Attestation Lookup · Specimen
The specimen attestation.
This page renders the full record template a real engagement ends with — every field, the badge, and the digest — populated with the same illustrative values the lookup page uses. It exists so a customer, an auditor or a regulator can see exactly what they would receive before any engagement is signed. It is a specimen: it attests nothing, about anyone.
Posture Attestation
TQ-PA-0000-ILLUSTRATIVE
- reference
- TQ-PA-0000-ILLUSTRATIVE
- issuer
- Theos Quantum Technologies Private Limited
- subject_organisation
- [PLACEHOLDER: illustrative — not a real customer]
- assessed_scope
- [PLACEHOLDER: illustrative — e.g. “Payments platform, EU region”]
- method_version
- theos-method-v1.0
- assessment_date
- 2026-07-27 (illustrative)
- expires
- 2027-07-27 (illustrative)
- asset_count
- 128 (illustrative)
- estate_exposure_score
- 58 / 100 (illustrative)
- estate_exposure_tier
- Watch (illustrative)
A real attestation carries this exact structure with a real reference, a named organisation, a dated scope and a genuine signature. The score and tier follow the published construction — see how the exposure score is built and the Theos Method.
The attested surfaces
Seven lines a reader checks first
The middle of the document is a table: surface by surface, what the assessment found in place at the assessment date. On the specimen, the values are the illustrative estate's.
- Key establishment
- X25519 + ML-KEM-768 · hybrid
- Primary signature
- ML-DSA-65 · FIPS 204
- Co-signature
- SLH-DSA-128s · FIPS 205
- Transport suite
- TLS 1.3 · AES-256-GCM
- Key custody
- Managed KMS · post-quantum key types
- Code signing
- Dual-signed · classical + ML-DSA-65
- Estate position
- 58 / 100 — Watch · theos-method-v1.0
What the underlying record shows
- Customer-facing transport terminators negotiate the hybrid establishment group by default.
- The release pipeline signs twice — classical and ML-DSA-65 — with the provenance of each artefact recorded.
- The conservative co-signature is attached to every artefact the stated method version covers.
- No verifier in scope accepts a classical-only artefact except the dated exceptions the register names.
- Handshake cost is measured against the estate's own classical baseline, not a vendor benchmark.
- The rollback path is rehearsed and timed before any cutover, and the rehearsal date is recorded.
On a real attestation each line carries the estate's own measurements. The specimen states the shape and invents no numbers.
The digest
One hash, honestly earned
This digest is computed from the specimen record above — the ten fields, in order, one per line as key=value — at the moment this page is built. Recompute it yourself and it will match. It anchors nothing anywhere else, which is exactly what a specimen's hash should do.
sha-256 · of the record block above
0c25ed43c55e4215a16b67ce820476a3bd0fc010b93e8d6f492314ad825524a7
Fingerprint · 0c·25·ed·43·c5·5e·42·15
The badge
Embeddable, in three sizes and two surfaces
A real attestation ships with a badge that links to its live lookup entry. The specimen badge links here, and says what it is in the artwork itself — so it cannot be mistaken for a claim even when it travels.
Light surface · 160 / 260 / 380 wide
Dark surface · same sizes
<a href="https://www.theosquantum.com/attest/specimen">
<img
src="https://www.theosquantum.com/attest/specimen-badge-light.svg"
alt="Posture Attestation — specimen"
width="260" height="72"
/>
</a>
<!-- dark surfaces: specimen-badge-dark.svg · sizes: set width 160 / 260 / 380 -->Holding a real one?
Check a real reference, or scope the work that earns one
Every engagement in the catalogue ends with an attestation on this template. If someone has handed you a reference, the lookup page checks its format; if you want your estate to have one, the conversation starts with a consult.