Skip to content
Theos Quantum Θ mark
Standards & compliance

How to read a Posture Attestation

The reference format, what each field asserts, the five readings that are wrong, and how to check a reference at Attestation Lookup.

Reviewed 27 Jul 2026 5 min read
On this page — 6 sections

A Posture Attestation is the signed record that a named scope was assessed on a named date under a named version of a published method. That is the entire claim. It is deliberately narrow, because a narrow claim can be checked and a broad one cannot. This article covers the reference format, what each field asserts, what the document refuses to say, and how a recipient checks one.

The reference format

Every attestation carries a reference in one fixed shape, printed on the document itself.

text
TQ-PA-YYYY-XXXXXX
│  │  │    └── XXXXXX   six uppercase letters or digits
│  │  └─────── YYYY     four-digit issue year
│  └────────── PA       Posture Attestation
└───────────── TQ       Theos Quantum

The lookup at Attestation Lookup trims surrounding whitespace and upper-cases what you type, so a reference pasted out of an email with a trailing space still checks. Nothing else about it is forgiving. The segments are fixed, and a reference of the wrong shape is reported as malformed rather than guessed at. One published reference, TQ-PA-0000-ILLUSTRATIVE, is a demonstration record rather than an issued one; its year segment is 0000 so it cannot be mistaken for a real reference, and it exists so a reader can see the shape of a populated result without us inventing a customer.

What each field asserts

The full annotated record is published field by field on Attestation Lookup. The table below is the reading order that matters when somebody hands you one and asks what it proves.

FieldWhat it asserts
referenceThe identifier above. It names the record. On its own it does not prove the record exists.
issuerTheos Quantum Technologies Private Limited. No accreditation body is involved at any point.
subject_organisation and assessed_scopeThe organisation, and the specific scope that was assessed. Anything outside that scope is not covered and is not implied to be safe by its absence.
method_versionThe published rules that produced the score, such as theos-method-v1.0. Two attestations issued under different versions are not directly comparable.
assessment_dateThe day the scope was assessed. The claim is about that day. It is not a statement about today.
estate_exposure_score and estate_exposure_tierThe scored result for that scope on that date. How each is constructed is published: see how the exposure score is built and what the risk tiers mean.
expiresThe date after which the record stops speaking to the estate's current state. An expired attestation does not become invalid retroactively.
evidence_ledger_digest and signatureTwo separate seals. The digest gives tamper evidence against the Evidence Ledger entry. The signature shows the record came from the issuer and was not altered in transit.
Field names as published on Attestation Lookup, in reading order.

The five readings that are wrong

A Posture Attestation is easy to over-read, particularly by a reader who was hoping for a certificate.

  • Not a certification. No accreditation body issued it. It is not SOC 2, not ISO 27001, and not any third-party compliance certification.
  • Not an audit opinion. No auditor examined controls against an audit standard and formed an opinion. It is a scoring output, not an assurance engagement.
  • Not a warranty. It records exposure as scored on the issue date under a stated method version. It says nothing about attacks not yet known and promises nothing about the future.
  • Not confirmation that remediation happened. It records what was found, not what was fixed. A lower score after remediation needs a new assessment, not an amendment to the old one.
  • Not a statement about anything out of scope. Assets that were never inventoried are not covered, not mentioned, and not implied to be safe.

Out of scope

A Posture Attestation is not a certification, not an audit opinion and not a warranty. We are not an audit firm, and no output of an engagement certifies your position to a regulator or to a customer. A digest match proves only that the record is intact: it does not prove the assessment was accurate, that the estate has not changed since the assessment date, or that the organisation still matches the scored scope. If your assessor is asking for accreditation, the honest answer is that we do not issue it and cannot. What we can give them is the scope, the date, the method version, and a hashed Evidence Pack they can check for themselves.

How to check one you have been sent

  1. 1

    Take the reference from the document

    Not from the covering email. References are exact strings, and a transcription error is the most common reason a check fails.

  2. 2

    Check the format at Attestation Lookup

    Enter it at Attestation Lookup. The tool reports one of three outcomes: well-formed, malformed, or the published illustrative example.

  3. 3

    Read what a well-formed result does not say

    A well-formed reference matches the published shape and nothing more. It is not a claim that the reference corresponds to a real, current attestation, and the tool will never render a verified badge it cannot support.

  4. 4

    Request manual verification

    There is no live registry yet, and the lookup endpoint is [PLACEHOLDER: verification endpoint — not yet published]. Until it ships, ask through our contact page and we will confirm in writing whether a specific reference is genuine.

  5. 5

    Compare the seals, if you hold what is needed to compare them against

    Recomputing the evidence digest and comparing it with the Evidence Ledger entry shows the document has not been altered since it was sealed. A single changed byte gives a different digest. The signature algorithm and the way the issuer public key is distributed are not yet finalised, and we would rather say so than name one that is not implemented.

Re-issue, expiry and revocation

An attestation is pinned to the method version that was active when it was issued. When the method is superseded, existing attestations are not rewritten to the new scoring. The estate is re-assessed and a new attestation is issued with its own reference and digest, and the old record still describes exactly what it always described. A revoked attestation is not deleted or hidden either: a lookup against its reference continues to show the record, marked as revoked, with the date of revocation. The full policy is in how the method is versioned and on The Theos Method.

Which engagements issue one

Five of the six engagements in the catalogue list a Posture Attestation among their artefacts. The Executive Briefing does not, because it reads an exposure position rather than establishing one; it produces a Board Summary and a Decision Record instead. Which artefacts a given engagement produces is listed on its own page, and that list is the one to check.

Check a reference format, and read the annotated record field by field.Attestation Lookup