QVAPT — Quantum-Ready VAPT · qvapt.com

QVAPT Assessment Methodology

We assess what is taking money today, and what will take it in 2030.

QVAPT (Quantum-VAPT) is Aurigraph DLT Corp's assessment platform for web/API, blockchain and DLT, smart contracts, wallets and custody, and post-quantum cryptography. Every engagement runs on NIST SP 800-115 (Planning → Discovery → Attack-in-lab → Reporting), closes on a deterministic score with no AI in the scoring path, and produces independently verifiable, hash-anchored results.

Six-module assessment scope

Scope is organised around the six failure classes that actually moved money in H1 2026, not a generic control checklist. Each module targets a distinct loss class and closes on a deterministic, on-ledger-anchored score. Module 1 (signer & key custody) is the MVP and ships in every engagement.

M1 — Signer & key-custody topology (MVP)

Assesses who can authorise value movement: signer count and quorum, hardware vs hot-key split, rotation age, and approval-flow social-engineering resistance. Compromised keys drove the single largest share of recent losses, and no audit helps when the attacker holds the key.

M2 — Bridge & cross-chain trust-path

Counts the independent verifiers on each bridge path and flags single-verifier designs as critical — one compromised attestation is total loss regardless of failure mode.

M3 — Emerging trust boundaries

A named test suite for the seams that sat outside 2025 audit scope: EIP-7702 wallet delegation, AI-agent signing authority, and off-chain prover / ZK boundaries.

M4 — Legacy & deprecated-code sweep

Finds live-but-sunset contracts still holding funds after monitoring was dropped — the cheapest high-signal finding in an engagement.

M5 — Crypto inventory, CBOM & quantum exposure

The post-quantum horizon: algorithm inventory (CBOM), quantum-vulnerable and broken-crypto grading, FIPS 203/204/205 conformance, and SLH-DSA posture. Delivered by the Q1–Q12 engine.

M6 — Detection-to-containment latency

Tracks how fast an incident is caught as a continuous posture signal, not a point-in-time PDF.

Quantum engine — twelve test cases (Q1–Q12)

The quantum-cryptography engine runs twelve cases and rolls them into one readiness grade. Five are critical — a FAIL on any caps the grade at F, because a broken root of trust cannot be graded readable.

IDCaseCritical
Q1Algorithm / parameter conformance
Q2Implementation authenticitycritical
Q3RNG / entropy qualitycritical
Q4Key lifecycle
Q5KMS non-PQC fallback
Q6Signature verification robustnesscritical
Q7Consensus signature integritycritical
Q8Key-material exposurecritical
Q9Transport & hybrid negotiation
Q10HNDL & crypto-agility
Q11Custody
Q12Timing side-channel

Deterministic scoring

Every module ends in a score computed from countable inputs by a fixed rubric — no AI decides a grade or a gate, and the same inputs produce the same score on every run. CBOM posture grades crypto A (quantum-safe) / B (monitor) / F (Shor-broken) / X (already broken); a critical-case FAIL caps the quantum readiness grade at F.

Independently verifiable, hash-anchored results

A conventional pentest report asks you to trust the vendor. QVAPT results are evidence: each run captures a redacted transcript, signs its canonical digest with an Ed25519 key, and links it into an append-only hash chain. Published artifacts carry a hash-anchor manifest (per-file SHA-256 → Merkle root → signature → prior-root chaining) that anyone can verify against the platform's pinned public key (GET /api/attestation/pubkey) — without trusting QVAPT.