TechEntangleGet in touch

Every claim, with its source.

Security marketing runs on numbers nobody can check. This is all of ours — 23 claims, each with where it came from and what kind of claim it is. If a figure appears anywhere on this site, it appears here.

What the labels mean

Third-party, published
Somebody else’s research, named where it appears, with the year. You can go and read it.
Measured by us
Our own run, with the conditions stated — how many files, how many participants, on what date.
Projected, not measured
An extrapolation from something we measured. Stated as a projection, never as a measurement.
Product behaviour
What the product does, which you can check by using it. Not a claim about performance.
Anticipated, not in force
Expected but not yet in force. Stated as expected, never as a requirement.

The register

23 claims. Generated from the same content the product pages render, so it cannot fall behind them.
ClaimSourceStatusWhere
2m 33s — to inventory the cryptography in 5,255 source filesOur own timed scan of hashicorp/vault, 5,255 source filesMeasured by us0dq — Post-quantum readiness
NIST published ML-KEM, ML-DSA and SLH-DSA in August 2024. What to migrate to is no longer an open question — only what to migrate, and in what order.NISTThird-party, published0dq — Post-quantum readiness
Cryptography and key management are already named control domains under the CBUAE Information Security Regulation and Operational Risk Standard.CBUAEThird-party, published0dq — Post-quantum readiness
Six pillars, weighted into one score: quantum readiness 30%, code 18%, dependencies 17%, secrets 13%, infrastructure 12%, licences 10%.0dq scoring modelProduct behaviour0dq — Post-quantum readiness
Static analysis runs 2,452 rules across OWASP Top Ten and CWE Top 25. Secrets are found in commit history, not only the working tree.0dq scannerProduct behaviour0dq — Post-quantum readiness
Every finding carries a reachability verdict — called, not called, dead code, dev only — so the queue is ordered by what can run, not by severity alone.0dq findings viewProduct behaviour0dq — Post-quantum readiness
Runs in the browser, on the command line, as a pipeline gate, and as a pre-commit hook that stops a credential locally in under a second.0dq surfacesProduct behaviour0dq — Post-quantum readiness
100% — completion at 50 concurrent participants, against productionOur own load testing, 16 November 2025Measured by usAegix — Resilience assurance
Designed for 100–150 participants. An extrapolation from the 50-participant run, not a measured figure.Our own load testing notes, extrapolated from the 16 November 2025 runProjected, not measuredAegix — Resilience assurance
A full scenario is generated in usually two to five minutes.Stated on the Aegix generation screenProduct behaviourAegix — Resilience assurance
Participants join by QR code. No app, no login.The Aegix participant join flowProduct behaviourAegix — Resilience assurance
Each session generates an incident response playbook: role assignments, escalation paths, timelines, and communication templates for internal, external and regulatory audiences.Aegix playbook generatorProduct behaviourAegix — Resilience assurance
Findings are mapped to NIST SP 800-61, ISO 27035 and SANS for the response plan, and to NIST CSF, DORA, ISO 22301 and CBUAE for the compliance record.Aegix framework mappingProduct behaviourAegix — Resilience assurance
RX9 is pre-release. The driver, agent and dashboard are built and working end to end. Not generally available until the kernel-mode signing certificate is issued.Us — falsifiable by trying to buy itProduct behaviourRX9 — Ransomware defence
8× — the recovery bill when the backups went down with everything else — $3m against $375,000Sophos, State of Ransomware 2025Third-party, publishedRX9 — Ransomware defence
Attackers went after the backups of 94% of ransomware victims, and succeeded against more than half.Sophos, State of Ransomware 2025Third-party, publishedRX9 — Ransomware defence
Median time from initial access to the domain controller: 3.4 hours.Sophos, Active Adversary Report 2026Third-party, publishedRX9 — Ransomware defence
85–98 — where every established asset scores, so a single threshold flags all of them or noneCipherScan scoring across six categories, sourced from CertiKMeasured by usCipherScan — Portfolio surveillance
No custody, no wallet connection, no keys, no signatures, and no holdings recorded. Analysis only.CipherScan product behaviourProduct behaviourCipherScan — Portfolio surveillance
One alert per condition, held open while it persists — rather than one per evaluation. An inbox you still read in month six.CipherScan alerting behaviourProduct behaviourCipherScan — Portfolio surveillance
A listing decision record states the evidence as at the listing date, and labels its own basis: a snapshot recorded at the time, a reconstruction from surviving data, or unavailable. The three are never presented as one.CipherScan listing decisionsProduct behaviourCipherScan — Portfolio surveillance
UAE authorities are widely expected to require a post-quantum migration roadmap. They have not yet.Industry expectation; no published CBUAE requirementAnticipated, not in forceHow we write about our products
TechEntangle sells products and not consulting.Us — and falsifiable by askingProduct behaviourWho we are

What is not here

No customer names, no logos, no testimonials, no “trusted by” count. Not because we have nothing to say about the people who use these products, but because we have nothing about them we can source, and a register that skips the claims it cannot support is not a register.

No figure for anything we have not measured. The Aegix one-pager quotes “10–500+ participants” — an interpolated capacity ceiling, extrapolated from a run on smaller hardware. This site states the measured number instead: 50 concurrent, proven, with 100–150 projected.

Both are defensible; they answer different questions. A ceiling tells you what the software could take, and in practice nobody runs a tabletop exercise with five hundred people. What we measured tells you what has actually been done, which is the number that survives a procurement conversation.

Nothing about post-quantum cryptography being mandated today. It is not. UAE authorities are widely expected to require a migration roadmap, and that expectation is in the register above, labelled as an expectation.