Discovery depth
Qtangl native discovery depth — host sensor + code/binary orchestration
Qtangl now ships partial native host, code, and binary discovery into the same CBOM merge and signed evidence pipeline — with honest partial scoring until enterprise ship gates clear.
Qtangl now ships partial native discovery depth per ADR-009:
- Host / endpoint — Qtangl Unified Sensor (cert stores, crypto libraries, TLS listeners) with fleet enrollment
- Source code / binary — CryptoScan, CryptoDeps, and CBOMkit-theia orchestration into the same CBOM merge and signed evidence pipeline
Why partial, not "yes" yet
Enterprise ship gates G3/G5 require 500+ agent pilots, mTLS agent identity, bundled OSS engines in CI, and production registry connectors. We label capabilities partial on the vendor comparison matrix until those gates clear.
What you can do today
- Enable
discovery.hostSensor,discovery.codeScan, anddiscovery.binaryScanper tenant (orQTANGL_DISCOVERY_ENABLE_ALL=truein dev) - Dashboard → Integrations → Discovery depth — hosts, code, images tabs with inventory counts
- Assess wizard → Discovery scope — external baseline plus optional fleet/repos/images
- GitHub Action
qtangl-scanwithmode: code|binary|external
Evidence layer unchanged
Discovery depth expands inventory; the moat remains signed, publicly verifiable evidence — the Readiness Passport auditors can check offline.
See deployment guides: host sensor deploy, code scan CI, and the enterprise pilot playbook in product docs.
Continue on the Q-Day hub: Vendor comparison hub
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- NIST IR 8547: Transition to Post-Quantum Cryptography StandardsNIST · 2024Federal transition guidance with deprecation timelines for quantum-vulnerable algorithms.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.