Skip to content

Discovery depth

Qtangl native discovery depth — host sensor + code/binary orchestration

Qtangl now ships partial native host, code, and binary discovery into the same CBOM merge and signed evidence pipeline — with honest partial scoring until enterprise ship gates clear.

Qtangl discovery depth expansion diagram.

Qtangl now ships partial native discovery depth per ADR-009:

  • Host / endpoint — Qtangl Unified Sensor (cert stores, crypto libraries, TLS listeners) with fleet enrollment
  • Source code / binary — CryptoScan, CryptoDeps, and CBOMkit-theia orchestration into the same CBOM merge and signed evidence pipeline

Why partial, not "yes" yet

Enterprise ship gates G3/G5 require 500+ agent pilots, mTLS agent identity, bundled OSS engines in CI, and production registry connectors. We label capabilities partial on the vendor comparison matrix until those gates clear.

What you can do today

  1. Enable discovery.hostSensor, discovery.codeScan, and discovery.binaryScan per tenant (or QTANGL_DISCOVERY_ENABLE_ALL=true in dev)
  2. Dashboard → Integrations → Discovery depth — hosts, code, images tabs with inventory counts
  3. Assess wizard → Discovery scope — external baseline plus optional fleet/repos/images
  4. GitHub Action qtangl-scan with mode: code|binary|external

Evidence layer unchanged

Discovery depth expands inventory; the moat remains signed, publicly verifiable evidence — the Readiness Passport auditors can check offline.

See deployment guides: host sensor deploy, code scan CI, and the enterprise pilot playbook in product docs.

Continue on the Q-Day hub: Vendor comparison hub

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.