Skip to content
Theos Quantum TQ globe markTHEOS QUANTUM

Signal Log

This replaces a conventional changelog. Every entry below is either verifiable inside this codebase — an article count, a method-version date — or a genuinely public standards fact. Nothing here is a roadmap item presented as shipped, and nothing is back-dated to manufacture a longer history than we have.

The record

What changed, and when.

This log begins on the date we started keeping it: 27 July 2026. Anything earlier appears only where it is a genuinely public fact — a standard being finalised, a regulation taking effect — cited for context, not presented as something we tracked in real time.

  1. 25 Sep 2026Site

    Discovery scope and exports

    Website updated: discovery pages list six source languages and dependency manifests (still in development); export formats stated (CycloneDX 1.7, HTML, SARIF); SPDX roadmap wording made specific; on-premises and customer-cloud operation stated; synthetic figures removed from the home page. Method data as of the 0.2.0.dev6 pre-release: detection catalogue 2026.09.39, classification table 2026.09.9, identity rules 5, cryptography-library list 2026.09.4 — every change is recorded in the method changelog that ships with the tool.

  2. 15 Sep 2026Site

    Published: Bitcoin quantum-exposure measurement

    Published: Bitcoin quantum-exposure measurement as of block 959,193, with method, independent comparison, supply-bound check and the dataset defect found in the process.

  3. 8 Sep 2026Site

    Home page: synthetic figures withdrawn

    Home page: synthetic reference-estate figures withdrawn from the home page (they remain on the Methodology page as a labelled worked example); capability wording aligned to Discovery v1 scope.

  4. 7 Sep 2026Site

    Batch A verified live; two refinements applied

    A verification pass against the live site confirmed every Batch A change of 7 September already published — a same-evening check that reported items missing had read a cached copy of the pages. Two refinements from that review were applied: the export-API note on the CBOM page was tightened, and the discovery surface-family table now carries a dedicated Status column with a one-line legend in place of inline labels. Follow-up: first-mention labels on /how-it-works and /methodology; Stage 1 wording corrected.

  5. 7 Sep 2026Site

    Capability labels and reference-estate labelling applied

    A website change brief from the product's technical architect was applied across the site. The SPDX export claim was removed — SPDX 3.0.1 has no cryptographic-asset model, so the export is now labelled announced, pending a standard CBOM profile. The eight discovery surface families now carry build-status labels (Shipping / Pilot / In development / Announced). The reference-estate figures are labelled illustrative — synthetic reference estate, not customer data — wherever they appear, and the model-accuracy figures now name their synthetic evaluation set. The unmeasured manual-review time comparison was removed; a time claim returns only with a published measurement method. A data-handling commitment was added: discovery runs inside your environment, and source code is never transmitted to Theos.

  6. 14 Aug 2026Site

    The site goes permanently dark

    Light mode is retired. The site now renders in its dark palette for every visitor: the theme toggle is gone from the navigation, no theme preference is stored in the browser any more, and the system light/dark setting is no longer consulted. The Cookie Policy's storage table was corrected the same day — the theme-preference item it documented no longer exists, leaving the consent choice as the only thing this site writes to a visitor's browser.

  7. 14 Aug 2026Site

    Natural spacing everywhere — the typography question closes

    The August cosmetic review examined every page of this site, section by section, and reached one verdict twenty-nine times: justified body text stretches the gaps between words, and hyphenation splits words mid-line to serve it. Both are now gone. Every paragraph on the site is naturally spaced at every screen width, no text is hyphenated to fit a column, and no rule reintroduces either above any breakpoint. The three earlier typography entries below — the July justification pass, the 31 July return to natural spacing, and the 4 August desktop-only compromise — stand as written; this record does not rewrite them, it ends the sequence. Natural spacing is the standard.

  8. 4 Aug 2026Site

    Justified at desktop, natural on small screens — the typography rule settles

    Third and final movement of a direction that changed twice. Body paragraphs were justified in July's typography pass, returned to natural spacing on 31 July when narrow columns made the stretched word gaps visible, and are now justified again — this time only at desktop widths, where columns are wide enough that justification does not fight the words, while phones and small tablets keep natural left alignment. Alongside it, the five Resources pages gain a one-second cipher entrance: the heading resolves out of scrambled glyphs with a brief fall of cyan code behind the hero, once per visit, still afterwards. Both earlier typography entries below stand as written; this entry replaces neither.

  9. 29 Jul 2026Site

    The Signal Replay: the record, replayed on the globe

    Exposure Signals gains its centrepiece: the vetted advisory record — twelve real disclosures, ROCA 2017 through the 2024 PuTTY key-recovery flaw — replayed on a night-lights Earth in the order the world learned of each failure. Every pulse is a ledger row with a date, a source link and a stated seat rule (the vendor's campus, the maintainer's institution, or the cataloguer's), because advisories have no geography and we will not invent one. The page carries exactly one globe: the eleven named institutions from the directory below are drawn on it as steady white beacons. Play, pause and scrub; under reduced motion the record renders settled and Play still works. No countdown, no invented dots, no geolocation of the reader: a record, not a show.

  10. 29 Jul 2026Site

    The Help Desk states its boundary: what support confirms, withholds, and never guesses

    The Help Desk gains five sections from the assurance review: the twelve questions we answer most often, the five things that make a support reply faster, the plain two-column statement of what support can usually confirm and what it may withhold to protect customers, the four-team escalation path a request can travel, and the list of things support will never guess to close a ticket. Every answer states only what holds for every workspace; anything workspace-specific routes to a person instead of speculation.

  11. 29 Jul 2026Site

    A sitewide typography pass: bold labels, justified prose, two reflows

    A 34-section cosmetic QA review of the site's own pages, applied in one pass. Every sky-blue section label is now bold, applied through the three shared label styles so no page can disagree. Descriptive paragraphs — page ledes, section intros, step and card bodies — are fully justified with automatic hyphenation. The Quantum Window caption reflows to exactly three balanced lines, and the Discover → Map → Prioritize → Prove heading holds one line at every width. Verified at four widths across sixteen pages with zero horizontal overflow.

  12. 28 Jul 2026Site

    One Name publishes — the portfolio, declined

    A directory page in the shape a brand portfolio would use, with the argument inverted: five surfaces — the exposure score, the CBOM export, the public signals, the verification trail, the disclosure door — matched by function to what a portfolio would split into separate companies, every row live on this site today under one name. Reserved domains: none. Coming-soon badges: none. Tokens: none. The standing version of the stance lives on Our Position, whose signature block covers everything this name ships.

  13. 28 Jul 2026Site

    The CBOM gets its own page

    The cryptographic bill of materials — already an artefact of four engagements — gains a first-party page: the two export shapes (CycloneDX 1.6 with its crypto-asset model, SPDX 3.0.1) emitted from one scan pass, a specimen scorecard on the illustrative estate, a real-schema extract, and six standing facts. The first fact is a position: one name on the report, never white-label, because a register is a claim and a claim needs a claimant.

  14. 28 Jul 2026Site

    The consult form learns its sixth field

    The Book a consult form gains a Sector select drawn from the same ten sectors Sector Pulse publishes, so an enquiry arrives already placed. The panel also states its three header facts in the versions we can stand behind: no charge, read by a person, and a placeholder where a session length would go until that is a real commitment. Still no calendar widget and still no automated sequence — someone reads what you wrote and answers it.

  15. 28 Jul 2026Site

    Our Position gains its anchors, its colour note, and a signature block

    Three additions to /position. The dates the page anchors to — 2024 standards, the 2030 and 2035 gates — each owned and sourced by the Deadline Board, plus a deliberate fourth card: no countdown, because the recording problem started without one. A margin note explaining why the cyan is rationed to a tenth of any screen. And a signature block in which the page signs itself: a SHA-256 digest computed from the six clauses at build time, recomputable by any reader — the same honesty mechanism the specimen attestation uses.

  16. 28 Jul 2026Site

    How it works gains the engagement process and the signing design

    Three additions to /how-it-works. The engagement's four moves — first read, the letter, the work, the attestation — published as a timeline, with every time-box we cannot yet stand behind written as a placeholder rather than invented. The attestation's two-family signing design — ML-DSA-65 primary, SLH-DSA-128s co-signature — published with its verification rule stated plainly: both must verify, because a policy that accepts either alone behaves as a downgrade. And the final-artefact section, linking the specimen attestation and the public lookup.

  17. 28 Jul 2026Site

    The Delegated Access Transition Review joins the Transition category

    The catalogue's ninth engagement reads the delegation chain — issue, delegate, exercise, revoke — as four signed moments with their own transition states, drawn as a pipeline on the page. The failure it reads hardest is the fallback trap: a revocation or recovery path that cancels post-quantum authority with a bare classical signature. Seven surfaces, a six-artefact manifest, and the standing rule that the emergency path is held to the standard of the chain it bypasses.

  18. 28 Jul 2026Site

    Two Transition Reviews join the catalogue

    The catalogue grows from six engagements to eight with a new Transition category: the Dual-Signing Transition Review, which reads the dual classical-plus-post-quantum signature pair — its shape, binding, fallbacks, ordering and verifier parity — and the Key Custody Transition Review, which walks a half-moved custody stack with both clocks running: what to move next, and what the record already says. Both are full detail pages with their own panels, spec rows, manifests and questions, and both appear in the navigation, the coverage grid, the scope builder and search.

  19. 28 Jul 2026Site

    The Key Management Review gains its custody-stack section

    The review page now walks the enterprise key custody stack layer by layer — roots, wrapping at rest, distribution channels, escrow, ceremonies, short-lived material, recovery paths and the custody trail — stating what is typically classical at each layer today and the transition move the review plans for it. An illustrative ceremony-quorum figure and a SOC 2 distinction question join the page; vendor postures remain the Compatibility Reference's job, cited rather than restated.

  20. 28 Jul 2026Site

    The specimen attestation publishes, and dual-signing gets its own section

    Two additions. The Attestation Lookup gains a specimen page: the full Posture Attestation template rendered with the lookup page's own illustrative values, an embeddable badge that names itself a specimen in the artwork, and a SHA-256 digest genuinely computed from the specimen record at build time. And the Signing & Identity Review gains a dual-signing composition section — the published FIPS signature sizes drawn to scale, five named composition checks, and the public standards the vocabulary is stated against.

  21. 28 Jul 2026Site

    The Review Programme publishes

    The catalogue's three layer reviews — Transport & PKI, Signing & Identity, Key Management — are now offered as one combined programme: one engagement letter, one delivery window, one combined register, one Posture Attestation. The page states what combining the reviews changes in scope terms, and introduces nothing that was not already in the catalogue.

  22. 27 Jul 2026Method

    The Theos Method reaches v1.0

    theos-method-v1.0 is now the current, canonical scoring method, published in full at /methodology. It supersedes theos-method-v0.1, published two days earlier, which remains referenced only as a historical revision.

    • Method version identifier: theos-method-v1.0, published 2026-07-27
    • Five weighted dimensions — Primitive Fragility, Confidentiality Horizon, Reachability, Change Cost, Substitution Gap — plus the fragility-floor override
    • Four tiers: Acute, Elevated, Watch, Contained
  23. 27 Jul 2026Site

    This Signal Log begins

    This page publishes today, alongside the rest of the pages below. Going forward it records true, dated changes to the product, the method, the standards we track and this site — not aspirational roadmap items and not a running list of marketing announcements.

  24. 27 Jul 2026Site

    Knowledge Base and Lexicon published

    The Knowledge Base went live at /knowledge with 41 articles across nine categories, alongside the Lexicon at /knowledge/lexicon, a 164-term glossary of post-quantum and cryptographic-inventory vocabulary. Both are searchable through the site's ⌘K palette.

    • 41 articles across Start Here, Discovery, Risk & Scoring, Migration, Standards & Compliance, The Threat, Platform & Access, Data & Privacy, and The Theos Method
    • 164 terms in the Lexicon, cross-referenced to related terms and to the article that uses each one
  25. 27 Jul 2026Security

    Assurance Center and Attestation Lookup published

    Two trust-surface pages went live: the Assurance Center at /assurance, documenting our controls and posture in plain language, and Attestation Lookup at /attest, where a recipient of a Posture Attestation can verify the reference independently rather than trusting the copy they were sent.

  26. 27 Jul 2026Security

    Security & Disclosure policy published

    Our vulnerability disclosure policy went live at /security, setting out how to report a security concern about this site or the platform, and what happens to a report once we have it.

  27. 27 Jul 2026Site

    Help Desk published

    A task-shaped Help Desk went live at /help, answering how-do-I questions across setup, running an assessment, reading results, exporting and sharing, and account access — distinct from the Knowledge Base, which explains how the method works rather than how to operate the platform.

  28. 27 Jul 2026Site

    Sector Pulse published

    Sector Pulse went live at /pulse, a public feed of cryptography-relevant advisory and standards activity organised by sector.

  29. 27 Jul 2026Standards

    FIPS 206 (FN-DSA) remains unpublished

    As of today, NIST has not published FIPS 206, the planned standard for FN-DSA (FALCON). We record its status here rather than mapping any finding against a draft, and we will log the publication the day it happens rather than anticipate a date.

  30. 25 Jul 2026Method

    theos-method-v0.1 published

    An earlier revision of the scoring method, theos-method-v0.1, was published on this date. It has since been superseded by theos-method-v1.0 (above) and is kept only as a historical reference — it is never presented as current.

  31. 17 Jan 2025Standards

    EU DORA becomes applicable

    The EU's Digital Operational Resilience Act became applicable across the financial sector on 17 January 2025, adding ICT and operational-resilience obligations that reach into cryptographic key management and third-party risk for in-scope entities.

  32. 13 Aug 2024Standards

    NIST finalises FIPS 203, 204 and 205

    NIST published the final versions of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) on 13 August 2024, settling the first generation of post-quantum key-establishment and signature standards that AutoPQC maps findings against.

Evidence Ledger

How a sealed finding resists silent alteration.

A distinct mechanism from this log above — the Signal Log is our own editorial record of what changed; the Evidence Ledger is a structural property of how AutoPQC stores findings, described in full in the Theos Method's method-versioning article.

What it proves

  • An append-only record of the evidence digest behind each finding — what was observed, when, and under which method version.
  • Tamper evidence: each record is chained to the one before it, so altering a sealed record changes the chain in a way that is detectable on inspection.
  • A stable reference you can hand to an auditor or attach to a Posture Attestation, independent of whether the underlying report file is later moved or renamed.

What it does not prove

  • It is not a blockchain. There is no distributed network, no token, and no consensus mechanism — it is an internal append-only log with a chaining scheme.
  • It is not notarised by any third party. No external timestamping authority or public ledger currently attests to these records. [PLACEHOLDER: whether a third-party timestamp authority will be added, and which one]
  • It does not prove the original observation was correct. It proves that a sealed record has not been silently altered since it was sealed — it says nothing about whether the finding itself was accurate. That question is answered by the review process described in the Help Desk, not by the ledger.

Illustrative sealed record — placeholders, not real digests

ILLUSTRATIVE — NOT A REAL RECORD
{
  "record_id": "eld_9f2ac1d4e8b04a2e",
  "asset_id": "ast_00042",
  "sealed_at": "2026-07-27T09:14:02Z",
  "method_version": "theos-method-v1.0",
  "evidence_digest": "sha256:4f2b9a0c-EXAMPLE-NOT-REAL-DIGEST",
  "prev_record_hash": "sha256:0c771e3d-EXAMPLE-NOT-REAL-DIGEST",
  "signature": "[PLACEHOLDER: signing scheme and key identifier]"
}

Every digest and identifier above is a placeholder. We will not publish a plausible-looking hash before the mechanism is live — see the concrete construction (hash function, chaining structure, publication cadence) in How the method is versioned.

Not yet built

  • [PLACEHOLDER: public inspection endpoint — where a recipient can independently verify a record's chain without contacting us]
  • [PLACEHOLDER: whether the ledger will be periodically anchored to an external timestamping service, and which one]
  • [PLACEHOLDER: retention period for sealed records after a workspace closes]

Public inspection endpoint: [PLACEHOLDER: public inspection endpoint URL for the Evidence Ledger]

How to be notified of changes

We do not operate a mailing list or an RSS feed for this page today, and would rather say so plainly than link a subscribe form that goes nowhere. [PLACEHOLDER: mailing list, RSS feed, or webhook for Signal Log updates — to be built] Until then, checking back here, or asking through /contact, are the only reliable ways to know what changed.