Skip to content

QStrike methodology

Model the attack path. Publish the boundary. Invite falsification.

QStrike methodology for modeled forward-threat validation across 6 provider-aligned modeled profiles, four modalities, and up to 8 access services—with zero connected quantum hardware and no live-hardware execution.

Truth boundary: provider names describe modeled profiles and published calibration context. They are not evidence of live provider execution, customer runtime, hardware access, or endorsement.

01

Bound the hypothesis

Start with a QScout finding, the affected cryptographic surface, the data-retention window, and a falsifiable attack-path question. QStrike does not expand scope without operator approval.

02

Separate observation from model input

Observed algorithms, configurations, dependencies, and evidence sources remain distinct from provider-profile assumptions, published calibration inputs, and future-adversary planning scenarios.

03

Run the provider-aligned model

The modeled runtime evaluates 6 provider-aligned modeled profiles across four modalities and can represent up to 8 access services. Current public status is zero connected quantum hardware and no live-hardware execution.

04

Attack the conclusion

Adversarial review checks alternative explanations, confidence, reproducibility boundaries, and the exact condition that would demote or falsify the modeled conclusion.

05

Deliver a governed decision object

The output ties scope, observed evidence, model inputs, result, confidence, falsification path, remediation owner, and QSolve handoff to one reviewable record.

Minimum evidence record

Observed
Approved-scope asset, algorithm, configuration, dependency, and source.
Modeled
Profile, modality, calibration input, assumption, and runtime version.
Result
Conclusion, confidence, alternative explanations, and falsification condition.
Action
Remediation owner, dependency, sequence, exit gate, and residual risk.

What the method never upgrades into fact

  • A resource estimate for a future machine is not a demonstrated cryptographic break.
  • A provider-aligned profile is not a submitted provider job.
  • A modeled runtime is not customer evidence or proof that a client key was broken.
  • The 2029 planning horizon is not a Q-Day prediction.