Aere Quantum Exposure Report
An exposure report your auditor can re-run without us
Most quantum-readiness reports are an opinion with a logo on it. This one carries the command that reproduces it, so the person who reviews your work next year can run it against a node they operate themselves and get the same answer, or a documented difference.
What you get
- A measurement, per address. What was measured, and what the tool refused to settle on its own. Those are different, and the report never blurs them.
- The exact command that reproduces it, with
--rpcpointing wherever you like. Nothing in the report depends on trusting us. - A digest manifest, so a report that has been edited after delivery is detectable.
- An on-chain anchor of the report digest, signed under a post-quantum validator certificate, with a public verifier you run yourself.
- Answers in the wording of the published criteria (NIST IR 8547 and CNSA 2.0), phrased as criteria and never as a certification.
Price
| Free scan, one address | 0 | Verdict and the reachable post-quantum verifiers. No account needed. |
|---|---|---|
| Report | 149 EUR | One report: PDF, JSON, manifest, anchored certificate, questionnaire annexes. |
| Portfolio, up to 50 addresses | 490 EUR | The same, aggregated, with prioritisation. |
| Monitoring | 99 EUR / month | Re-scan on change, alert on regression. |
| Reseller licence, for audit firms | 990 EUR / year | Unlimited reports under your own brand. Your client can still reproduce every one of them. |
Prices exclude VAT, which is handled by the payment processor as merchant of record.
What this report does not claim, written before you buy
- We are not an accredited audit firm, and this is not an accredited audit. It measures the on-chain slice: bytecode and what it can reach. Repositories, TLS, dependencies, key custody and HSMs are out of scope.
- It does not say compliant with NIST. It says measured against the criteria published in NIST IR 8547. Compliance is a statement only an accredited body can make.
- A post-quantum verifier called from a transaction that is itself authorised with ECDSA gives no post-quantum security. The adversary forges the outer transaction. Anyone selling you the opposite can be taken apart in five minutes, and we would rather you heard it here.
- "Harvest now, decrypt later" does not apply to signatures. A signature is public and is not harvested. The threat that applies to a chain is retroactive rewriting of history with keys recovered later, which is a different and more serious problem.
- No legal effect is promised. What an anchored digest means in court depends on jurisdiction.
- The chain this anchors to has one operator and no external security audit yet. We publish that ourselves, on the decentralisation page, with the measurements. The report's value does not rest on trusting that chain: it rests on you being able to re-run the measurement.
Why us
Because the tooling was built to measure our own chain first, and it is unkind to it. The same scanner that produces your report produces our public findings register, including the ones that make us look bad. A vendor whose tool has never returned a red verdict about the vendor is selling you a brochure.
The verifier for the anchored certificate is public, installs nothing, and accepts your own
node: node verifica-certificat.mjs certificate.json --rpc https://your-node.
Five deliberately falsified certificates were planted against it and all five were rejected.
Start with the free scan
Send the address you want measured. You get the verdict and the open questions at no cost and with no account, and you decide afterwards whether the full report is worth 149 EUR.
Payment is handled by a merchant of record. Never in AERE tokens: the token is not listed and has no liquidity, and paying for a compliance report in an illiquid token would be a bad idea for you.