QVAPT Assessment Methodology
We assess what is taking money today, and what will take it in 2030.
QVAPT (Quantum-VAPT) is Aurigraph DLT Corp's assessment platform for web/API, blockchain and DLT, smart contracts, wallets and custody, and post-quantum cryptography. Every engagement runs on NIST SP 800-115 (Planning → Discovery → Attack-in-lab → Reporting), closes on a deterministic score with no AI in the scoring path, and produces independently verifiable, hash-anchored results.
Six-module assessment scope
Scope is organised around the six failure classes that actually moved money in H1 2026, not a generic control checklist. Each module targets a distinct loss class and closes on a deterministic, on-ledger-anchored score. Module 1 (signer & key custody) is the MVP and ships in every engagement.
M1 — Signer & key-custody topology (MVP)
Assesses who can authorise value movement: signer count and quorum, hardware vs hot-key split, rotation age, and approval-flow social-engineering resistance. Compromised keys drove the single largest share of recent losses, and no audit helps when the attacker holds the key.
M2 — Bridge & cross-chain trust-path
Counts the independent verifiers on each bridge path and flags single-verifier designs as critical — one compromised attestation is total loss regardless of failure mode.
M3 — Emerging trust boundaries
A named test suite for the seams that sat outside 2025 audit scope: EIP-7702 wallet delegation, AI-agent signing authority, and off-chain prover / ZK boundaries.
M4 — Legacy & deprecated-code sweep
Finds live-but-sunset contracts still holding funds after monitoring was dropped — the cheapest high-signal finding in an engagement.
M5 — Crypto inventory, CBOM & quantum exposure
The post-quantum horizon: algorithm inventory (CBOM), quantum-vulnerable and broken-crypto grading, FIPS 203/204/205 conformance, and SLH-DSA posture. Delivered by the Q1–Q12 engine.
M6 — Detection-to-containment latency
Tracks how fast an incident is caught as a continuous posture signal, not a point-in-time PDF.
Quantum engine — twelve test cases (Q1–Q12)
The quantum-cryptography engine runs twelve cases and rolls them into one readiness grade. Five are critical — a FAIL on any caps the grade at F, because a broken root of trust cannot be graded readable.
| ID | Case | Critical |
|---|---|---|
| Q1 | Algorithm / parameter conformance | — |
| Q2 | Implementation authenticity | critical |
| Q3 | RNG / entropy quality | critical |
| Q4 | Key lifecycle | — |
| Q5 | KMS non-PQC fallback | — |
| Q6 | Signature verification robustness | critical |
| Q7 | Consensus signature integrity | critical |
| Q8 | Key-material exposure | critical |
| Q9 | Transport & hybrid negotiation | — |
| Q10 | HNDL & crypto-agility | — |
| Q11 | Custody | — |
| Q12 | Timing side-channel | — |
Deterministic scoring
Every module ends in a score computed from countable inputs by a fixed rubric — no AI decides a grade or a gate, and the same inputs produce the same score on every run. CBOM posture grades crypto A (quantum-safe) / B (monitor) / F (Shor-broken) / X (already broken); a critical-case FAIL caps the quantum readiness grade at F.
Independently verifiable, hash-anchored results
A conventional pentest report asks you to trust the vendor. QVAPT results are evidence: each run
captures a redacted transcript, signs its canonical digest with an Ed25519 key,
and links it into an append-only hash chain. Published artifacts carry a
hash-anchor manifest (per-file SHA-256 → Merkle root → signature → prior-root
chaining) that anyone can verify against the platform's pinned public key
(GET /api/attestation/pubkey) — without trusting QVAPT.