Citation record

Numbered sources and verification dates

Every product and finding page links back to this record. Descriptions are reproduced from the supplied edition. Where a primary source could be resolved, its canonical URL is included for direct verification.

  1. S01

    Qtonic Quantum public trust endpoints: capability manifest with per-surface availability, certification posture, score reconciliation and methodology v2026.08.12. Verified 15 August 2026 against build 07237bd8.

  2. S02

    Qtonic Quantum public trust endpoints: signed CycloneDX 1.7 inventory, detached ML-DSA-65 signature, public verification key and procedure, release corruption gate, 1,368-case accuracy corpus with recall 0.7628, hash-chained change events and published vantage policy. Verified 15 August 2026.

  3. S03

    Qtonic Quantum integrations documentation: Jira and ServiceNow mappings, workflow envelope, canonical hash rule, closed-loop sequence and the limitation that connectors are one-way creation and dry-run by default. Verified 15 August 2026.

  4. S04

    Encryption Consulting discovery documentation: seven languages, at least seventy cryptographic libraries, more than eight hundred function patterns, cross-file reachability, key-reuse detection and HSM versus software-key separation. Reviewed 13 August 2026.

    Open primary source

  5. S05

    Encryption Consulting posture documentation: discovery across cloud key services, HSMs, key managers, databases, directories, network endpoints and source; 0-100 risk scoring; continuous evaluation; cryptographically verifiable asset-change log. Reviewed 13 August 2026.

    Open primary source

  6. S06

    Encryption Consulting launch material, June 2026: audit artifacts generated in CycloneDX 1.6 and 1.7. Reviewed 13 August 2026.

    Open primary source

  7. S07

    AppViewX post-quantum readiness documentation: assessment across code, packages, dependencies, configuration and certificates, CycloneDX CBOM, readiness score and delivery-pipeline agent. Verified 27 July 2026.

    Open primary source

  8. S08

    Keyfactor AgileSec release notes 3.4 and 3.5.1, April 2026: per-source CycloneDX 1.6 CBOM export. Verified 26 July 2026.

    Open primary source

  9. S09

    IBM Quantum Safe documentation and CBOM specification history: CBOM developed by IBM researchers and upstreamed into CycloneDX 1.6. Verified 27 July 2026.

    Open primary source

  10. S10

    IBM open-source CBOM toolchain generating standards-conformant inventory from source and container images, listed in the CycloneDX Tool Center. Reviewed 1 August 2026.

    Open primary source

  11. S11

    TYCHON documentation: continuous discovery across networks, endpoints, containers, cloud storage, VPNs and embedded systems, including air-gapped estates. Verified 26 July 2026.

    Open primary source

  12. S12

    SandboxAQ AQtive Guard public product and trust marketing. Verified 26 July 2026.

    Open primary source

  13. S13

    QuSecure QuProtect documentation: automated scanning across cloud, on-premises, air-gapped and legacy systems with real-time inventory and bill-of-materials access. Verified 27 July 2026.

    Open primary source

  14. S14

    ISARA Advance documentation: agentless inventory, posture scoring and audit-ready reporting across cloud, on-premises and hybrid estates. Verified 27 July 2026.

    Open primary source

  15. S15

    Fortanix Key Insight documentation: CycloneDX extension export, generally available from release 25.07, with provenance through key-management correlation. Verified 26 July 2026.

    Open primary source

  16. S16

    CryptoNext COMPASS documentation: CycloneDX inventory database fed by network probes. Verified 27 July 2026.

    Open primary source

  17. S17

    O3 Security material: discovery across code, dependencies, containers and cloud; forecasts for quantum vulnerability; migration priority using inventory, vulnerability class, sensitivity and data lifespan. Reviewed 13 August 2026.

    Open primary source

  18. S18

    DigiCert Quantum Central free preview documentation from 1 July 2026. Verified 26 July 2026.

    Open primary source

  19. S19

    QCecuring documentation: scanning source, certificates, keys, HSMs, cloud services and network endpoints with CycloneDX-compliant output. Reviewed 13 August 2026.

    Open primary source

  20. S20

    CycloneDX Tool Center listing for a static cryptographic asset scanner producing CycloneDX 1.6 and 1.7 with post-quantum readiness classification across more than forty NIST algorithms. Reviewed 1 August 2026.

    Open primary source

  21. S21

    Encryption Consulting launch material, June 2026: deployment supporting cloud, on-premises and air-gapped environments. Reviewed 13 August 2026.

    Open primary source

  22. S22

    Independent post-quantum migration timeline analysis naming Keyfactor, Venafi and IBM Guardium as discovery tooling. Reviewed 1 August 2026.

  23. S23

    August 2026 arXiv research paper: Cryben uses independently constructed CycloneDX 1.7 ground truth; Crypsy and CBOMkit-hyperion are compared on a Go-invocation subset with the same occurrence-level evaluator. These separate tool results do not establish performance of QScout, CBOM Secure or the other scored vendor products.

    Open primary source

  24. S24

    AppViewX certificate-lifecycle material: ServiceNow and automation descriptions concern AVX ONE CLM. The reviewed Quantum Trust Hub guide describes its PQC remediation as manual; these product scopes must not be conflated.

    Open primary source

  25. S25

    Keyfactor AgileSec ServiceNow VR documentation: a scheduled connector imports cryptographic vulnerabilities and detections into ServiceNow. This page does not document reverse write-back or verified closure. Reviewed 29 September 2026.

    Open primary source

  26. S26

    IBM Research Cryptoscope preprint: its reported 97-asset evaluation found 92 percent full-match recall, 98 percent recall including partial matches, and 97 percent precision. This is a separate research tool, not a test of the scored Guardium + Quantum Safe product. Reviewed 29 September 2026.

    Open primary source

  27. S27

    Qtonic Quantum public trust endpoint /public/trust/v4-capability: the vendor instrument publishes its own index and states 'not a peer rank; zero peers run through v4'. Verified 27 September 2026 against build 9497e709.

    Open primary source

  28. S28

    Qtonic Quantum public trust endpoint /public/trust/accuracy-metrics: 1,368-case corpus, recall 0.7628, precision marked construction_artifact, labels derived with the detector's own vocabulary. Verified 27 September 2026.

    Open primary source

  29. S29

    Qtonic Quantum public trust endpoints /public/trust/workflow and /public/trust/integrations: inbound HMAC receipt and conflict-reopen rule implemented; no live ticketing tenant; write-back client not deployed. Verified 27 September 2026.

    Open primary source

  30. S30

    Qtonic Quantum signed CycloneDX 1.7 sample with detached ML-DSA-65 signature, public verification key and five-step verification procedure. Verified 27 September 2026.

    Open primary source

  31. S31

    Edition 2026.7 evidence files: one JSON per product with, for every cell, the URLs read, a verbatim quote and the scoring rationale, plus the post-review totals (_FINAL.json). The publisher reports five researchers on 26 September 2026 and three adversarial reviews that applied 14 cell changes.

    Open primary source

  32. S32

    Products found in category during the 2026.7 research and not yet scored: Arqit Encryption Intelligence, PQStation QVision, QryptoCyber, QuintessenceLabs TSF Sentry. Vendor pages reviewed 26 September 2026.

    Open primary source