For boards, CISOs, CTOs, investors, and vendor-risk teams. Send one vendor claim, deck, white paper, NISQ result, or board question. Six deliverables. One verdict on paper — attach it to the vendor file, the investment memo, or the board pack.
$5,000 fixed scope · 10 business days · Limited to 3 concurrent engagements
Intake only — do not email confidential materials. Secure upload provided after conflict check.
Vendor due diligence — a claim in a pitch, RFP, or contract. PoC result review — a team returned a quantum result and you need to know if it's real. Board claim verification — a memo that depends on a quantum milestone or a "quantum safe" assertion. Investment or partnership diligence — one technical claim at the center of a decision. Pre-publication adversarial review — before quantum research is cited in decisions.
Formal regulatory certification or compliance filing. Legal or investment advice. Penetration testing. Full PQC migration planning or implementation. Review of multiple independent claims in one engagement — each additional claim is a separate scope. Unlimited vendor portfolio review.
What counts as "one claim"? One vendor assertion, one milestone interpretation, or one connected PoC result with a defined decision attached. If you're not sure, submit intake and we'll advise on scope.
Ask: "What exactly did the hardware demonstration validate — implementation behavior, interoperability, or cryptanalytic resistance?"
A vendor who ran an interoperability test on a classical library has a defensible answer. A vendor who claims the demo validated quantum resistance is revealing either a misunderstanding of current hardware capability (today's NISQ machines cannot break RSA-2048 or ECC-256, so they cannot meaningfully "fail to break" a PQC scheme) or a willingness to sell theater. Either answer belongs in the vendor file.
Nine more questions like it are in Scorecard 001 (PDF) — the "quantum safe" claim graded in the open, free.
The vendor claim, deck, white paper, or NISQ result — whatever the claim is based on. If materials are confidential, do not email them. The intake form collects a description; a one-time secure upload link is sent after the conflict check.
No, unless the client specifically requests and consents to it. The review is conducted on the materials provided and on publicly available information.
Yes, by default. Reports are confidential to the client. They may not be submitted to regulators or used as a compliance filing. If the client wants to publish findings (anonymized or attributed), that requires written agreement.
Yes — within the client organization. The board memo is written for internal use and may be circulated to any board, committee, or executive team within the commissioning organization. External publication requires written agreement.
The report states what was available and what its limits are. A verdict of "cannot assess — insufficient evidence" is a valid finding and, in some cases, is itself the answer the client needs.
A PoC or Measurement Integrity Review — for teams running NISQ experiments who need a full methodological review rather than a single claim verdict — is scoped individually. Submit intake and describe the experiment; we'll advise on scope and pricing.