vendor · quantum risk
Evidence levels | Quantum-Safe Claims & Education
Verdict
This site rates claim evidence as unknown, partial, documented, or audited. Marketing alone is never “audited.” Use levels to compare products honestly.
Overview
Wave 5 introduced evidence_level on vendor pages. Wave 7i applies the same scale to product categories and stacks.
unknown = insufficient public detail; partial = some public algorithms/docs; documented = clear public design; audited = third-party review of relevant scope (rare, verify date/scope).
Cryptographic profile
- Signatures: N/A — evaluation framework
- Hash: N/A
- Public-key exposure: Mis-rated evidence creates false residual risk acceptance.
Claim scrutiny (buyer checklist)
Marketing / stated claims
- Independently audited quantum-safe
Open questions
- What fraction of “quantum-safe” pages cite a scoped audit?
Educational analysis only. Verify primary sources, specs, and audits yourself before any financial or procurement decision.
What breaks
- Treating blog posts as audits
- Expired audit scopes
- Audits of classical crypto sold as PQC proof
Mitigations
- Read audit engagement letters and versions
- Map audit scope to your threat model
- Keep evidence_level conservative when unsure
FAQ
Does audited mean quantum-proof?
No. It means a defined review happened—still check algorithms and residual risk.
Related?
/is-quantum-proof/quantum-safe-blockchain-claims
Key concepts (technical dictionary)
Terms used on this page — open a definition: