Cryptographic inventory, exposure class, data lifetime, and CBOM-ready evidence.
Identify the cryptography, systems, vendors, certificates, and protocols that create quantum-relevant exposure inside approved scope.
How we work
Scope. Evidence. Next action.
Scope is stated. Evidence is reviewable. Action is governed. Public pages do not display customer environments.
QScout Enterprise Product
QScout is the risk-adjusted first mile of cryptographic discovery: agentless, non-destructive, quantum-scored, from the attacker’s view—with credentialed depth when authorized. Maximum intelligence per unit of risk introduced into the buyer’s estate. Where estates permit agents and need runtime-depth inventory, agent-based platforms see more—and the coverage ledger states exactly what they would see that QScout does not.
A governed assessment produces a CycloneDX 1.7 CBOM, quantum-risk scoring, HNDL prioritization, Pulse reassessment, and finding-to-framework mapping across 15 enterprise framework families (mapping, not certification).
What is exposed?
Public, application, dependency, and platform cryptography across the approved lane.
What matters first?
Evidence thresholds, HNDL indicator, and operator review separate noise from decision-grade risk.
What changes next?
Outputs map remediation to owners, controls, artifacts, and CryptoAgility follow-on assessment.
CycloneDX 1.7 CBOM excerpt
Synthetic illustrative sample—not customer evidence. This public excerpt demonstrates the machine-readable QScout output shape.
{
"bomFormat": "CycloneDX",
"specVersion": "1.7",
"metadata": { "scope": "approved-scope synthetic example" },
"components": [{
"type": "cryptographic-asset",
"name": "tls-edge-example",
"cryptoProperties": {
"assetType": "certificate",
"algorithmProperties": {
"primitive": "signature",
"parameterSetIdentifier": "ECDSA-P256"
}
}
}]
}QScout Operating Layer
exposure state > evidence > signed proof
Quantum Exposure Index · QScout measured
Elevated · above threshold
| Endpoint | Crypto | Harvest | Conf. | State |
|---|---|---|---|---|
| api.example.test:443 | RSA-2048 · TLS 1.2 | Today | 0.98 | Exposed |
| login.example.test:443 | ECDSA-P256 · TLS 1.2 | Today | 0.96 | Exposed |
| vpn.example.test:500 | RSA-2048 · IKEv2 | Stored | 0.91 | At risk |
| mail.example.test:993 | RSA-3072 · IMAPS | Stored | 0.88 | At risk |
| edge.example.test:443 | X25519+ML-KEM · TLS 1.3 | Hybrid | 0.99 | Scored |
No customer telemetry is used. Synthetic placeholders only.
Find > Prove > Fix > Credential
QScout in the operating model
A buyer-readable path from quantum exposure to governed evidence: find the cryptographic surface, prove materiality, fix the migration sequence, and credential outcomes without exposing customer data.
Cryptographic inventory, exposure class, data lifetime, and CBOM-ready evidence.
Identify the cryptography, systems, vendors, certificates, and protocols that create quantum-relevant exposure inside approved scope.
Materiality, attacker path, validation boundary, and falsifiable evidence.
Convert selected exposure into governed forward-threat demonstration and separate evidence from noise before migration work expands.
Owner assignment, exception handling, migration sequence, and control routing.
Turn the finding record into a buyer-controlled remediation sequence aligned to standards, procurement, architecture, and operating constraints.
Release proof, sample evidence, diligence boundaries, and readiness records.
Publish public proof where it is safe, keep buyer-specific evidence controlled, and preserve a record leaders can defend.
Evidence-led platform claims
The platform message is intentionally bounded: public-surface discovery is not the same as an authenticated internal assessment, verified evidence is separated from advisory intelligence, and every output is designed to be reconstructable for buyer, auditor, operator, and board review.
Enterprise proof boundary
Proof platform
Inventory is where discovery starts. Proof is where QScout changes the conversation: findings, risk context, runtime state, and evidence artifacts in one buyer-reviewable chain.
Migration-state discovery
Built for organizations moving from today’s cryptography to hybrid and post-quantum readiness.
CBOM-ready inventory
Binds CBOM output into governed operational evidence so teams can see what ran, when, against which release, and whether it passed. ML-DSA signing capability may be available without public artifact delivery on every path.
HNDL prioritization
Prioritizes quantum risk by asset exposure, data sensitivity, crypto posture, and migration urgency.
Cryptographic debt
Helps teams decide what to fix first, what to monitor, and what requires deeper access.
Governance and migration use
What QScout Delivers
QScout translates authorized findings into risk language, proof boundaries, and next actions that procurement, security, audit, and engineering can use.
Executive quantum-risk brief
Cryptographic-debt and HNDL indicator
Evidence ledger with scope boundaries
Control and compliance mapping
CryptoAgility readiness path by ownership lane
CBOM and governed artifacts where approved
QScout Model
QScout starts from approved scope. Surface, Silver, and Gold are the governed assessment tiers. QScout Pulse is the report family across all three, not a fourth tier.
QScout Surface
Approved public domains and external cryptographic surface.
Exposure map, executive brief, and non-destructive proof line.
QScout Silver
Approved credentials, application evidence, source, build, and dependency context.
Assessed exposure, control mapping, and CryptoAgility sequence.
QScout Gold
Privileged infrastructure, runtime, telemetry, CBOM, and governed evidence.
Audit-grade evidence packets for enterprise review where privileged scope, runtime, telemetry, CBOM, and governed evidence are approved.
QScout Pulse: report family across Surface, Silver, and Gold. Reassessment or continuity work requires separately approved scope; this page does not promise continuous monitoring.
Operator Intake
The public page captures authorization context and routes the request to Qtonic Quantum Corp. An analyst confirms the requester and scope before the assessment is fulfilled.
Assessment work starts only after operator scope approval.
Intake requests do not collect credentials, secrets, internal data, or raw artifacts.
Surface, Silver, and Gold are QScout's governed assessment tiers; QScout Pulse is the report family across all three. No self-serve public scan runs from the website; assessment work starts only after explicit authorization and operator scope approval.
QScout uses a governed 74-module catalog across Surface, Silver, and Gold.
Operating proof · QScout
Company-reported public metrics. Each figure links to its governing artifact — inspect before you trust.
Market validation for QScout
Policy, standards, and hyperscaler signals all point to the same front door: find cryptography, identify vulnerable systems, and keep the inventory alive enough to govern.
Third-party quotations and source references are provided solely as public market, policy, and technical context for post-quantum readiness. They do not imply endorsement, sponsorship, certification, partnership, resale authorization, or validation of Qtonic Quantum, QScout, QStrike, QSolve, or Qtonic Quantum Lab by the quoted individual, publisher, agency, company, or organization. Third-party names and marks belong to their owners.
Regulatory references are informational and may apply differently by jurisdiction, agency, system classification, contract, and final rulemaking. This is not legal or compliance advice.
“collecting United States information now, and decrypting it later”
QScout finds harvestable exposure; QStrike proves which paths matter under governed scope.
“Manual processes are often inadequate for this migration scope.”
QScout becomes the front door; QSolve turns inventory and risk evidence into accountable CryptoAgility execution.
“controlled, non-production environment”
QStrike and QLab support non-destructive validation and reviewable readiness evidence before migration pressure hits production.
“find and prioritize vulnerable systems”
QScout is positioned as quantum cyber risk and vulnerability intelligence, not generic vulnerability scanning.
OMB M-26-15 is here - 92 days remaining
Federal agencies have until Oct 22, 2026 to submit PQC Migration Plans. Qtonic Quantum Corp helps produce cryptographic inventory, CBOM-grade visibility, and prioritization evidence.
M-26-15 inventory evidence
QScout helps identify quantum-vulnerable cryptographic indicators, TLS posture, certificate evidence, protocol exposure, and owner-ready risk evidence for PQC migration planning.
Evidence
Cryptographic exposure inventory
Evidence
TLS and certificate posture
Evidence
CBOM-grade evidence where scope permits