How it proves

An AI claim is not evidence. A signed verdict is.

Quaestor’s multi-turn technique turns an unverifiable model claim into a defensible verdict. Every finding walks the same path; every gate decision is Ed25519-signed with a per-tenant key.

0

Sanitise

Secrets stripped, redacted, and sealed with a manifest — before any model sees a line.

B

Map

The codebase cartographed: entrypoints, privileged sinks, and what is actually reachable.

C

Source→sink

The exploit path traced end to end and proven — not asserted from a snippet.

F

Negative control

A counter-test a genuine finding must survive. This is what kills the hallucination.

G

Impact

Blast radius calibrated to CVSS, OWASP, and CWE — provisional until confirmed.

H

Readiness

Report-grade and signed, or refused. There is no “probably.”

The dossier

Every case is an exhibit.

A finding arrives with its full chain of custody: the sanitised source it was found in, the traced path, the negative control it survived, the signed gate ledger A–H, and the signer identity. Nothing is taken on faith.

When a candidate can’t survive a gate, that is recorded too — a disproven case is first-class, not swept away. The portal shows what was refused and why. That honesty is the difference between a scanner and a tribunal.

CASE · 01KXPKT02QM4 CRITICAL · 9.8

Unauthenticated endpoint exposes all claim records

A01 · Broken Access Control · CWE-862
AB CD
SIGNED Needs evidence — the pipeline refused to over-claim.
signer tenant:local:root · Ed25519 · payload sha256 9f2a…c71b
The moat

Metrics competitors structurally cannot produce.

Because most tools guess, they can report volume but never integrity. A governed pipeline can report both.

25Candidates found
23Held for evidence
2Disproven
0Rubber-stamped

Mean time-to-evidence, proof rate, and disproven rate — the numbers a board trusts because they can be traced to a signature.

Read a real dossier.

Run a scan and get the whole chain of custody back — proven, disproven, and signed.