What the labels mean
- Third-party, published
- Somebody else’s research, named where it appears, with the year. You can go and read it.
- Measured by us
- Our own run, with the conditions stated — how many files, how many participants, on what date.
- Projected, not measured
- An extrapolation from something we measured. Stated as a projection, never as a measurement.
- Product behaviour
- What the product does, which you can check by using it. Not a claim about performance.
- Anticipated, not in force
- Expected but not yet in force. Stated as expected, never as a requirement.
The register
| Claim | Source | Status | Where |
|---|---|---|---|
| 2m 33s — to inventory the cryptography in 5,255 source files | Our own timed scan of hashicorp/vault, 5,255 source files | Measured by us | 0dq — Post-quantum readiness |
| NIST published ML-KEM, ML-DSA and SLH-DSA in August 2024. What to migrate to is no longer an open question — only what to migrate, and in what order. | NIST | Third-party, published | 0dq — Post-quantum readiness |
| Cryptography and key management are already named control domains under the CBUAE Information Security Regulation and Operational Risk Standard. | CBUAE | Third-party, published | 0dq — Post-quantum readiness |
| Six pillars, weighted into one score: quantum readiness 30%, code 18%, dependencies 17%, secrets 13%, infrastructure 12%, licences 10%. | 0dq scoring model | Product behaviour | 0dq — Post-quantum readiness |
| Static analysis runs 2,452 rules across OWASP Top Ten and CWE Top 25. Secrets are found in commit history, not only the working tree. | 0dq scanner | Product behaviour | 0dq — Post-quantum readiness |
| Every finding carries a reachability verdict — called, not called, dead code, dev only — so the queue is ordered by what can run, not by severity alone. | 0dq findings view | Product behaviour | 0dq — Post-quantum readiness |
| Runs in the browser, on the command line, as a pipeline gate, and as a pre-commit hook that stops a credential locally in under a second. | 0dq surfaces | Product behaviour | 0dq — Post-quantum readiness |
| 100% — completion at 50 concurrent participants, against production | Our own load testing, 16 November 2025 | Measured by us | Aegix — Resilience assurance |
| Designed for 100–150 participants. An extrapolation from the 50-participant run, not a measured figure. | Our own load testing notes, extrapolated from the 16 November 2025 run | Projected, not measured | Aegix — Resilience assurance |
| A full scenario is generated in usually two to five minutes. | Stated on the Aegix generation screen | Product behaviour | Aegix — Resilience assurance |
| Participants join by QR code. No app, no login. | The Aegix participant join flow | Product behaviour | Aegix — Resilience assurance |
| Each session generates an incident response playbook: role assignments, escalation paths, timelines, and communication templates for internal, external and regulatory audiences. | Aegix playbook generator | Product behaviour | Aegix — Resilience assurance |
| Findings are mapped to NIST SP 800-61, ISO 27035 and SANS for the response plan, and to NIST CSF, DORA, ISO 22301 and CBUAE for the compliance record. | Aegix framework mapping | Product behaviour | Aegix — Resilience assurance |
| RX9 is pre-release. The driver, agent and dashboard are built and working end to end. Not generally available until the kernel-mode signing certificate is issued. | Us — falsifiable by trying to buy it | Product behaviour | RX9 — Ransomware defence |
| 8× — the recovery bill when the backups went down with everything else — $3m against $375,000 | Sophos, State of Ransomware 2025 | Third-party, published | RX9 — Ransomware defence |
| Attackers went after the backups of 94% of ransomware victims, and succeeded against more than half. | Sophos, State of Ransomware 2025 | Third-party, published | RX9 — Ransomware defence |
| Median time from initial access to the domain controller: 3.4 hours. | Sophos, Active Adversary Report 2026 | Third-party, published | RX9 — Ransomware defence |
| 85–98 — where every established asset scores, so a single threshold flags all of them or none | CipherScan scoring across six categories, sourced from CertiK | Measured by us | CipherScan — Portfolio surveillance |
| No custody, no wallet connection, no keys, no signatures, and no holdings recorded. Analysis only. | CipherScan product behaviour | Product behaviour | CipherScan — Portfolio surveillance |
| One alert per condition, held open while it persists — rather than one per evaluation. An inbox you still read in month six. | CipherScan alerting behaviour | Product behaviour | CipherScan — Portfolio surveillance |
| A listing decision record states the evidence as at the listing date, and labels its own basis: a snapshot recorded at the time, a reconstruction from surviving data, or unavailable. The three are never presented as one. | CipherScan listing decisions | Product behaviour | CipherScan — Portfolio surveillance |
| UAE authorities are widely expected to require a post-quantum migration roadmap. They have not yet. | Industry expectation; no published CBUAE requirement | Anticipated, not in force | How we write about our products |
| TechEntangle sells products and not consulting. | Us — and falsifiable by asking | Product behaviour | Who we are |
What is not here
No customer names, no logos, no testimonials, no “trusted by” count. Not because we have nothing to say about the people who use these products, but because we have nothing about them we can source, and a register that skips the claims it cannot support is not a register.
No figure for anything we have not measured. The Aegix one-pager quotes “10–500+ participants” — an interpolated capacity ceiling, extrapolated from a run on smaller hardware. This site states the measured number instead: 50 concurrent, proven, with 100–150 projected.
Both are defensible; they answer different questions. A ceiling tells you what the software could take, and in practice nobody runs a tabletop exercise with five hundred people. What we measured tells you what has actually been done, which is the number that survives a procurement conversation.
Nothing about post-quantum cryptography being mandated today. It is not. UAE authorities are widely expected to require a migration roadmap, and that expectation is in the register above, labelled as an expectation.