Citation record

Numbered sources and verification dates

Every product and finding page links back to this record. Descriptions are reproduced from the supplied edition. Where a primary source could be resolved, its canonical URL is included for direct verification.

  1. S01

    Qtonic Quantum public trust endpoints: capability manifest with per-surface availability, certification posture, score reconciliation and methodology v2026.08.12. Verified 15 August 2026 against build 07237bd8.

  2. S02

    Qtonic Quantum public trust endpoints: signed CycloneDX 1.7 inventory, detached ML-DSA-65 signature, public verification key and procedure, release corruption gate, 1,368-case accuracy corpus with recall 0.7628, hash-chained change events and published vantage policy. Verified 15 August 2026.

  3. S03

    Qtonic Quantum integrations documentation: Jira and ServiceNow mappings, workflow envelope, canonical hash rule, closed-loop sequence and the limitation that connectors are one-way creation and dry-run by default. Verified 15 August 2026.

  4. S04

    Encryption Consulting discovery documentation: seven languages, more than seventy cryptographic libraries, more than eight hundred function patterns, cross-file reachability, key-reuse detection and HSM versus software-key separation. Reviewed 13 August 2026.

    Open primary source

  5. S05

    Encryption Consulting posture documentation: discovery across cloud key services, HSMs, key managers, databases, directories, network endpoints and source; 0-100 risk scoring; continuous evaluation; cryptographically verifiable asset-change log. Reviewed 13 August 2026.

    Open primary source

  6. S06

    Encryption Consulting launch material, June 2026: audit artifacts generated in CycloneDX 1.6 and 1.7. Reviewed 13 August 2026.

    Open primary source

  7. S07

    AppViewX post-quantum readiness documentation: assessment across code, packages, dependencies, configuration and certificates, CycloneDX CBOM, readiness score and delivery-pipeline agent. Verified 27 July 2026.

    Open primary source

  8. S08

    Keyfactor AgileSec release notes 3.4 and 3.5.1, April 2026: per-source CycloneDX 1.6 CBOM export. Verified 26 July 2026.

    Open primary source

  9. S09

    IBM Quantum Safe documentation and CBOM specification history: CBOM developed by IBM researchers and upstreamed into CycloneDX 1.6. Verified 27 July 2026.

    Open primary source

  10. S10

    IBM open-source CBOM toolchain generating standards-conformant inventory from source and container images, listed in the CycloneDX Tool Center. Reviewed 1 August 2026.

    Open primary source

  11. S11

    TYCHON documentation: continuous discovery across networks, endpoints, containers, cloud storage, VPNs and embedded systems, including air-gapped estates. Verified 26 July 2026.

    Open primary source

  12. S12

    SandboxAQ AQtive Guard public product and trust marketing. Verified 26 July 2026.

    Open primary source

  13. S13

    QuSecure QuProtect documentation: automated scanning across cloud, on-premises, air-gapped and legacy systems with real-time inventory and bill-of-materials access. Verified 27 July 2026.

    Open primary source

  14. S14

    ISARA Advance documentation: agentless inventory, posture scoring and audit-ready reporting across cloud, on-premises and hybrid estates. Verified 27 July 2026.

    Open primary source

  15. S15

    Fortanix Key Insight documentation: CycloneDX extension export, generally available from release 25.07, with provenance through key-management correlation. Verified 26 July 2026.

    Open primary source

  16. S16

    CryptoNext COMPASS documentation: CycloneDX inventory database fed by network probes. Verified 27 July 2026.

    Open primary source

  17. S17

    O3 Security material: discovery across code, dependencies, containers and cloud; forecasts for quantum vulnerability; migration priority using inventory, vulnerability class, sensitivity and data lifespan. Reviewed 13 August 2026.

    Open primary source

  18. S18

    DigiCert Quantum Central free preview documentation from 1 July 2026. Verified 26 July 2026.

    Open primary source

  19. S19

    QCecuring documentation: scanning source, certificates, keys, HSMs, cloud services and network endpoints with CycloneDX-compliant output. Reviewed 13 August 2026.

    Open primary source

  20. S20

    CycloneDX Tool Center listing for a static cryptographic asset scanner producing CycloneDX 1.6 and 1.7 with post-quantum readiness classification across more than forty NIST algorithms. Reviewed 1 August 2026.

    Open primary source

  21. S21

    Encryption Consulting launch material, June 2026: deployment supporting cloud, on-premises and air-gapped environments. Reviewed 13 August 2026.

    Open primary source

  22. S22

    Independent post-quantum migration timeline analysis naming Keyfactor, Venafi and IBM Guardium as discovery tooling. Reviewed 1 August 2026.

  23. S23

    Peer-reviewed benchmark for static cryptographic asset discovery, August 2026: independently constructed CycloneDX 1.7 ground truth and occurrence-level comparison of two tools under one evaluator. Reviewed 15 August 2026.

    Open primary source

  24. S24

    AppViewX ServiceNow integration material and marketplace listing: northbound and southbound control, closed-loop workflows, last-mile certificate installation and remediation in delivery pipelines. Reviewed 15 August 2026.

    Open primary source

  25. S25

    Keyfactor ServiceNow announcements and listings from October 2025 onward: cryptographic findings routed into vulnerability response, tracked to remediation, with automated certificate deployment and endpoint binding. Reviewed 15 August 2026.

  26. S26

    Peer-reviewed cryptographic-usage study reporting 92 percent correct asset identification, rising to 98 percent with partial matches, and a low false-positive rate. Reviewed 15 August 2026.