbom",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "db5bfd7e3d7145c4bfcf1cac599a1cd850148c956f800c63f00fd7eefd7e2553",
            "checked_utc": "2026-10-01T02:20:09.715730+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/getting-started/first-scan",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/getting-started/first-scan",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "02fa560cf162eb2099f1e38056fc4a76a75508d1603ccf029088650478fdfd8f",
            "checked_utc": "2026-10-01T02:20:09.851503+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/network",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/network",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "27734f201a8ab3bd0a625bb577ebebd380705587fc73cc46861bc32989c8493c",
            "checked_utc": "2026-10-01T02:20:10.256287+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/source-code",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/source-code",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "039aaccda1e99d0ae71d15e871868d5d21cc6c276452c16fa048360ee2cd39f5",
            "checked_utc": "2026-10-01T02:20:10.318612+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/binary",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/binary",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6caf200fa65aef64012d78c3d8b6ba874fd45bb31d974d805a0234ea66f560f7",
            "checked_utc": "2026-10-01T02:20:10.155835+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/cloud",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/cloud",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "f6a55a6c5b9533798e635b543a9d742ef89d7077de94eee1ec7d2a4d5d233da7",
            "checked_utc": "2026-10-01T02:20:10.365602+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/filesystem",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/filesystem",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "b474cdf25697c52120c4453f26384408d84077001200e75ba4bc043f677e8b82",
            "checked_utc": "2026-10-01T02:20:10.470375+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/directory-services",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/directory-services",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "773cb30f2e42b6eb09bf7082eab42ca7bbf46d4e704b685577a12fdd92c382bd",
            "checked_utc": "2026-10-01T02:20:10.192288+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/certstore-windows",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/certstore-windows",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "27dafd5567f3320b972bb51491cc404547a94f8bb53dfc16950a5114c420382e",
            "checked_utc": "2026-10-01T02:20:10.268844+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qcecuring-cbom.json",
      "original_cell_score": 9,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.qcecuring.com/cbom",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/getting-started/first-scan",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/network",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/source-code",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/binary",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/cloud",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/filesystem",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/directory-services",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/certstore-windows",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qcecuring-cbom/C2",
      "product": "QCecuring CBOM",
      "slug": "qcecuring-cbom",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Public documentation explicitly specifies CycloneDX 1.6 JSON output; no integrity mechanism cited.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.qcecuring.com/cbom/platform/import-export"
        ],
        "sources": [
          {
            "url": "https://docs.qcecuring.com/cbom/platform/import-export",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/import-export",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "41191abf29f2c49ebd8524f56ca01373827f3767d73350b013e856241e19ca97",
            "checked_utc": "2026-10-01T02:20:10.113468+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/platform/inventory",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/inventory",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "74bfe5117469815c6ac6647e38eba96b870fd6f231f5dd577d7775f522a3017a",
            "checked_utc": "2026-10-01T02:20:10.119634+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qcecuring-cbom.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.qcecuring.com/cbom/platform/import-export",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.qcecuring.com/cbom/platform/inventory",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qcecuring-cbom/C3",
      "product": "QCecuring CBOM",
      "slug": "qcecuring-cbom",
      "criterion": "C3",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Documented comparison lists improved/regressed/unchanged and violation deltas; no signed change history shown.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.qcecuring.com/cbom/platform/compliance"
        ],
        "sources": [
          {
            "url": "https://docs.qcecuring.com/cbom/architecture",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/architecture",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "ab88e01582ec74747f30fffa3bd19137d048052cc955173a37285a8a1aa0e492",
            "checked_utc": "2026-10-01T02:20:09.850017+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/platform/compliance",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/compliance",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "f0aff80243812664c4d15b73445143552c6b45cfd9dec747923e7aa43bf523b9",
            "checked_utc": "2026-10-01T02:20:09.805229+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/platform/sensors",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/sensors",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "033e3df888a4668608808ab4203e38c8a0e78586ae926b7377338419e0cc6415",
            "checked_utc": "2026-10-01T02:20:09.918349+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/administration/licensing",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/administration/licensing",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2db6c21e035de85655c2bae9bec260979527b389326cd895f9600faa4f3121f8",
            "checked_utc": "2026-10-01T02:20:09.852247+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qcecuring-cbom.json",
      "original_cell_score": 7,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_B.json",
          "before": 7,
          "after": 6,
          "reason": "The diff comes from a user-triggered compliance assessment, not from scan-to-scan drift on the scheduled scans. Anchor 6 is therefore met only loosely. One of the two 8-conditions (tamper-evident history) is wholly absent, and the alert is a single architecture-table row. That is not 'clearly between' two anchors, so the rubric's lower-anchor default applies. Row total falls 6.68 -> 6.53 (124/19).",
          "evidence": "/platform/sensors: 'Schedule | Scan frequency (hourly, 6h, 12h, daily, weekly)'. /platform/compliance: 'Click Run Assessment on any standard...' then 'Trend Comparison | Delta vs. the previous assessment for the same standard | Direction indicator: IMPROVED, REGRESSED, or UNCHANGED'. /architecture: one table row, 'Alerts | Email notifications for policy violations and certificate expiry'. No tamper-evident history, audit log, hash chain or signature was found in the 22 docs pages."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.qcecuring.com/cbom/architecture",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/platform/compliance",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.qcecuring.com/cbom/platform/sensors",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/administration/licensing",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qcecuring-cbom/C4",
      "product": "QCecuring CBOM",
      "slug": "qcecuring-cbom",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents risk categories with algorithm examples; no numerical model asserted.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.qcecuring.com/cbom"
        ],
        "sources": [
          {
            "url": "https://docs.qcecuring.com/cbom",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "db5bfd7e3d7145c4bfcf1cac599a1cd850148c956f800c63f00fd7eefd7e2553",
            "checked_utc": "2026-10-01T02:20:09.715730+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/platform/compliance",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/compliance",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "f0aff80243812664c4d15b73445143552c6b45cfd9dec747923e7aa43bf523b9",
            "checked_utc": "2026-10-01T02:20:09.805229+00:00",
            "error": ""
          },
          {
            "url": "https://www.qcecuring.com/blog/quantum-risk-scoring-methodology",
            "status": "200",
            "final": "https://www.qcecuring.com/blog/quantum-risk-scoring-methodology",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "fa21c7a0731b6e668950aed6754425beee581aa572ff40788098195c40acf308",
            "checked_utc": "2026-10-01T02:20:40.430526+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qcecuring-cbom.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.qcecuring.com/cbom",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.qcecuring.com/cbom/platform/compliance",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.qcecuring.com/blog/quantum-risk-scoring-methodology",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qcecuring-cbom/C5",
      "product": "QCecuring CBOM",
      "slug": "qcecuring-cbom",
      "criterion": "C5",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Parsing limitations describe potential misses, not a measured false-positive rate; score four remains a rubric judgment.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.qcecuring.com/cbom/scanners/filesystem"
        ],
        "sources": [
          {
            "url": "https://docs.qcecuring.com/cbom/scanners/filesystem",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/scanners/filesystem",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "b474cdf25697c52120c4453f26384408d84077001200e75ba4bc043f677e8b82",
            "checked_utc": "2026-10-01T02:20:10.470375+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/platform/sensors",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/sensors",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "033e3df888a4668608808ab4203e38c8a0e78586ae926b7377338419e0cc6415",
            "checked_utc": "2026-10-01T02:20:09.918349+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qcecuring-cbom.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.qcecuring.com/cbom/scanners/filesystem",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.qcecuring.com/cbom/platform/sensors",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qcecuring-cbom/C6",
      "product": "QCecuring CBOM",
      "slug": "qcecuring-cbom",
      "criterion": "C6",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "JSON export and Action Required guidance satisfy final six; no named ticket integration inferred.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.qcecuring.com/cbom/platform/compliance"
        ],
        "sources": [
          {
            "url": "https://docs.qcecuring.com/cbom/platform/compliance",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/compliance",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "f0aff80243812664c4d15b73445143552c6b45cfd9dec747923e7aa43bf523b9",
            "checked_utc": "2026-10-01T02:20:09.805229+00:00",
            "error": ""
          },
          {
            "url": "https://www.qcecuring.com/integrations",
            "status": "200",
            "final": "https://www.qcecuring.com/integrations",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "b1a49890e28f724cd85249817dc50f525e46295b87ce9bf3340147fa869a8df6",
            "checked_utc": "2026-10-01T02:20:40.274637+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qcecuring-cbom.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.qcecuring.com/cbom/platform/compliance",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.qcecuring.com/integrations",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qcecuring-cbom/C7",
      "product": "QCecuring CBOM",
      "slug": "qcecuring-cbom",
      "criterion": "C7",
      "final_score": 7,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Framework families listed, but mapping output/accuracy not independently checked.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.qcecuring.com/cbom/platform/compliance"
        ],
        "sources": [
          {
            "url": "https://docs.qcecuring.com/cbom/platform/dashboard",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/dashboard",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "eaf81f443372ac497c2bff1ca48fc073518b9f61ea7e11274f179d061e25fbdd",
            "checked_utc": "2026-10-01T02:20:10.034655+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/platform/compliance",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/platform/compliance",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "f0aff80243812664c4d15b73445143552c6b45cfd9dec747923e7aa43bf523b9",
            "checked_utc": "2026-10-01T02:20:09.805229+00:00",
            "error": ""
          },
          {
            "url": "https://docs.qcecuring.com/cbom/api-reference",
            "status": "200",
            "final": "https://docs.qcecuring.com/cbom/api-reference",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6335c6a7f8f32d9f188c19ac55b9a7f9bff453c0edd0e5e7aa8cb8ce9339b1b4",
            "checked_utc": "2026-10-01T02:20:09.659629+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qcecuring-cbom.json",
      "original_cell_score": 7,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.qcecuring.com/cbom/platform/dashboard",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.qcecuring.com/cbom/platform/compliance",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.qcecuring.com/cbom/api-reference",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qscout-pulse-gold/C1",
      "product": "QScout Pulse Gold",
      "slug": "qscout-pulse-gold",
      "criterion": "C1",
      "final_score": 8,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor modules document eight surfaces but active production coverage and parameter depth across all eight are not demonstrated.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://qtonicquantum.com/modules"
        ],
        "sources": [
          {
            "url": "https://qtonicquantum.com/modules",
            "status": "200",
            "final": "https://qtonicquantum.com/modules",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "4142932e0dca59dd14559ed618873f5c5e33eaef4c4100c9bd0296167d1fe139",
            "checked_utc": "2026-10-01T02:20:13.628076+00:00",
            "error": ""
          },
          {
            "url": "https://qtonicquantum.com/cryptographic-inventory",
            "status": "200",
            "final": "https://qtonicquantum.com/cryptographic-inventory",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "9a292ccadbe46e6759210726d52e774d1de1a3fbece70859ad7bf4f62c296dfe",
            "checked_utc": "2026-10-01T02:20:12.689742+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/capabilities/source-depth",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/capabilities/source-depth",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "c3ceba168a67b8fb969c09765d646ecbbbabf0ec7509725bd64eb45ec78ab67c",
            "checked_utc": "2026-10-01T02:20:04.936858+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/cbom.sample.json",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/cbom.sample.json",
            "content_type": "application/vnd.cyclonedx+json",
            "method": "node_verified_tls",
            "sha256": "97d01e8b5ebe72679a6ee099727d04948512848bfc746a630afa8d8a0172e673",
            "checked_utc": "2026-10-01T02:20:06.303954+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qscout-pulse-gold.json",
      "original_cell_score": 10,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_A.json",
          "before": 10,
          "after": 8,
          "reason": "Anchor 10 requires >=7 surfaces WITH algorithm+parameter depth and PQC/hybrid detection. Parameter depth (e.g. RSA-2048) and hybrid/PQC detection are documented only for TLS/certificates. SSH and IKE get 'quantum-vulnerable' detection, not PQC. The other surfaces are one-line catalog entries with no mechanism, and the vendor says specifications come only in a sales engagement. Several 'surfaces' ingest customer-provided snapshots rather than discover assets. About 6 surfaces have algorithm-level wording (a,b,c,d,e,i), which fits anchor 8 (5-6 surfaces with algorithm depth). Host agent (g) and OT (j) were not documented. Symmetry check: CBOM Secure's datasheet documents per-surface detail (PKCS#11 HSMs, 7 languages and 70+ libraries, binary scanning, 'Agents for depth, agentless for reach', 'hybrid TLS (X25519MLKEM768) detected in production'), so its 10 survives the same rule.",
          "evidence": "https://qtonicquantum.com/modules: 'All 74 catalog modules shown. Full module specifications available during sales engagement.' Every surface has a one-line entry, e.g. 'KMS & Vault Inventory: Summarizes KMS and Vault key metadata -- assesses key age, rotation posture, and algorithm strength', 'TLS Termination Mapper: Parses TLS termination configuration snapshots', 'Service Mesh Crypto Mapper: Summarizes mesh crypto posture from provided config snapshots', 'Cloud Metadata Collector: Summarizes cloud assets from provided metadata snapshots'. https://api.qtonicquantum.com/public/capabilities/source-depth: languages count 5; 'libraries':{'status':'unpublished'}, 'function_patterns':{'status':'unpublished'}. https://qtonicquantum.com/downloads/qscout-hndl-methodology.md line 535: 'Future Decrypt Risk (20%) | Directly measured from TLS cipher suites, certificate key types, key exchange algorithms'."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://qtonicquantum.com/modules",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://qtonicquantum.com/cryptographic-inventory",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/capabilities/source-depth",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/cbom.sample.json",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qscout-pulse-gold/C2",
      "product": "QScout Pulse Gold",
      "slug": "qscout-pulse-gold",
      "criterion": "C2",
      "final_score": 9,
      "weight_numerator": 3,
      "evidence_class": "artifact_tested_public_own_api_sample",
      "source_review_evidence_class": "artifact_tested_public_own_api_sample",
      "source_entailment": "artifact_tested_narrow",
      "source_entailment_note": "Separate public 13-component own-API CBOM sample was schema/signature/tamper checked; this is not an estate Gold native scan.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://api.qtonicquantum.com/public/trust/cbom.verification.json"
        ],
        "sources": [
          {
            "url": "https://api.qtonicquantum.com/public/trust/cbom.sample.json",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/cbom.sample.json",
            "content_type": "application/vnd.cyclonedx+json",
            "method": "node_verified_tls",
            "sha256": "97d01e8b5ebe72679a6ee099727d04948512848bfc746a630afa8d8a0172e673",
            "checked_utc": "2026-10-01T02:20:06.303954+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/cbom.verification.json",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/cbom.verification.json",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "99fcbd01a75fb7746cef3ff49b266c6fc6da130013f5809ec21c0da2986f5c7a",
            "checked_utc": "2026-10-01T02:20:06.501673+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/verification-key",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/verification-key",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "37f0d2ed88f62f98aae2aeb1fc6f28598a3fcd439a2edad200d0537621663a41",
            "checked_utc": "2026-10-01T02:20:07.050056+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/verifier-cli",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/verifier-cli",
            "content_type": "text/x-python; charset=utf-8",
            "method": "node_verified_tls",
            "sha256": "fd0c11d4e38e2de46d679bf3e18286f6ac90a925ab92df782f5e5b07c360877d",
            "checked_utc": "2026-10-01T02:20:07.083803+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qscout-pulse-gold.json",
      "original_cell_score": 10,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_A.json",
          "before": 10,
          "after": 9,
          "reason": "The signature is real and verifiable by an outsider with OpenSSL 3.5, so the claim is above 8. It sits clearly between 8 and 10: the signed file is a self-inventory of the vendor's own API ('sample-not-estate-cbom'), not a sample of what the product produces for a scanned estate. No documentation page links to it, and the API reference says the opposite. The public product pages also disagree about the export format (JSON/SARIF on cryptographic-inventory versus CycloneDX 1.7 on /qscout).",
          "evidence": "https://api.qtonicquantum.com/public/trust/cbom.sample.json is 'CycloneDX 1.7 13' components, with metadata.component 'qscout-api ... internal crypto surface (algorithms, protocols, and related material that the service itself implements)', and properties 'qscout:sample-not-estate-cbom=true' and 'qscout:not=estate-scale Gold CBOM'. sha256 06e2fcec...883c3 equals cbom.verification.json cbom_sha256 and is stable across two fetches. Independent verification with stock OpenSSL 3.5.7 (no liboqs), after wrapping the 1952-byte key in an ML-DSA-65 SPKI: 'Signature Verified Successfully'; a 1-bit flip gives 'Signature Verification Failure'. /api-reference: 'signed reports ... are not exposed as anonymous public routes'. /cryptographic-inventory: 'CBOM data exports to JSON and SARIF formats'."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://api.qtonicquantum.com/public/trust/cbom.sample.json",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/cbom.verification.json",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://api.qtonicquantum.com/public/verification-key",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/verifier-cli",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qscout-pulse-gold/C3",
      "product": "QScout Pulse Gold",
      "slug": "qscout-pulse-gold",
      "criterion": "C3",
      "final_score": 8,
      "weight_numerator": 3,
      "evidence_class": "production_observed_vendor_dogfood_log",
      "source_review_evidence_class": "production_observed_vendor_dogfood_log",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Public 500-event hash chain/signatures are inspectable, but 10 unsigned events, before=null and heartbeat labels limit cryptographic drift proof.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://qtonicquantum.com/cryptographic-inventory"
        ],
        "sources": [
          {
            "url": "https://qtonicquantum.com/cryptographic-inventory",
            "status": "200",
            "final": "https://qtonicquantum.com/cryptographic-inventory",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "9a292ccadbe46e6759210726d52e774d1de1a3fbece70859ad7bf4f62c296dfe",
            "checked_utc": "2026-10-01T02:20:12.689742+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/pulse",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/pulse",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "e1582f083f5b36aa747bda24624045455e1c5df9aa0e25537d84ef100fe72b13",
            "checked_utc": "2026-10-01T02:20:06.881334+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/pulse-changes",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/pulse-changes",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "cf6f1ef17481966a869ac576b6a6f5e3fc4e50aada52e86b76032f7cd077a373",
            "checked_utc": "2026-10-01T02:20:07.291438+00:00",
            "error": ""
          },
          {
            "url": "https://qtonicquantum.com/modules",
            "status": "200",
            "final": "https://qtonicquantum.com/modules",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "4142932e0dca59dd14559ed618873f5c5e33eaef4c4100c9bd0296167d1fe139",
            "checked_utc": "2026-10-01T02:20:13.628076+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qscout-pulse-gold.json",
      "original_cell_score": 9,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_A.json",
          "before": 9,
          "after": 8,
          "reason": "Three independent reasons 9 fails. (1) The endpoint cited for the latency and chain labels itself 'not_gold_pulse', so it belongs to a different product than the one scored. (2) The 'change history' holds no change content: all 500 events have before=null and host-level 'after' fields, with no crypto diff. (3) The headline latency is pipeline time by the vendor's own note, and the detection samples are n=5. Anchor 8 is met: scheduled and event-triggered monitoring with drift reporting is documented, and a signed hash chain exists. A stricter reading (history without change content is not change history) would give 6.",
          "evidence": "https://api.qtonicquantum.com/public/trust/pulse: '\"product\":\"qscout_pulse\",\"not_gold_pulse\":true', 'dogfood':true, 'third_party_customer':false, 'real_time':false, drift_latency note 'not collector ingest SLO', per-source cloud_audit_event and certificate_transparency sample_count 5 each. https://api.qtonicquantum.com/public/trust/pulse-changes: 500 changes, python Counter of before-is-null gives 'Counter({True: 500})'. A sample event has after={'host':'qtonicquantum.com','customer_estate':true,'third_party_customer':false}. https://qtonicquantum.com/qscout/pulse: 'scheduled reassessment, event-triggered updates when a certificate rotates or a domain appears, and drift reporting when posture regresses'."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://qtonicquantum.com/cryptographic-inventory",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/pulse",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/pulse-changes",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://qtonicquantum.com/modules",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qscout-pulse-gold/C4",
      "product": "QScout Pulse Gold",
      "slug": "qscout-pulse-gold",
      "criterion": "C4",
      "final_score": 9,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Published seven-factor model is organization-level while per-asset priority uses different factors; final nine is a contestable interpolation.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://qtonicquantum.com/downloads/qscout-hndl-methodology.md"
        ],
        "sources": [
          {
            "url": "https://qtonicquantum.com/downloads/qscout-hndl-methodology.md",
            "status": "200",
            "final": "https://qtonicquantum.com/downloads/qscout-hndl-methodology.md",
            "content_type": "text/markdown; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "52409cfec99eed282b75e88f7ba4f2523bd7af128b9e93bb14912c4d4c90cb5a",
            "checked_utc": "2026-10-01T02:20:12.882425+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/hndl",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/hndl",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "ee1bcc25ddbfda3a80ae11afffd9281558ed8e43a12bcdb07777d06bdb061b9f",
            "checked_utc": "2026-10-01T02:20:06.723816+00:00",
            "error": ""
          },
          {
            "url": "https://qtonicquantum.com/cryptographic-inventory",
            "status": "200",
            "final": "https://qtonicquantum.com/cryptographic-inventory",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "9a292ccadbe46e6759210726d52e774d1de1a3fbece70859ad7bf4f62c296dfe",
            "checked_utc": "2026-10-01T02:20:12.689742+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qscout-pulse-gold.json",
      "original_cell_score": 9,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://qtonicquantum.com/downloads/qscout-hndl-methodology.md",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/hndl",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://qtonicquantum.com/cryptographic-inventory",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qscout-pulse-gold/C5",
      "product": "QScout Pulse Gold",
      "slug": "qscout-pulse-gold",
      "criterion": "C5",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "artifact_recomputed_vendor_labeled_corpus",
      "source_review_evidence_class": "artifact_recomputed_vendor_labeled_corpus",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Public corpus arithmetic recomputes but labels are partly detector-derived, legacy, and narrow; it is not an independently adjudicated product miss rate.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://api.qtonicquantum.com/public/trust/accuracy-metrics"
        ],
        "sources": [
          {
            "url": "https://api.qtonicquantum.com/public/trust/accuracy-metrics",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/accuracy-metrics",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "c23df85e6a8247ccae46cbca65115df601fc298c73869add4406fc1f356b6fe9",
            "checked_utc": "2026-10-01T02:20:06.664417+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/accuracy-corpus",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/accuracy-corpus",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "1d6fa3dc6d7f21883710a921dd07892e05babd37c647dacf2b4725a1dbdbbc1b",
            "checked_utc": "2026-10-01T02:20:05.081607+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/independent-corpus",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/independent-corpus",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "1d6b9ea18c473bc0f9a9a68bfe87deb46a1d77b3c47df5e522297b544a27732c",
            "checked_utc": "2026-10-01T02:20:06.747159+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qscout-pulse-gold.json",
      "original_cell_score": 8,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_A.json",
          "before": 8,
          "after": 6,
          "reason": "The rubric NOTE says detector-in-label ground truth is NOT independent, and anchor 6 names exactly this case ('ground truth not independent'). Anchor 8's second branch drops the independence requirement and contradicts both. Default-to-lower resolves this to 6. Substance: 77% of cases classify IANA registry rows (a table lookup, not discovery), 97 cases are the vendor's own certificates, and only 2 of 7 claimed capabilities are measured.",
          "evidence": "https://api.qtonicquantum.com/public/trust/accuracy-corpus: case_count 1368, precision 1.0, recall 0.7628. Sources: tls-signaturescheme.csv 538, tls-parameters-4.csv 448, tls-parameters-8.csv 70 (1,056 IANA registry rows), badssl 82, crt.sh %.qryptonic.com 71 and %.qtonicquantum.com 26 (the vendor's own domains), test.openquantumsafe.org 9. Capabilities: tls_surface 1246, cert_expiry 122. A sample case: 'ground_truth':'positive','signal':'tls-ciphersuites TLS_NULL_WITH_NULL_NULL','detected':false."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://api.qtonicquantum.com/public/trust/accuracy-metrics",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/accuracy-corpus",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/independent-corpus",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qscout-pulse-gold/C6",
      "product": "QScout Pulse Gold",
      "slug": "qscout-pulse-gold",
      "criterion": "C6",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "artifact_tested_fixture_not_live_tenant",
      "source_review_evidence_class": "artifact_tested_fixture_not_live_tenant",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Inbound closure rule is documented/fixture-tested; public harness is not a live tenant and outbound integration defaults dry-run.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://qtonicquantum.com/integrations"
        ],
        "sources": [
          {
            "url": "https://qtonicquantum.com/integrations",
            "status": "200",
            "final": "https://qtonicquantum.com/integrations",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "95cb70bcbf6411e3789c8ed4ac04e0bc1b4f0875889e9916258d784a4d71c329",
            "checked_utc": "2026-10-01T02:20:13.028607+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/workflow",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/workflow",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "1b2b952ace62aa12ba89a098a9a7ce3a43e12e0bda52c83d4a548d2b9eb1cb64",
            "checked_utc": "2026-10-01T02:20:06.910817+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/workflow/inbound",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/workflow/inbound",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "e7f463cf3c918e7f105f3d3c215e1b1db20b92c47b6978a143407d0a013f1163",
            "checked_utc": "2026-10-01T02:20:07.024057+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/closed-loop-harness",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/closed-loop-harness",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "8631d0ddcdb7d771c4259147269c90b25450ff06d813df215e6f44d27ebcb57d",
            "checked_utc": "2026-10-01T02:20:06.527993+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qscout-pulse-gold.json",
      "original_cell_score": 8,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_A.json",
          "before": 8,
          "after": 6,
          "reason": "Under the admissibility rule, the vendor's two linked product pages say one-way and control over an unlinked route. Anchor 8 (bidirectional or inbound state machine) is not established as available to customers. Anchor 7 needs automated remediation actions, and none are documented. Anchor 6 applies: one-way ticketing plus guidance. Documented rescan closure verification ('Presence of the vulnerability with a closed ticket is a conflict, not a pass') is noted as a plus but does not reach 7.",
          "evidence": "https://qtonicquantum.com/integrations: 'Connectors are one-way creation today: QScout opens or updates tickets outbound. They are dry-run by default (dry_run=true)... Bidirectional ticket-driven state and non-dry write-back are on the Workflow 10 path'. https://qtonicquantum.com/qscout: 'Workflow connectors (Jira / ServiceNow) are one-way ticket creation and dry-run by default today.' https://api.qtonicquantum.com/public/trust/workflow/inbound: 'customer_estate':false. https://api.qtonicquantum.com/public/trust/closed-loop-harness: 'mode':'recorded_http_fixture','live_tenant':false."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://qtonicquantum.com/integrations",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/workflow",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/workflow/inbound",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/closed-loop-harness",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qscout-pulse-gold/C7",
      "product": "QScout Pulse Gold",
      "slug": "qscout-pulse-gold",
      "criterion": "C7",
      "final_score": 9,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Public role views/framework names/API exist, but sample report is fictional and mappings are not certifications.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 5,
        "total_cited_urls": 5,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://qtonicquantum.com/qscout"
        ],
        "sources": [
          {
            "url": "https://qtonicquantum.com/qscout/sample-report",
            "status": "200",
            "final": "https://qtonicquantum.com/qscout/sample-report",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "dfcd47dfd9ea0d97e5dedfafe9c337d3a9c6a16f12457c156da69131b27646fe",
            "checked_utc": "2026-10-01T02:20:13.467777+00:00",
            "error": ""
          },
          {
            "url": "https://qtonicquantum.com/qscout",
            "status": "200",
            "final": "https://qtonicquantum.com/qscout",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "dcb746d515663e0d25a8288376da9856969c74c3ed605f105db0af9094fa7961",
            "checked_utc": "2026-10-01T02:20:13.364229+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/framework-inventory",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/framework-inventory",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "d3911e96fa97b8f6253ef9149691a66a89cf3ee7f66b7e953bd6961626091c62",
            "checked_utc": "2026-10-01T02:20:06.527672+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/public/trust/board-pack",
            "status": "200",
            "final": "https://api.qtonicquantum.com/public/trust/board-pack",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "c2f8ad496b16bfd0f6502e1da0211eeb319ff31f6493536d4325840186f6fdff",
            "checked_utc": "2026-10-01T02:20:06.302159+00:00",
            "error": ""
          },
          {
            "url": "https://api.qtonicquantum.com/openapi-public.json",
            "status": "200",
            "final": "https://api.qtonicquantum.com/openapi-public.json",
            "content_type": "application/json",
            "method": "node_verified_tls",
            "sha256": "8d312030a409467bf4bb8a53aa4c20debda96f5b2942cd202d2bcb5a1f414542",
            "checked_utc": "2026-10-01T02:20:06.326432+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qscout-pulse-gold.json",
      "original_cell_score": 10,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_A.json",
          "before": 10,
          "after": 9,
          "reason": "A published sample report exists, which CBOM Secure lacks, so the claim is above 8. It is not 10: the sample is one combined report, not separate role-specific executive and technical reports. It shows no compliance mapping, and the 15 frameworks are a name list rather than a mapping. CBOM Secure publishes a per-framework table. The evidence is clearly between 8 and 10.",
          "evidence": "https://qtonicquantum.com/qscout/sample-report: 'Illustrative sample. This report uses synthetic demonstration data'. It is one document containing an 'Executive summary' and 'Top findings'. Its only framework reference is 'may not meet upcoming NIST PQC CNSA 2.0 requirements'. https://api.qtonicquantum.com/public/trust/framework-inventory: a list of 15 framework names with no control mapping. https://api.qtonicquantum.com/public/trust/board-pack: 'sample':true, role_views board/ciso/engineering, and embedded self-ratings 'field_total':9.3,'lab_total':9.54 (inadmissible). https://qtonicquantum.com/qscout/pulse: 'Methodology mapped to NIST IR 8547 (initial public draft) / FIPS 203-205 / CNSA 2.0'."
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://qtonicquantum.com/qscout/sample-report",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://qtonicquantum.com/qscout",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/framework-inventory",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/public/trust/board-pack",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://api.qtonicquantum.com/openapi-public.json",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qusecure-quprotect-r3/C1",
      "product": "QuSecure QuProtect R3",
      "slug": "qusecure-quprotect-r3",
      "criterion": "C1",
      "final_score": 4,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Reconnaissance documents network-negotiated algorithms/certs; exact one-to-two surface boundary is a rubric judgment.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.qusecure.com/recon/"
        ],
        "sources": [
          {
            "url": "https://www.qusecure.com/recon/",
            "status": "200",
            "final": "https://www.qusecure.com/recon/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "49428b96167defad9bdd9af761ac799b26423037c0858e6cadf04b5ae523d0cc",
            "checked_utc": "2026-10-01T02:20:40.489225+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/quprotect/",
            "status": "200",
            "final": "https://www.qusecure.com/quprotect/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "38fa6c233f99c77629f9a6dc169d85019428b63488753aaac32927ba445bb5b3",
            "checked_utc": "2026-10-01T02:20:40.423707+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "6f4e274de3c5b021e87d3bc0341a808037ba2b0196448e69ad34418ae75f2df1",
            "checked_utc": "2026-10-01T02:20:40.433301+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qusecure-quprotect-r3.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.qusecure.com/recon/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.qusecure.com/quprotect/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qusecure-quprotect-r3/C2",
      "product": "QuSecure QuProtect R3",
      "slug": "qusecure-quprotect-r3",
      "criterion": "C2",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Vendor documents CycloneDX 1.6 CBOM export from live inventory; exported bytes were not tested.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.qusecure.com/quprotect/"
        ],
        "sources": [
          {
            "url": "https://www.qusecure.com/quprotect/",
            "status": "200",
            "final": "https://www.qusecure.com/quprotect/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "38fa6c233f99c77629f9a6dc169d85019428b63488753aaac32927ba445bb5b3",
            "checked_utc": "2026-10-01T02:20:40.423707+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/reporting/",
            "status": "200",
            "final": "https://www.qusecure.com/reporting/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "68b1e93128e1ef734fb6568ead778ddf0e80b07ab5bff53e35bc3e719b252c6e",
            "checked_utc": "2026-10-01T02:20:40.507964+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qusecure-quprotect-r3.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.qusecure.com/quprotect/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.qusecure.com/reporting/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qusecure-quprotect-r3/C3",
      "product": "QuSecure QuProtect R3",
      "slug": "qusecure-quprotect-r3",
      "criterion": "C3",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Continuous traffic inventory is documented, but explicit cryptographic diff and tamper history are absent.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.qusecure.com/reporting/"
        ],
        "sources": [
          {
            "url": "https://www.qusecure.com/reporting/",
            "status": "200",
            "final": "https://www.qusecure.com/reporting/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "68b1e93128e1ef734fb6568ead778ddf0e80b07ab5bff53e35bc3e719b252c6e",
            "checked_utc": "2026-10-01T02:20:40.507964+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/recon/",
            "status": "200",
            "final": "https://www.qusecure.com/recon/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "49428b96167defad9bdd9af761ac799b26423037c0858e6cadf04b5ae523d0cc",
            "checked_utc": "2026-10-01T02:20:40.489225+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qusecure-quprotect-r3.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.qusecure.com/reporting/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.qusecure.com/recon/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qusecure-quprotect-r3/C4",
      "product": "QuSecure QuProtect R3",
      "slug": "qusecure-quprotect-r3",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Exposure-based risk ordering is documented; model and calibration not supplied.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.qusecure.com/quprotect/"
        ],
        "sources": [
          {
            "url": "https://www.qusecure.com/quprotect/",
            "status": "200",
            "final": "https://www.qusecure.com/quprotect/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "38fa6c233f99c77629f9a6dc169d85019428b63488753aaac32927ba445bb5b3",
            "checked_utc": "2026-10-01T02:20:40.423707+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/recon/",
            "status": "200",
            "final": "https://www.qusecure.com/recon/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "49428b96167defad9bdd9af761ac799b26423037c0858e6cadf04b5ae523d0cc",
            "checked_utc": "2026-10-01T02:20:40.489225+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qusecure-quprotect-r3.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.qusecure.com/quprotect/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.qusecure.com/recon/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qusecure-quprotect-r3/C5",
      "product": "QuSecure QuProtect R3",
      "slug": "qusecure-quprotect-r3",
      "criterion": "C5",
      "final_score": 0,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor says always accurate but provides no benchmark; zero means not documented under rubric, not measured inaccuracy.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 6,
        "total_cited_urls": 6,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/"
        ],
        "sources": [
          {
            "url": "https://www.qusecure.com/quprotect/",
            "status": "200",
            "final": "https://www.qusecure.com/quprotect/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "38fa6c233f99c77629f9a6dc169d85019428b63488753aaac32927ba445bb5b3",
            "checked_utc": "2026-10-01T02:20:40.423707+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/recon/",
            "status": "200",
            "final": "https://www.qusecure.com/recon/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "49428b96167defad9bdd9af761ac799b26423037c0858e6cadf04b5ae523d0cc",
            "checked_utc": "2026-10-01T02:20:40.489225+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/",
            "status": "200",
            "final": "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "6f4e274de3c5b021e87d3bc0341a808037ba2b0196448e69ad34418ae75f2df1",
            "checked_utc": "2026-10-01T02:20:40.433301+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/reporting/",
            "status": "200",
            "final": "https://www.qusecure.com/reporting/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "68b1e93128e1ef734fb6568ead778ddf0e80b07ab5bff53e35bc3e719b252c6e",
            "checked_utc": "2026-10-01T02:20:40.507964+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/frequently-asked-questions-faqs/",
            "status": "200",
            "final": "https://www.qusecure.com/frequently-asked-questions-faqs/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "dd1cf17a2feaf64a91bba734097a0a2fe5251a59c5dad8a79f83bf0bc80372f6",
            "checked_utc": "2026-10-01T02:20:40.358228+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/cryptographic-bill-of-materials-cbom/",
            "status": "200",
            "final": "https://www.qusecure.com/cryptographic-bill-of-materials-cbom/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "2d1182d65d02e4024f5227a1ef5d1485e6ee0db236839671db2b4fddc0f6ba43",
            "checked_utc": "2026-10-01T02:20:40.350490+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qusecure-quprotect-r3.json",
      "original_cell_score": 0,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.qusecure.com/quprotect/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.qusecure.com/recon/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.qusecure.com/quprotect/cryptographic-discovery-and-inventory/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.qusecure.com/reporting/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.qusecure.com/frequently-asked-questions-faqs/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.qusecure.com/cryptographic-bill-of-materials-cbom/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qusecure-quprotect-r3/C6",
      "product": "QuSecure QuProtect R3",
      "slug": "qusecure-quprotect-r3",
      "criterion": "C6",
      "final_score": 6.5,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Orchestrator action is an adjacent network control and inventory refresh; no cross-product peer run verifies closure.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 3,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.qusecure.com/recon/"
        ],
        "sources": [
          {
            "url": "https://www.qusecure.com/recon/",
            "status": "200",
            "final": "https://www.qusecure.com/recon/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "49428b96167defad9bdd9af761ac799b26423037c0858e6cadf04b5ae523d0cc",
            "checked_utc": "2026-10-01T02:20:40.489225+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/resilience/",
            "status": "200",
            "final": "https://www.qusecure.com/resilience/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "b0efcd7891a16973ea9c147d39075d15361380e4bbe70a05df7595d929a8b515",
            "checked_utc": "2026-10-01T02:20:40.509135+00:00",
            "error": ""
          },
          {
            "url": "https://www.qusecure.com/quprotect/",
            "status": "200",
            "final": "https://www.qusecure.com/quprotect/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "38fa6c233f99c77629f9a6dc169d85019428b63488753aaac32927ba445bb5b3",
            "checked_utc": "2026-10-01T02:20:40.423707+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qusecure-quprotect-r3.json",
      "original_cell_score": 6.5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.qusecure.com/recon/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.qusecure.com/resilience/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.qusecure.com/quprotect/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "qusecure-quprotect-r3/C7",
      "product": "QuSecure QuProtect R3",
      "slug": "qusecure-quprotect-r3",
      "criterion": "C7",
      "final_score": 8,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Human/machine report outputs are documented; compliance mapping detail needs direct report review.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 1,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://www.qusecure.com/reporting/"
        ],
        "sources": [
          {
            "url": "https://www.qusecure.com/reporting/",
            "status": "200",
            "final": "https://www.qusecure.com/reporting/",
            "content_type": "text/html",
            "method": "curl_verified_tls",
            "sha256": "68b1e93128e1ef734fb6568ead778ddf0e80b07ab5bff53e35bc3e719b252c6e",
            "checked_utc": "2026-10-01T02:20:40.507964+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/qusecure-quprotect-r3.json",
      "original_cell_score": 8,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://www.qusecure.com/reporting/",
          "accessibility": true,
          "excerpt_reproduced": true
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "sandboxaq-aqtive-guard/C1",
      "product": "SandboxAQ AQtive Guard",
      "slug": "sandboxaq-aqtive-guard",
      "criterion": "C1",
      "final_score": 10,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor docs support broad discovery and hybrid TLS, but all seven-plus surfaces/depth are not jointly validated in one test.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 8,
        "total_cited_urls": 8,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/reference/"
        ],
        "sources": [
          {
            "url": "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/reference/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/reference/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "b94174add64b15ff2917a6d6c9032628a70ccb8b217ed7b8cb18e855a752af1f",
            "checked_utc": "2026-10-01T02:20:08.183704+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/aws/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/aws/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "c3c1085ea1dd09e1eb9e46fff7cdb3776382ed2a2b3d8ef102663bd4dcd40aed",
            "checked_utc": "2026-10-01T02:20:08.279979+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2fe6acad2cf1b25dafe48cd97a499eba12558b166f0c7fc1394641ee87291282",
            "checked_utc": "2026-10-01T02:20:08.010063+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/supported-formats/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/supported-formats/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "210135ff38f0cda3348a92a9cae4add60f50088d136e3c4367fd99cf2d1162db",
            "checked_utc": "2026-10-01T02:20:08.124344+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/aqg-java-tracer/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/aqg-java-tracer/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5e16ebcb715e021e1d56b7326bfc333423dc4f2ba2208bc9746a64d37514c72a",
            "checked_utc": "2026-10-01T02:20:08.249986+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/crowdstrike/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/crowdstrike/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "3cd1958913acbb2a87df6fce7ad543dd108e928c41ea0325335e2da24a4529b1",
            "checked_utc": "2026-10-01T02:20:08.624127+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/gitlab/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/gitlab/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "e451535a694ec99b8b9dae2ce93e5f23e75eecb09a080bbc0a4f506d831778d2",
            "checked_utc": "2026-10-01T02:20:08.692479+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/aqtive-scanning/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/aqtive-scanning/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "75837eda7cee60f5c27e70e7e5e56e12eef7bb3a60a11f52a9946841e76e2045",
            "checked_utc": "2026-10-01T02:20:07.982617+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/sandboxaq-aqtive-guard.json",
      "original_cell_score": 10,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/reference/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/aws/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/aqg-filesystem-scanner/supported-formats/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/aqg-java-tracer/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/crowdstrike/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/gitlab/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/aqtive-scanning/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "sandboxaq-aqtive-guard/C2",
      "product": "SandboxAQ AQtive Guard",
      "slug": "sandboxaq-aqtive-guard",
      "criterion": "C2",
      "final_score": 4,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "CSV export is documented; marketed CBOM mechanism lacks version/sample, so stronger standard-export claim is withheld.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.aqtiveguard.com/exports/"
        ],
        "sources": [
          {
            "url": "https://docs.aqtiveguard.com/exports/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/exports/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "29caaaa0e65df6e506a236da30ff45b8ce36c878e5529be819e73c1f34b273dd",
            "checked_utc": "2026-10-01T02:20:08.608085+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/cbom/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/cbom/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "83231d34d75021850d7cb1b467d630d3c57edf7578113785bf433b5ea8792729",
            "checked_utc": "2026-10-01T02:20:08.385277+00:00",
            "error": ""
          },
          {
            "url": "https://www.aqtiveguard.com/",
            "status": "200",
            "final": "https://www.aqtiveguard.com/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "fb0fd5eebe4d0819490ef730be9c2cb460fe334745870ef8af71bfce9dfbf67b",
            "checked_utc": "2026-10-01T02:20:15.804240+00:00",
            "error": ""
          },
          {
            "url": "https://aqtiveguard.sandboxaq.com/docs/fundamentals/report-fundamentals/",
            "status": "200",
            "final": "https://aqtiveguard.sandboxaq.com/docs/fundamentals/report-fundamentals/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "a8c0ec1fdaabf140dc81d83476fbdbd01eb938cf22d1daf6cd47a654db007737",
            "checked_utc": "2026-10-01T02:20:07.403923+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/sandboxaq-aqtive-guard.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.aqtiveguard.com/exports/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/cbom/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.aqtiveguard.com/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://aqtiveguard.sandboxaq.com/docs/fundamentals/report-fundamentals/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "sandboxaq-aqtive-guard/C3",
      "product": "SandboxAQ AQtive Guard",
      "slug": "sandboxaq-aqtive-guard",
      "criterion": "C3",
      "final_score": 5,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "CloudTrail change observation documented; generic quote does not establish diff/alert completeness.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.aqtiveguard.com/data-sources/aws/"
        ],
        "sources": [
          {
            "url": "https://docs.aqtiveguard.com/data-sources/aws/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/aws/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "c3c1085ea1dd09e1eb9e46fff7cdb3776382ed2a2b3d8ef102663bd4dcd40aed",
            "checked_utc": "2026-10-01T02:20:08.279979+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "ca63039bde2cc3631bca25cefa4e6cc02600d9629f27536918df53a64474d9d5",
            "checked_utc": "2026-10-01T02:20:08.163127+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/inventory/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/inventory/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6a99dc85721ee34a4e31a76ee13d11da2423f081daeb905fbedb6710c7bc180a",
            "checked_utc": "2026-10-01T02:20:08.765253+00:00",
            "error": ""
          },
          {
            "url": "https://aqtiveguard.sandboxaq.com/docs/projects/compare-reports/",
            "status": "200",
            "final": "https://aqtiveguard.sandboxaq.com/docs/projects/compare-reports/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "9867d17662f32f639f32aa4d4398de76de4de30fd24856bed06da389538b32aa",
            "checked_utc": "2026-10-01T02:20:07.462100+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/sandboxaq-aqtive-guard.json",
      "original_cell_score": 6,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_C.json",
          "before": 6,
          "after": 5,
          "reason": "The current SaaS docs show continuous, event-driven collection and last-scanned history, with no diff or drift output. The only diff feature, Compare reports, appears in docs labelled 'original release'. Those same docs are the reason the researcher denied the ticketing leg in C6, so crediting them here would be inconsistent. Either both cells credit legacy docs (C3=6, C6=7) or neither does. QC takes the lower path: 5. The published 8 is not restored.",
          "evidence": "https://docs.aqtiveguard.com/data-sources/aws/ ('Event-driven ingestion from CloudTrail to keep CPM and AI-SPM inventories current'); https://docs.aqtiveguard.com/inventory/ (Sessions = 'Last scanned history'); https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/ (live monitoring, no change detection); https://aqtiveguard.sandboxaq.com/docs/projects/compare-reports/ ('This guide is for the original release of AQtive Guard')"
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.aqtiveguard.com/data-sources/aws/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/aqg-network-analyzer/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/inventory/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://aqtiveguard.sandboxaq.com/docs/projects/compare-reports/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "sandboxaq-aqtive-guard/C4",
      "product": "SandboxAQ AQtive Guard",
      "slug": "sandboxaq-aqtive-guard",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Policy severity categories documented, without numerical calibration.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.aqtiveguard.com/dashboard/"
        ],
        "sources": [
          {
            "url": "https://docs.aqtiveguard.com/dashboard/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/dashboard/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2f28e5bfa92d7c99167b621b984b1e13b9a91c517ebc2b2869550e62a5ffed10",
            "checked_utc": "2026-10-01T02:20:08.009474+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/issues/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/issues/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "088b03860af4f1485453a834de73d8d56ab0deb6374894c9a26b3f504ff2fe5b",
            "checked_utc": "2026-10-01T02:20:08.897940+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/impact-assessment/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/impact-assessment/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "67c75b262f61adea86655521087d13975f990dedb98b18e3f99594c45134c0f3",
            "checked_utc": "2026-10-01T02:20:08.662028+00:00",
            "error": ""
          },
          {
            "url": "https://www.aqtiveguard.com/",
            "status": "200",
            "final": "https://www.aqtiveguard.com/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "fb0fd5eebe4d0819490ef730be9c2cb460fe334745870ef8af71bfce9dfbf67b",
            "checked_utc": "2026-10-01T02:20:15.804240+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/sandboxaq-aqtive-guard.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.aqtiveguard.com/dashboard/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.aqtiveguard.com/issues/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/impact-assessment/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.aqtiveguard.com/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "sandboxaq-aqtive-guard/C5",
      "product": "SandboxAQ AQtive Guard",
      "slug": "sandboxaq-aqtive-guard",
      "criterion": "C5",
      "final_score": 4,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Vendor says false positives reduced but provides no method or metric in cited source.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 2,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.aqtiveguard.com/"
        ],
        "sources": [
          {
            "url": "https://docs.aqtiveguard.com/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "9fc4751705a1a090ec55941784426edbc5666436e64258057813b36e9e6bdeda",
            "checked_utc": "2026-10-01T02:20:07.823689+00:00",
            "error": ""
          },
          {
            "url": "https://www.sandboxaq.com/post/introducing-opencryptography",
            "status": "200",
            "final": "https://www.sandboxaq.com/post/introducing-opencryptography",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6f1f4bf80ddcb63d53631326f2cb3696329246d2a96381cb756feae389e596f0",
            "checked_utc": "2026-10-01T02:20:40.594668+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/sandboxaq-aqtive-guard.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.aqtiveguard.com/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://www.sandboxaq.com/post/introducing-opencryptography",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "sandboxaq-aqtive-guard/C6",
      "product": "SandboxAQ AQtive Guard",
      "slug": "sandboxaq-aqtive-guard",
      "criterion": "C6",
      "final_score": 6.5,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "qualified_or_partial_anchor",
      "source_entailment_note": "Certificate rotation is documented; attribution to the scored AQG product scope and closure needs checking.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 6,
        "total_cited_urls": 6,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.aqtiveguard.com/aqg-protect/"
        ],
        "sources": [
          {
            "url": "https://docs.aqtiveguard.com/aqg-protect/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/aqg-protect/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "407c9d2b2f73bb14a41e60cdcb1230edd5fda31ecd851647fbde7e289b11fdfd",
            "checked_utc": "2026-10-01T02:20:07.843492+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/aqg-protect/deployment-orchestration/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/aqg-protect/deployment-orchestration/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "fe9f370883c5c3dc165302b651dd7674e2a447687ca444c56ba284b14469255b",
            "checked_utc": "2026-10-01T02:20:07.839908+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/servicenow/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/servicenow/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "5d2f4f27445a8c4feb2b313a87b4de5252150c5abab928a36410df28304e9485",
            "checked_utc": "2026-10-01T02:20:08.492869+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/data-sources/gitlab/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/data-sources/gitlab/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "e451535a694ec99b8b9dae2ce93e5f23e75eecb09a080bbc0a4f506d831778d2",
            "checked_utc": "2026-10-01T02:20:08.692479+00:00",
            "error": ""
          },
          {
            "url": "https://aqtiveguard.sandboxaq.com/docs/integrations/servicenow/",
            "status": "200",
            "final": "https://aqtiveguard.sandboxaq.com/docs/integrations/servicenow/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "6aaa721d229906b04d73e635ae51961cf1aa357f49b2dba499c4b6727f11816a",
            "checked_utc": "2026-10-01T02:20:07.409039+00:00",
            "error": ""
          },
          {
            "url": "https://aqtiveguard.sandboxaq.com/docs/integrations/jira/issue-export/",
            "status": "200",
            "final": "https://aqtiveguard.sandboxaq.com/docs/integrations/jira/issue-export/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "7cd4adce73401d8e166edeb88077c51059a96fba37b91e2408fc19f3dff3ed90",
            "checked_utc": "2026-10-01T02:20:07.419567+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/sandboxaq-aqtive-guard.json",
      "original_cell_score": 6.5,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.aqtiveguard.com/aqg-protect/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.aqtiveguard.com/aqg-protect/deployment-orchestration/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/servicenow/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/data-sources/gitlab/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://aqtiveguard.sandboxaq.com/docs/integrations/servicenow/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://aqtiveguard.sandboxaq.com/docs/integrations/jira/issue-export/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "sandboxaq-aqtive-guard/C7",
      "product": "SandboxAQ AQtive Guard",
      "slug": "sandboxaq-aqtive-guard",
      "criterion": "C7",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "documented_feature",
      "source_entailment_note": "Weak-key/certificate dashboard and export are documented; no compliance evidence mapping asserted.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 4,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": true,
        "quote_match_urls": [
          "https://docs.aqtiveguard.com/dashboard/"
        ],
        "sources": [
          {
            "url": "https://docs.aqtiveguard.com/dashboard/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/dashboard/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "2f28e5bfa92d7c99167b621b984b1e13b9a91c517ebc2b2869550e62a5ffed10",
            "checked_utc": "2026-10-01T02:20:08.009474+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/exports/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/exports/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "29caaaa0e65df6e506a236da30ff45b8ce36c878e5529be819e73c1f34b273dd",
            "checked_utc": "2026-10-01T02:20:08.608085+00:00",
            "error": ""
          },
          {
            "url": "https://docs.aqtiveguard.com/aqg-aispm/compliance/framework-mapping/",
            "status": "200",
            "final": "https://docs.aqtiveguard.com/aqg-aispm/compliance/framework-mapping/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "0da1eaebbf582f359587071f1b3d88d90433bb6c2a3abe44db75a7e0dd4d75ac",
            "checked_utc": "2026-10-01T02:20:07.832169+00:00",
            "error": ""
          },
          {
            "url": "https://www.aqtiveguard.com/",
            "status": "200",
            "final": "https://www.aqtiveguard.com/",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "fb0fd5eebe4d0819490ef730be9c2cb460fe334745870ef8af71bfce9dfbf67b",
            "checked_utc": "2026-10-01T02:20:15.804240+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/sandboxaq-aqtive-guard.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "exact_quote_found",
      "cited_sources": [
        {
          "url": "https://docs.aqtiveguard.com/dashboard/",
          "accessibility": true,
          "excerpt_reproduced": true
        },
        {
          "url": "https://docs.aqtiveguard.com/exports/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://docs.aqtiveguard.com/aqg-aispm/compliance/framework-mapping/",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://www.aqtiveguard.com/",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "tychon-quantum-command/C1",
      "product": "TYCHON Quantum Command",
      "slug": "tychon-quantum-command",
      "criterion": "C1",
      "final_score": 8,
      "weight_numerator": 4,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor product pages returned 403; third-party Elastic PR does not establish scored surface count/depth.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://tychon.io/products/tychon/pqc-management-module/",
            "status": "403",
            "final": "https://tychon.io/products/tychon/pqc-management-module/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15abf1442b43867db2fa47e442af42c201c4112becd90ed3bba32c392d2b5611",
            "checked_utc": "2026-10-01T02:20:15.590187+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/tychoncryptographicinventory/",
            "status": "403",
            "final": "https://tychon.io/tychoncryptographicinventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "2f9c80adacb71d4ab8c1a7bcbbe270f3e55e7931ede29d28d386e95e8ac8eeca",
            "checked_utc": "2026-10-01T02:20:15.594377+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/elastic/integrations/pull/20142",
            "status": "200",
            "final": "https://github.com/elastic/integrations/pull/20142",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1316d53a72595841c894e4c38c01a848fd5d19f875fdcc8f8674597e10fa822c",
            "checked_utc": "2026-10-01T02:20:15.456368+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/tychon-quantum-command.json",
      "original_cell_score": 8,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://tychon.io/products/tychon/pqc-management-module/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/tychoncryptographicinventory/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/elastic/integrations/pull/20142",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "tychon-quantum-command/C2",
      "product": "TYCHON Quantum Command",
      "slug": "tychon-quantum-command",
      "criterion": "C2",
      "final_score": 4,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor pages returned 403; third-party integration PR does not prove a product CycloneDX export.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://tychon.io/tychoncryptographicinventory/",
            "status": "403",
            "final": "https://tychon.io/tychoncryptographicinventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "2f9c80adacb71d4ab8c1a7bcbbe270f3e55e7931ede29d28d386e95e8ac8eeca",
            "checked_utc": "2026-10-01T02:20:15.594377+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/elastic/integrations/pull/20142",
            "status": "200",
            "final": "https://github.com/elastic/integrations/pull/20142",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1316d53a72595841c894e4c38c01a848fd5d19f875fdcc8f8674597e10fa822c",
            "checked_utc": "2026-10-01T02:20:15.456368+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/products/tychon/pqc-management-module/",
            "status": "403",
            "final": "https://tychon.io/products/tychon/pqc-management-module/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15abf1442b43867db2fa47e442af42c201c4112becd90ed3bba32c392d2b5611",
            "checked_utc": "2026-10-01T02:20:15.590187+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/tychon-quantum-command.json",
      "original_cell_score": 5,
      "final_review_adjustments": [
        {
          "review_file": "/evidence/2026-7/_QC_C.json",
          "before": 5,
          "after": 4,
          "reason": "CycloneDX appears once, in a feature list, with no version, schema, procedure or sample. Rubric line 19 caps it AT anchor 4. The documented output is NDJSON/JSON, which is proprietary (anchor 4). This matches how the researcher scored DigiCert C2 (a CBOM export claimed with no schema scored 4).",
          "evidence": "https://tychon.io/tychoncryptographicinventory/ ('Complete Inventory: CBOM (CycloneDX) format', a single line); https://tychon.io/products/tychon/pqc-management-module/ (no CBOM or export text); https://github.com/elastic/integrations/pull/20142 (NDJSON/JSON output, PR still open)"
        }
      ],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://tychon.io/tychoncryptographicinventory/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/elastic/integrations/pull/20142",
          "accessibility": true,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/products/tychon/pqc-management-module/",
          "accessibility": false,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "tychon-quantum-command/C3",
      "product": "TYCHON Quantum Command",
      "slug": "tychon-quantum-command",
      "criterion": "C3",
      "final_score": 4,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor pages returned 403; archived change-alert wording has no accessible mechanism.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 4,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://tychon.io/use-cases/quantumreadiness/",
            "status": "403",
            "final": "https://tychon.io/use-cases/quantumreadiness/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "8e61f25301b1612962dda1c7d04aab1a3e2e3649882fb0464481c662f2b093ab",
            "checked_utc": "2026-10-01T02:20:15.635554+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/products/tychon/pqc-management-module/",
            "status": "403",
            "final": "https://tychon.io/products/tychon/pqc-management-module/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15abf1442b43867db2fa47e442af42c201c4112becd90ed3bba32c392d2b5611",
            "checked_utc": "2026-10-01T02:20:15.590187+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/tychoncryptographicinventory/",
            "status": "403",
            "final": "https://tychon.io/tychoncryptographicinventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "2f9c80adacb71d4ab8c1a7bcbbe270f3e55e7931ede29d28d386e95e8ac8eeca",
            "checked_utc": "2026-10-01T02:20:15.594377+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/elastic/integrations/pull/20142",
            "status": "200",
            "final": "https://github.com/elastic/integrations/pull/20142",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1316d53a72595841c894e4c38c01a848fd5d19f875fdcc8f8674597e10fa822c",
            "checked_utc": "2026-10-01T02:20:15.456368+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/tychon-quantum-command.json",
      "original_cell_score": 4,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://tychon.io/use-cases/quantumreadiness/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/products/tychon/pqc-management-module/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/tychoncryptographicinventory/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/elastic/integrations/pull/20142",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "tychon-quantum-command/C4",
      "product": "TYCHON Quantum Command",
      "slug": "tychon-quantum-command",
      "criterion": "C4",
      "final_score": 6,
      "weight_numerator": 3,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor pages returned 403; exact risk score factors and categories unverified.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 3,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://tychon.io/products/tychon/pqc-management-module/",
            "status": "403",
            "final": "https://tychon.io/products/tychon/pqc-management-module/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15abf1442b43867db2fa47e442af42c201c4112becd90ed3bba32c392d2b5611",
            "checked_utc": "2026-10-01T02:20:15.590187+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/tychoncryptographicinventory/",
            "status": "403",
            "final": "https://tychon.io/tychoncryptographicinventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "2f9c80adacb71d4ab8c1a7bcbbe270f3e55e7931ede29d28d386e95e8ac8eeca",
            "checked_utc": "2026-10-01T02:20:15.594377+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/elastic/integrations/pull/20142",
            "status": "200",
            "final": "https://github.com/elastic/integrations/pull/20142",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1316d53a72595841c894e4c38c01a848fd5d19f875fdcc8f8674597e10fa822c",
            "checked_utc": "2026-10-01T02:20:15.456368+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/tychon-quantum-command.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://tychon.io/products/tychon/pqc-management-module/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/tychoncryptographicinventory/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/elastic/integrations/pull/20142",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "tychon-quantum-command/C5",
      "product": "TYCHON Quantum Command",
      "slug": "tychon-quantum-command",
      "criterion": "C5",
      "final_score": 0,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor pages returned 403; zero is bounded no metric, not a product accuracy result.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 6,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://tychon.io/products/tychon/pqc-management-module/",
            "status": "403",
            "final": "https://tychon.io/products/tychon/pqc-management-module/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15abf1442b43867db2fa47e442af42c201c4112becd90ed3bba32c392d2b5611",
            "checked_utc": "2026-10-01T02:20:15.590187+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/cryptographic-inventory/",
            "status": "403",
            "final": "https://tychon.io/cryptographic-inventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "759d2b1693ecc9252de682cc79ab6bb84667bb53070b033e9300ea769c79a795",
            "checked_utc": "2026-10-01T02:20:15.548120+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/tychoncryptographicinventory/",
            "status": "403",
            "final": "https://tychon.io/tychoncryptographicinventory/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "2f9c80adacb71d4ab8c1a7bcbbe270f3e55e7931ede29d28d386e95e8ac8eeca",
            "checked_utc": "2026-10-01T02:20:15.594377+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/use-cases/quantumreadiness/",
            "status": "403",
            "final": "https://tychon.io/use-cases/quantumreadiness/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "8e61f25301b1612962dda1c7d04aab1a3e2e3649882fb0464481c662f2b093ab",
            "checked_utc": "2026-10-01T02:20:15.635554+00:00",
            "error": ""
          },
          {
            "url": "https://tychon.io/implementing-quantum-safe-cryptographic-discovery-in-your-ci-cd-pipeline-part-8-of-8/",
            "status": "403",
            "final": "https://tychon.io/implementing-quantum-safe-cryptographic-discovery-in-your-ci-cd-pipeline-part-8-of-8/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "60c9142f7a5d4489c676e23b417c09efeeaed8cad84d63ca961b82abd915cb86",
            "checked_utc": "2026-10-01T02:20:15.546765+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/elastic/integrations/pull/20142",
            "status": "200",
            "final": "https://github.com/elastic/integrations/pull/20142",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1316d53a72595841c894e4c38c01a848fd5d19f875fdcc8f8674597e10fa822c",
            "checked_utc": "2026-10-01T02:20:15.456368+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/tychon-quantum-command.json",
      "original_cell_score": 0,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://tychon.io/products/tychon/pqc-management-module/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/cryptographic-inventory/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/tychoncryptographicinventory/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/use-cases/quantumreadiness/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://tychon.io/implementing-quantum-safe-cryptographic-discovery-in-your-ci-cd-pipeline-part-8-of-8/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/elastic/integrations/pull/20142",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "tychon-quantum-command/C6",
      "product": "TYCHON Quantum Command",
      "slug": "tychon-quantum-command",
      "criterion": "C6",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor pages returned 403; archived response-action claim cannot verify automation/product scope.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://tychon.io/products/tychon/pqc-management-module/",
            "status": "403",
            "final": "https://tychon.io/products/tychon/pqc-management-module/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15abf1442b43867db2fa47e442af42c201c4112becd90ed3bba32c392d2b5611",
            "checked_utc": "2026-10-01T02:20:15.590187+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/elastic/integrations/pull/20142",
            "status": "200",
            "final": "https://github.com/elastic/integrations/pull/20142",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1316d53a72595841c894e4c38c01a848fd5d19f875fdcc8f8674597e10fa822c",
            "checked_utc": "2026-10-01T02:20:15.456368+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/tychon-quantum-command.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://tychon.io/products/tychon/pqc-management-module/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/elastic/integrations/pull/20142",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    },
    {
      "id": "tychon-quantum-command/C7",
      "product": "TYCHON Quantum Command",
      "slug": "tychon-quantum-command",
      "criterion": "C7",
      "final_score": 6,
      "weight_numerator": 2,
      "evidence_class": "archived_vendor_claim",
      "source_review_evidence_class": "documented",
      "source_entailment": "unverified_anchor",
      "source_entailment_note": "Vendor pages returned 403; dashboard/export claim unverified.",
      "internal_review_basis": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution; 1 October authenticated source status and quote context are recorded in fresh_verified_tls",
      "internal_review_basis_original": "archived exact quote/rationale and 2026-09-30 accessibility screen; fresh primary PDF/V1.1 checks where stated; no peer software execution",
      "internal_review_independence": "internal Qtonic/AWS verifier; no external assessor or uniform peer executable test",
      "fresh_verified_tls": {
        "checked_utc": "2026-10-01T02:22:55.912275+00:00",
        "accessible_source_count": 1,
        "total_cited_urls": 2,
        "full_archived_quote_reproduced": false,
        "quote_match_urls": [],
        "sources": [
          {
            "url": "https://tychon.io/products/tychon/pqc-management-module/",
            "status": "403",
            "final": "https://tychon.io/products/tychon/pqc-management-module/",
            "content_type": "text/html; charset=UTF-8",
            "method": "curl_verified_tls",
            "sha256": "15abf1442b43867db2fa47e442af42c201c4112becd90ed3bba32c392d2b5611",
            "checked_utc": "2026-10-01T02:20:15.590187+00:00",
            "error": ""
          },
          {
            "url": "https://github.com/elastic/integrations/pull/20142",
            "status": "200",
            "final": "https://github.com/elastic/integrations/pull/20142",
            "content_type": "text/html; charset=utf-8",
            "method": "curl_verified_tls",
            "sha256": "1316d53a72595841c894e4c38c01a848fd5d19f875fdcc8f8674597e10fa822c",
            "checked_utc": "2026-10-01T02:20:15.456368+00:00",
            "error": ""
          }
        ]
      },
      "original_archive": "/evidence/2026-7/tychon-quantum-command.json",
      "original_cell_score": 6,
      "final_review_adjustments": [],
      "researched_at": "2026-09-26",
      "source_access_checked_at": "2026-09-30T03:55:35Z",
      "source_access_state": "accessible_excerpt_not_reproduced",
      "cited_sources": [
        {
          "url": "https://tychon.io/products/tychon/pqc-management-module/",
          "accessibility": false,
          "excerpt_reproduced": false
        },
        {
          "url": "https://github.com/elastic/integrations/pull/20142",
          "accessibility": true,
          "excerpt_reproduced": false
        }
      ],
      "limitation": "This internal semantic review assesses source support for the archived wording; it does not validate the numeric score, product behavior, or deployed build. Read the archived rationale and final review adjustment."
    }
  ],
  "separate_artifact_records": [
    {
      "id": "qscout-own-api-sample",
      "evidence_class": "artifact-tested",
      "observed": "13-component own-API CBOM sample signature and one-byte tamper check",
      "build_custody": "vendor public API sample; deployed code identity not independently attested",
      "source": "/product-proof/qscout-sample-audit-2026-09-30.zip",
      "limitation": "Not a customer-estate scan or complete discovery proof."
    },
    {
      "id": "qscout-native-owned-lab",
      "evidence_class": "artifact-tested",
      "observed": "One seeded MD5 finding before and none after a harness edit; local candidate CBOM schema and format pass",
      "build_custody": "local source candidate 03e3b4f, not deployed",
      "source": "/product-proof/owned-lab-2026-09-30.zip",
      "limitation": "One synthetic file; after CBOM omits SHA-256 use and does not prove complete inventory."
    },
    {
      "id": "qscout-loopback-closure",
      "evidence_class": "artifact-tested",
      "observed": "One closed synthetic loopback case and four nonclosed controls",
      "build_custody": "owned harness and local candidate, not customer tenant",
      "source": "/product-proof/owned-lab-2026-09-30/workflow-summary.json",
      "limitation": "Harness polls and rescans; no autonomous product remediation or live customer outcome."
    },
    {
      "id": "owned-tls-transition",
      "evidence_class": "artifact-tested",
      "observed": "26 of 32 compatible same-port requests authenticated; six failed during two intentional restarts",
      "build_custody": "owned Node/OpenSSL fixture, not QScout actuator",
      "source": "/product-proof/owned-lab-2026-09-30/continuity.json",
      "limitation": "Interrupted service in a synthetic lab; no zero-downtime, PQ authentication or production result."
    }
  ]
}
