Fact
Directly observed in an approved source or tracked public artifact.
QScout-specific methodology
How QScout derives HNDL scores, severity weighting, finding confidence, CycloneDX CBOM structure, and report quality gates. The comprehensive treatment below covers the 7-factor HNDL model, single-break-year confidence intervals, NIST CNSA 2.0 alignment, and the migration-deadline calculator.
Approved Public Scope
QScout Surface starts from 46 approved external modules. Silver expands to 57, Gold covers the full 74-module governed catalog, and Pulse keeps the baseline current through reassessment.
One operating method
Qtonic Quantum uses one evidence chain from approved scope to governed action. The method separates observed facts, modeled inference, and recommendations so a buyer can challenge each conclusion without decoding multiple competing frameworks.
Scope first
Directly observed in an approved source or tracked public artifact.
A bounded conclusion with inputs, confidence, and a falsification condition.
A prioritized action with owner, dependency, and exit evidence.
01 · Find
Operator-approved collection maps algorithms, certificates, protocols, dependencies, and ownership evidence. Findings are normalized into CycloneDX 1.6 CBOM structure, prioritized by exposure and business context, then reviewed before delivery.
Observable output: asset, algorithm, location, evidence source, severity, owner, and recommended next action.
Inspect QScout method02 · Prove
QStrike evaluates selected findings against 6 provider-aligned modeled profiles across four modalities and up to 8 access services. Current public status is zero quantum hardware connected and no live-hardware execution. Provider-calibrated runtime is modeled evidence—not a client-key break or a live provider job.
Observable output: scoped hypothesis, model inputs, calibration boundary, result, confidence, and falsification condition.
Inspect QStrike truth boundary03 · Fix
QSolve turns accepted findings into a five-phase roadmap: inventory, prioritize, design, migrate, and govern. Each work item receives an owner, dependency, exit gate, and evidence requirement so migration is managed as an operating program.
Observable output: phase, control objective, evidence, accountable owner, dependency, and exit gate.
Open tracked roadmapSeparate public evidence registry
Qtonic Quantum Lab is not a fourth engagement step. It applies a published rubric to public implementation evidence and exposes provenance boundaries without turning registry inclusion into endorsement.
Inspect the Lab methodology