One-pager

Assure

Every finding arrives with its own alibi.

Most scanners hand you a list and ask you to trust it. Q² Assure is a deterministic security review platform — no model participates in any verdict — and every finding is replayed against the exact bytes it cites and challenged for evidence that would refute it, with its prerequisites recorded on the finding and counter-evidence recorded wherever the review found any.

On the record

67 detection rules across SAST, secrets, SCA, IaC, container, and post-quantum analysis
554 synthetic findings, each replayed and validated
0 repository code executions

Analysis coverage

  • 01JS/TS SAST
  • 02Python/Go/Java/C# SAST
  • 03SCA (npm/PyPI/Maven/Go)
  • 04Secrets
  • 05IaC (Terraform/K8s/CFN)
  • 06Containers
  • 07DAST (authorized synthetic targets)
  • 08Post-quantum (PQC) readiness
  • 09Governed remediation

Why it is different

Deterministic engine

No model participates in any verdict.

Fail-closed replay

Mutation or missing context cannot silently pass as confirmed.

Counter-evidence is first-class

Unresolved assumptions and counter-evidence get their own panel beside impact and attack paths.

Immutable source identity

Content-addressed manifests bind every claim to exact evidence.

Visible 1V–4V

Finder, validator, truth review, and human judgment stay distinct.

Governed remediation

Minimal-diff proposals, independently re-verified. No auto-write.

What the demonstration does not show

JavaScript, the Python, Go, Java, and C# engines, the PyPI, Maven, and Go dependency ecosystems, CloudFormation, authorized DAST, the post-quantum checks, and provider-pattern secret matching are real and wired, but they are not exercised by the published demonstration corpus.

Internal engineering candidate · synthetic static-only demonstration Assure capabilities audited against package source 13 August 2026

Layer comparison qa.bwtr.ai/comparison.html · capability roadmap qa.bwtr.ai/roadmap.html