Skip to content

QScout · Find

Find the cryptography that creates tomorrow’s risk.

QScout turns approved scope into a decision-ready view of what is exposed and what must move first.

QScout · exposure map

Discovery to CBOM

What is exposed, why it matters, and what action follows — shown as a reviewable path, not a raw score.

  • Context · what is in scope
  • Evidence · what supports the claim
  • Exposed · what needs attention
  • Ready · what can move next
  1. Sample stage 1Approved scope asset

    Long lived records service

  2. Sample stage 2Observed dependency

    RSA-2048 · TLS (sample)

  3. Sample stage 3Exposure decision

    Confidentiality window past plan

  4. Sample stage 4QScout output

    Owner · evidence · priority

Illustrative product view · synthetic data · not customer telemetry

Illustrative view with synthetic data. Not customer telemetry.

The decision

Where is vulnerable cryptography, what data stays sensitive long enough to matter, and what should we migrate first?

QScout · supportability ledger · read live

connecting

Values populate after this page loads in your browser; the server-rendered copy asserts no current state.

Deployed identity · connecting

API version
—
Build
—
One-SHA identity
—

Runtime gate · connecting

Runtime gate
—
Release slot
—
Failed required gates
—
Degraded
—

Published incidents · connecting —

Registry evidence · connecting

Scored entries
—
Strict-pass
—
Provisional
—
Candidates rejected
—
Audit-log entries
—
Registry last scored
—

Version, runtime-gate state and incident ledger are read live from api.qtonicquantum.com on each page load. Registry counts are read live from lab.qtonicquantum.com; the entries themselves were last scored on the date shown, not today. A green runtime gate is an internal release check — it is not ATLAS, not FIPS, not an ATO, and not a certification. Published incidents are Qtonic Quantum Corp's own disclosures, not third-party attestation. The exposure map in the hero above remains a Demonstration on synthetic data.

Guided product demonstration

Every frame is labeled by evidence state, explains the decision it supports, and links to the method or public sample behind it.

Two brushed-steel blocks split by a violet pulse line beneath a suspended needle

QScout · operator console

What the operator sees

QScout operator console showing an approved-scope cryptographic inventory with observed algorithms, certificates, and harvest-now-decrypt-later exposure rows
Sanitized product screen. Composite, anonymized data; no customer telemetry. Coverage shown is bounded by the approved scope of the engagement it came from.

QScout · 1:27 film

QScout: Find It First

Demonstration film · 1:27 · captions included · composite, anonymized data. Read the full transcript

QScout outcomes

What the buyer can decide next

01

A defensible inventory

See systems, protocols, and cryptographic dependencies in one governed evidence set, each with its sensitive-data lifetime, quantum urgency, and owner.

02

Materiality, not a list

Connect exposure to data lifetime, business context, and harvest-now risk.

03

A migration starting point

Give owners an ordered path into validation and remediation planning.

Why QScout

The product truth that makes this step distinct

Governed assessment depth

QScout uses a governed 74-module catalog across Surface, Silver, and Gold. Surface, Silver, and Gold map to 46, 57, and 74 cumulative modules. The governed catalog is 74 modules. Availability still depends on approved scope.

One continuous report family

QScout Gold Pulse carries approved evidence forward across the governed QScout tiers; it is not a fourth flagship product.

Framework mapping, not certification

Findings can map to a scoped subset of 15 enterprise framework families. A mapping is evidence context, never a certification claim.

Operating method

Three governed assessment moves

  1. 01

    Approve scope

    An operator confirms authorization and the assessment boundary before work starts.

  2. 02

    Collect evidence

    QScout examines the approved surface and separates observations from validated findings.

  3. 03

    Deliver the decision record

    Leaders receive evidence, prioritization, and CBOM output where the engagement approves it.

Proof receipt

Claim, method, state, and limit—in one place

Bounded product truth. No customer telemetry in this public view.

Claim
QScout maintains a governed assessment catalog and produces CycloneDX CBOM output where approved.
Scope
Approved-scope QScout assessment evidence and CBOM output; not an unrestricted public scan.
Method
Read the product truth registry, module catalog, and representative QScout report structure.
Artifact
74-module catalog · CycloneDX 1.7
Freshness
Product canon bound to website build 8583df0f5fe3.
Status
documented
Limitation
Module availability depends on approved scope. Mapping is not certification, and the public site does not run an unrestricted scan. Workflow connectors (Jira / ServiceNow) are one-way ticket creation and dry-run by default today.

Governed intake

Assessment begins with authorization.

The intake captures business context only. Qtonic Quantum Corp confirms requester authority and approved scope before assessment work runs.

What a full run covers (preview)

Not a self-serve public scan. After authorization, assessment work uses the governed catalog: Surface 46 · Silver 57 · Gold 74 cumulative modules.

  1. Surface: 46
  2. Silver: 57
  3. Gold: 74

Fulfilled by request — a Qtonic Quantum Corp analyst confirms authorization and scope before any assessment work.