Quantum Claim Audit · $5,000 · 10 business days

One claim in.
One defensible
verdict out.

For boards, CISOs, CTOs, investors, and vendor-risk teams. Send one vendor claim, deck, white paper, NISQ result, or board question. Six deliverables. One verdict on paper — attach it to the vendor file, the investment memo, or the board pack.

$5,000 fixed scope · 10 business days · Limited to 3 concurrent engagements
Intake only — do not email confidential materials. Secure upload provided after conflict check.

Six deliverables · Fixed scope

What you receive.

  1. Claim mapThe assertion restated in testable terms. What is claimed, what it implies, what evidence is cited.
  2. Threat-model checkWhat would need to be true for this to matter to your organization — including risk timing under NIST PQC standards and the Dec 31, 2030 federal migration deadline.
  3. Evidence reviewHardware vs. simulator vs. emulator, benchmark design, post-processing dependence, unstated assumptions.
  4. Failure-mode analysisWhere false positives and cherry-picking enter this specific claim — which of the five failure modes applies and how.
  5. Board memoOne page. Ignore, monitor, test, fund, or reject — with the reasoning your board can hold. Designed to attach to a vendor file or be read in a 90-second briefing.
  6. Vendor question set5–10 questions tailored to the specific claim — for your next call with the vendor, the investor, or the PoC team.
The scorecard

Five questions. Each one has a finding.

Claim specificity What exactly is being asserted, in testable terms? A claim that cannot be falsified in principle receives a structural flag.
Evidence provenance Where did the evidence come from? QPU, simulator, emulator, or hybrid? Job IDs, backend, shot counts, execution timestamps.
Baseline adequacy Does the result survive synthetic null replacement — random data through the same pipeline? Does classical post-processing alone reproduce it?
Falsification strength Which of the five failure modes applies? Which alternative explanations were tested? What would the result have to look like for the claim to be false?
Decision relevance What action does the surviving evidence justify? Ignore, monitor, test, fund, or reject — with the specific reasoning and the conditions that would change it.
Fit

For / not for.

Good fit

Vendor due diligence — a claim in a pitch, RFP, or contract. PoC result review — a team returned a quantum result and you need to know if it's real. Board claim verification — a memo that depends on a quantum milestone or a "quantum safe" assertion. Investment or partnership diligence — one technical claim at the center of a decision. Pre-publication adversarial review — before quantum research is cited in decisions.

Not included

Formal regulatory certification or compliance filing. Legal or investment advice. Penetration testing. Full PQC migration planning or implementation. Review of multiple independent claims in one engagement — each additional claim is a separate scope. Unlimited vendor portfolio review.

What counts as "one claim"? One vendor assertion, one milestone interpretation, or one connected PoC result with a defined decision attached. If you're not sure, submit intake and we'll advise on scope.

A free sample of the method

The trap question for PQC vendor demos

Ask: "What exactly did the hardware demonstration validate — implementation behavior, interoperability, or cryptanalytic resistance?"

A vendor who ran an interoperability test on a classical library has a defensible answer. A vendor who claims the demo validated quantum resistance is revealing either a misunderstanding of current hardware capability (today's NISQ machines cannot break RSA-2048 or ECC-256, so they cannot meaningfully "fail to break" a PQC scheme) or a willingness to sell theater. Either answer belongs in the vendor file.

Nine more questions like it are in Scorecard 001 (PDF) — the "quantum safe" claim graded in the open, free.

FAQ
What materials are required?

The vendor claim, deck, white paper, or NISQ result — whatever the claim is based on. If materials are confidential, do not email them. The intake form collects a description; a one-time secure upload link is sent after the conflict check.

Will Firebringer contact the vendor?

No, unless the client specifically requests and consents to it. The review is conducted on the materials provided and on publicly available information.

Is the report confidential?

Yes, by default. Reports are confidential to the client. They may not be submitted to regulators or used as a compliance filing. If the client wants to publish findings (anonymized or attributed), that requires written agreement.

Can the board memo be shared?

Yes — within the client organization. The board memo is written for internal use and may be circulated to any board, committee, or executive team within the commissioning organization. External publication requires written agreement.

What happens if the evidence is incomplete?

The report states what was available and what its limits are. A verdict of "cannot assess — insufficient evidence" is a valid finding and, in some cases, is itself the answer the client needs.

What does a broader PoC review cost?

A PoC or Measurement Integrity Review — for teams running NISQ experiments who need a full methodological review rather than a single claim verdict — is scoped individually. Submit intake and describe the experiment; we'll advise on scope and pricing.