Skip to main content

What is qtrace?

qtrace is a cryptographic bill of materials scanner for repositories.

It scans the code where it already lives and identifies cryptographic assets across the repository. It then classifies those assets according to their quantum vulnerability and provides information about where they were found.

What qtrace provides​

qtrace provides:

  • Cryptographic asset discovery
  • Quantum risk classification
  • File and line information
  • Confidence information
  • Risk scoring
  • Remediation guidance
  • Migration guidance
  • Reports in multiple formats
  • Gaps where an asset could not be read or classified

How qtrace works​

When you run a scan, qtrace examines the repository and collects cryptographic information from:

  • Manifest and lock files
  • Cryptographic artifacts
  • Configuration
  • Source code
  • Binaries

The detected information is combined into scan findings and evaluated for risk.

Quantum risk classification​

qtrace classifies cryptographic assets using risk classes including:

  • shor-broken
  • grover-weakened
  • unknown
  • pqc-safe
  • not-applicable

The risk classification is used together with confidence information to rank findings.

Findings​

A finding identifies a cryptographic asset and provides information such as:

  • Algorithm
  • File
  • Line
  • Risk classification
  • Confidence
  • Recommended action

qtrace reports gaps when it cannot read or classify something. A repository with no findings is different from a repository where something could not be read or classified.

Remediation and migration​

qtrace separates remediation from migration.

Remediation explains what is wrong with the detected algorithm and identifies the recommended destination.

Migration provides guidance based on what qtrace actually found, such as the library or source call site involved.

Migration recommendations can be either:

  • Product - a quant0 offering
  • Advisory - an action to perform yourself

Deterministic results​

The same repository tree produces the same output.

qtrace uses deterministic ordering, and the risk reference year comes from the knowledge base rather than the wall clock.

Re-running a scan against the same tree produces byte-identical output.

Scan outputs​

qtrace can produce:

  • HTML reports
  • CycloneDX 1.7
  • CycloneDX 1.6
  • SARIF
  • Terminal summaries

The HTML report includes:

  • Overview
  • Findings
  • Files
  • Migrate
  • Gaps
  • Provenance