Citation record
Numbered sources and verification dates
Every product and finding page links back to this record. Descriptions are reproduced from the supplied edition. Where a primary source could be resolved, its canonical URL is included for direct verification.
- S01
Qtonic Quantum public trust endpoints: capability manifest with per-surface availability, certification posture, score reconciliation and methodology v2026.08.12. Verified 15 August 2026 against build 07237bd8.
- S02
Qtonic Quantum public trust endpoints: signed CycloneDX 1.7 inventory, detached ML-DSA-65 signature, public verification key and procedure, release corruption gate, 1,368-case accuracy corpus with recall 0.7628, hash-chained change events and published vantage policy. Verified 15 August 2026.
- S03
Qtonic Quantum integrations documentation: Jira and ServiceNow mappings, workflow envelope, canonical hash rule, closed-loop sequence and the limitation that connectors are one-way creation and dry-run by default. Verified 15 August 2026.
- S04
Encryption Consulting discovery documentation: seven languages, at least seventy cryptographic libraries, more than eight hundred function patterns, cross-file reachability, key-reuse detection and HSM versus software-key separation. Reviewed 13 August 2026.
- S05
Encryption Consulting posture documentation: discovery across cloud key services, HSMs, key managers, databases, directories, network endpoints and source; 0-100 risk scoring; continuous evaluation; cryptographically verifiable asset-change log. Reviewed 13 August 2026.
- S06
Encryption Consulting launch material, June 2026: audit artifacts generated in CycloneDX 1.6 and 1.7. Reviewed 13 August 2026.
- S07
AppViewX post-quantum readiness documentation: assessment across code, packages, dependencies, configuration and certificates, CycloneDX CBOM, readiness score and delivery-pipeline agent. Verified 27 July 2026.
- S08
Keyfactor AgileSec release notes 3.4 and 3.5.1, April 2026: per-source CycloneDX 1.6 CBOM export. Verified 26 July 2026.
- S09
IBM Quantum Safe documentation and CBOM specification history: CBOM developed by IBM researchers and upstreamed into CycloneDX 1.6. Verified 27 July 2026.
- S10
IBM open-source CBOM toolchain generating standards-conformant inventory from source and container images, listed in the CycloneDX Tool Center. Reviewed 1 August 2026.
- S11
TYCHON documentation: continuous discovery across networks, endpoints, containers, cloud storage, VPNs and embedded systems, including air-gapped estates. Verified 26 July 2026.
- S12
SandboxAQ AQtive Guard public product and trust marketing. Verified 26 July 2026.
- S13
QuSecure QuProtect documentation: automated scanning across cloud, on-premises, air-gapped and legacy systems with real-time inventory and bill-of-materials access. Verified 27 July 2026.
- S14
ISARA Advance documentation: agentless inventory, posture scoring and audit-ready reporting across cloud, on-premises and hybrid estates. Verified 27 July 2026.
- S15
Fortanix Key Insight documentation: CycloneDX extension export, generally available from release 25.07, with provenance through key-management correlation. Verified 26 July 2026.
- S16
CryptoNext COMPASS documentation: CycloneDX inventory database fed by network probes. Verified 27 July 2026.
- S17
O3 Security material: discovery across code, dependencies, containers and cloud; forecasts for quantum vulnerability; migration priority using inventory, vulnerability class, sensitivity and data lifespan. Reviewed 13 August 2026.
- S18
DigiCert Quantum Central free preview documentation from 1 July 2026. Verified 26 July 2026.
- S19
QCecuring documentation: scanning source, certificates, keys, HSMs, cloud services and network endpoints with CycloneDX-compliant output. Reviewed 13 August 2026.
- S20
CycloneDX Tool Center listing for a static cryptographic asset scanner producing CycloneDX 1.6 and 1.7 with post-quantum readiness classification across more than forty NIST algorithms. Reviewed 1 August 2026.
- S21
Encryption Consulting launch material, June 2026: deployment supporting cloud, on-premises and air-gapped environments. Reviewed 13 August 2026.
- S22
Independent post-quantum migration timeline analysis naming Keyfactor, Venafi and IBM Guardium as discovery tooling. Reviewed 1 August 2026.
- S23
August 2026 arXiv research paper: Cryben uses independently constructed CycloneDX 1.7 ground truth; Crypsy and CBOMkit-hyperion are compared on a Go-invocation subset with the same occurrence-level evaluator. These separate tool results do not establish performance of QScout, CBOM Secure or the other scored vendor products.
- S24
AppViewX certificate-lifecycle material: ServiceNow and automation descriptions concern AVX ONE CLM. The reviewed Quantum Trust Hub guide describes its PQC remediation as manual; these product scopes must not be conflated.
- S25
Keyfactor AgileSec ServiceNow VR documentation: a scheduled connector imports cryptographic vulnerabilities and detections into ServiceNow. This page does not document reverse write-back or verified closure. Reviewed 29 September 2026.
- S26
IBM Research Cryptoscope preprint: its reported 97-asset evaluation found 92 percent full-match recall, 98 percent recall including partial matches, and 97 percent precision. This is a separate research tool, not a test of the scored Guardium + Quantum Safe product. Reviewed 29 September 2026.
- S27
Qtonic Quantum public trust endpoint /public/trust/v4-capability: the vendor instrument publishes its own index and states 'not a peer rank; zero peers run through v4'. Verified 27 September 2026 against build 9497e709.
- S28
Qtonic Quantum public trust endpoint /public/trust/accuracy-metrics: 1,368-case corpus, recall 0.7628, precision marked construction_artifact, labels derived with the detector's own vocabulary. Verified 27 September 2026.
- S29
Qtonic Quantum public trust endpoints /public/trust/workflow and /public/trust/integrations: inbound HMAC receipt and conflict-reopen rule implemented; no live ticketing tenant; write-back client not deployed. Verified 27 September 2026.
- S30
Qtonic Quantum signed CycloneDX 1.7 sample with detached ML-DSA-65 signature, public verification key and five-step verification procedure. Verified 27 September 2026.
- S31
Edition 2026.7 evidence files: one JSON per product with, for every cell, the URLs read, a verbatim quote and the scoring rationale, plus the post-review totals (_FINAL.json). The publisher reports five researchers on 26 September 2026 and three adversarial reviews that applied 14 cell changes.
- S32
Products found in category during the 2026.7 research and not yet scored: Arqit Encryption Intelligence, PQStation QVision, QryptoCyber, QuintessenceLabs TSF Sentry. Vendor pages reviewed 26 September 2026.