Skip to content

Reference for procurement, security, and audit teams

QScout Enterprise Buyer's Guide

QScout is the discovery layer of the Qtonic Quantum suite. This guide explains how QScout Surface, QScout Silver, QScout Gold, and QScout Pulse work, what evidence each depth can receive, and the operator intake path. Talk to us for a tailored enterprise proposal.

Approved Public Scope

QScout uses a governed 74-module catalog across Surface, Silver, Gold, and Pulse. No self-serve public scan runs from the website.

01

What QScout Is

QScout is a cryptographic-discovery and HNDL-scoring product. QScout Surface is requester-verified and operator-reviewed; QScout Silver, QScout Gold, and QScout Pulse are scoped assessment paths with explicit consent and governed evidence delivery.

Output is procurement-grade: every finding is traceable to its source, the scoring rubric is public, and governed evidence delivery follows the current capability manifest so downstream auditors can verify integrity without relying on marketing copy.

02

Who It's For

  • CISO & security architects — quantifying HNDL exposure ahead of NIST CNSA 2.0 and NSM-10 deadlines.
  • Procurement and TPRM teams — evaluating crypto posture of vendors and acquisitions.
  • Audit and compliance leads — producing governed evidence for FIPS 203/204/205, PCI DSS 4.0.1, and HIPAA control frameworks.
  • Boards and risk committees — enterprise quantum-risk evidence reporting on a recurring cadence.

03

How QScout Scope Depths Differ

Every governed QScout path starts from declared buyer-approved scope. Public intake stays bounded; public, credentialed, privileged, and reassessment scope depths add depth only when approved.

Public Intake — Approved Surface Snapshot
Requester-authorized public-surface family across up to 10 total authorized same-domain public hosts. No credentials, no penetration, no all-domain assessment claim.
QScout Surface — All Approved Public Domains
Paid unauthenticated external validation across all approved public domains: exposed locks, doors, services, panels, TLS, certificate posture, cryptographic controls, and outsider-reachable paths.
QScout Silver — Surface Plus Approved Credentials
Adds approved credentials for application, source, build, dependency, authenticated workflow, and integration evidence.
QScout Gold — Approved Privileged Evidence
Adds privileged infrastructure, runtime, telemetry, CBOM, cryptographic inventory, and governed evidence packaging.
QScout Pulse — Continuous Intelligence After Approved Scope
Keeps approved QScout intelligence current with scheduled reassessment, event-triggered updates, drift reporting, and exposure-regression monitoring.

04

What You Get

  • Public intake: executive-safe public-surface snapshot, severity profile, HNDL indicator, and proof boundary.
  • QScout Surface: all-approved-public-domain external validation without credentials.
  • QScout Silver: approved credentialed app, source, build, and dependency evidence.
  • QScout Gold: privileged infrastructure, runtime, telemetry, CBOM, and governed evidence packaging.
  • QScout Pulse: continuous cryptographic risk intelligence after approved QScout scope.
  • Buyer briefing document tailored to the requesting role.

05

Procurement Path

  1. Request QScout assessment intake for approved public scope or a demonstration scope.
  2. Sign the QScout MSA and statement of work. Scope and consent are explicit per environment.
  3. Engagement begins on the agreed start date. Findings stream into the operator console as they land.
  4. Final delivery includes the governed evidence pack and a procurement briefing for the requesting team.
  5. Enterprise work starts through contact/ticket intake, then an operator provisions the approved engagement.

06

Frequently Asked Questions

Is QScout the same as a vulnerability scanner?
No. QScout is a cryptographic-inventory and HNDL-scoring service. It is purpose-built for quantum-readiness reporting, not generic CVE enumeration.
Do you scan without consent?
Never. Scope and consent are the first artifacts of every engagement. Public-surface assessment work still requires a confirmed requester.
Can findings be independently verified?
Yes. Governed evidence delivery follows the published verification path and current capability manifest. A third-party auditor can re-run supported verification offline.
How does this fit with QStrike and QSolve?
QScout finds it. QStrike proves it. QSolve fixes it. The three share evidence formats so the discovery from QScout flows directly into governed validation and remediation workflows.

Want this guide as it evolves?

We update the buyer's guide each quarter as standards and regulations move. Leave your address and we will send the next revision.

We use your address to send the requested information. No third-party sharing.