Quantum Clarity — End-to-End Quantum Assurance Pipeline
Quantum Assurance Pipeline · Preflight → Postflight · One Provenance Trail

One auditable trail from quantum job to verdict —
that checks its own models before it questions your hardware.

Quantum Clarity is an end-to-end assurance layer for quantum operations. QuantaCore™ records and freezes the execution context before a job runs; Eigenspectrum™ scores the returned result against a contract fixed before the outcome is seen. Every step is hash-bound, and the final verdict is recomputable from the provider's own raw output — no re-run required.

Why this matters for a platform

A trustworthy verifier's hardest test is restraint. When our pipeline hit a large residual on real hardware, it traced the fault to a false capability claim in its own reference model — and declined to call it a hardware anomaly. An assurance layer that suspects itself first is one that won't generate false alarms about your QPU.

The Pipeline

A single provenance trail,
submission to verdict.

The two halves are not separate tools that hand off. They are the preflight and postflight ends of one continuous, tamper-evident chain. Each stage emits a hash-bound artifact; the verdict at the end is bound to the contract declared at the start.

Unified runner: in integration
Input
Submit
job + declared intent
Preflight · QuantaCore
Freeze context
snapshot, plan, limits, qubit selection — hashed
QPU
Execute
run on selected backend
Return
Artifacts
counts + provider job IDs
Postflight · Eigenspectrum
Score vs. contract
invariants fixed before the result
Verdict
ACCEPT / FLAG / ABSTAIN
bound to the frozen contract
QuantaCore — preflight & runtime
Eigenspectrum — postflight result assurance
The spine: every stage above produces a frozen, hash-bound record — execution-context SHA, contract SHA, policy SHA, circuit and result hashes, provider job IDs. The verdict is recomputable from the provider's own returned data, after the fact, by anyone — without touching the QPU again. The architecture runs end to end today, stage by stage; a single-command runner that drives the whole chain is in integration.
Two Ends, One Spine

Where each half
does its job.

A quantum result can be untrustworthy for two different reasons: it ran somewhere unreliable, or it came back violating the rules it was supposed to preserve. The pipeline addresses both — and is honest about the maturity of each end.

Preflight · Execution

QuantaCore™

Records the conditions under which a quantum workload runs — backend and physical-qubit selection, calibration and device-health context, circuit and transpilation provenance, execution plans and limits — and freezes them so a run is a documented, controlled execution rather than a black-box submission. It also runs small, controlled probe circuits with matched controls as a placement diagnostic.

Maturity: a control-disciplined diagnostic and provenance recorder, demonstrated on real IBM hardware — including noise-aware preflight qubit selection applied end-to-end to a third party's published protocol (EC-STORAGE-001, below). Whether its runtime probe predicts workload quality better than published calibration remains an open, pre-registered question we state plainly.

QuantaCore detail →
Postflight · Results

Eigenspectrum™

Evaluates a returned result against a contract declared before the run — the invariants the result was supposed to preserve — and produces an auditable ACCEPT / FLAG / ABSTAIN. The contract, scoring policy, and thresholds are frozen and hashed before the outcome is known, so the acceptance rule cannot be quietly changed after the data is seen.

Maturity: a validated invariant detector — demonstrated on simulation with ground truth and on real IBM hardware.

Eigenspectrum detail →
The Evidence

What the pipeline
has actually shown.

Every figure below is reproducible. Hardware results are tied to public IBM Quantum job IDs — across three independent Heron-class processors to date — and the reported observables recompute from the provider's own returned measurement data.

The pipeline caught a fault in its own reference model.

A five-probe suite on IBM hardware produced a large residual on the single-qubit idle-relaxation probe. A conventional pipeline might have blamed the device. Ours did not. Investigation found the reference model had declared idle thermal relaxation as "modeled" while its executable path never applied duration-matched relaxation to the delay — a false capability claim inside our own reference, not a hardware fault.

The first repair was also rejected: it computed the correct analytic answer but reused it while claiming executable verification. Only a second repair — a real duration-aware path, independently sampled — qualified. After correction, a residual remained:

hardware P1 0.93945  ·  executable reference P1 0.90942  ·  residual +0.03003  ·  z 5.15  ·  RESIDUAL_DETECTED

And we still did not call it a hardware anomaly. The evidence establishes a result-versus-reference discrepancy — most likely a frozen snapshot stale relative to execution — and does not yet isolate the cause. The entire correction reused the original hardware counts, with no additional QPU execution.

Preflight selection, proven on someone else's protocol.

In February 2026, Yamaguchi, Kempf and collaborators published encrypted quantum cloning — a lawful workaround structure to the no-cloning theorem — and proposed quantum storage as its headline application, without measuring the storage regime itself. Our preflight layer selected the qubits from the same-day calibration snapshot and ran the first storage-lifetime measurement of their protocol, on ibm_kingston, the same device as their original demonstration, on a calibration day below chip median. Entry fidelities landed at the top of the original authors' published cross-session range.

bare storage crossing ≈9.0 µs  ·  XY4-protected ≈18.6 µs  ·  fitted decay 8.8 ± 0.3 → 17.3 ± 0.5 µs  ·  QPU one job, ≈23 s, zero reruns

Pre-registered — including a prediction miss, documented in the record rather than hidden. Data, calibration snapshot, and a public reproduction script: DOI 10.5281/zenodo.21299091.

Two quantum processors, one frozen contract — fully public.

In a separate, openly published study, a single pre-registered contract (SHA-256 44d34db0…), hashed before any result was seen, was applied across an exact solver, a noisy simulator, a device-calibrated twin, and two independent IBM Heron processors — Kingston and Fez.

It accepted the exact reference, abstained honestly on a shot-limited valid hardware run, and flagged a deliberately corrupted one — the complete ACCEPT / FLAG / ABSTAIN triad, on real hardware, from one hashed contract. Every verdict recomputes from published data with two one-command scripts: no QPU re-run, no "trust us."

Open repository — code, data, and verifiers: github.com/amitb-quantum/helium-vqe-assurance

Validated detector · simulation
On 35 simulated quantum-chemistry records with independent ground truth, the invariant detector reproduced the classification with zero disagreements — 30 clean results accepted, 5 bad results flagged.
Frozen contract · real hardware
On IBM Kingston (156-qubit Heron r2), a single pre-registered contract accepted a valid result and flagged a violating one — both verdicts from the same hashed contract and threshold.
Pre-registered error ledger · public
A four-experiment decoherence-free-subspace study published with an eleven-entry public deviations ledger — including a withdrawn analysis and a falsified, amended model — and two pre-registered nulls reported as findings, not buried. DOI 10.5281/zenodo.21302900
Multi-backend footprint
Published, reproducible hardware results across three independent Heron-class processors — Kingston, Fez, and Marrakesh — each anchored to public IBM Quantum job IDs and deposited raw data.
Reproducible provenance: the five-probe hardware run is bound to public IBM Quantum job IDs. The structured-probe observable was independently recomputed from the returned measurement data and reproduced the published value <Y0·Z1> = −0.701172 exactly. The claim is not "trust us" — it is "clone the repo and run the verifier scripts": every verdict recomputes from published data, anchored to public IBM Quantum job IDs, with no QPU re-run and no dependence on third-party job access.
For Platforms

An assurance layer,
not another algorithm.

For a platform like IBM Quantum or Google Quantum AI, the value here is not a faster result — it is a reproducible, pre-registered audit trail over quantum jobs, and a verifier disciplined enough to suspect its own models first. These properties stand on their own, the way build-provenance tooling does for software.

Pre-registered verdicts

Contracts, policies, and thresholds are frozen and hashed before the result is seen — the acceptance rule can't move after the data lands.

Recomputable results

Verdicts and observables regenerate from the provider's own returned data, tied to public job IDs — auditable by anyone, after the fact, with no QPU re-run.

Self-suspecting by design

The pipeline is architected to flag its own reference models and repairs before attributing a discrepancy to hardware — the property that prevents false alarms about your QPU.

Shadow-mode ready

Runs alongside jobs that execute anyway, logging the verdicts and placements it would have produced — evaluated against real outcomes without affecting a single user job.

Knows when to abstain

A verifier that always answers is not measuring its own resolution. When the data cannot certify a result, the verdict is ABSTAIN — an honest "not yet," not a false pass. That restraint is what makes an ACCEPT mean something.

Beyond Quantum

The same architecture,
wherever you can't check the answer.

Quantum is the proving ground, not the boundary. The core discipline — declare the invariants, freeze and hash the contract before the result, then score ACCEPT / FLAG / ABSTAIN — applies to any process that returns results you cannot check against ground truth but can constrain by rules the right answer must obey.

Financial model validation

No-arbitrage, VaR ≥ component VaR, P&L and balance-sheet identities. Freezing the acceptance rule before the out-of-sample test attacks overfitting and p-hacking head-on, with an audit trail for model governance (SR 11-7).

AI / ML evaluation & governance

Frozen, hashed eval contracts that resist benchmark gaming and test-set contamination; out-of-distribution outputs route to ABSTAIN. Pre-registered, recomputable evidence for emerging audit requirements.

Scientific & engineering simulation

Conservation of mass, energy, and momentum; symmetry; thermodynamic bounds. Catch ML surrogates that silently drift before their output feeds safety certification.

Clinical trials & data pipelines

Pre-specified endpoints and analysis plans, schema and reconciliation integrity — made tamper-evident and recomputable rather than merely procedural.

Quantum hardware is the hardest case. If the method can certify a noisy QPU's output, your domain's invariants are more tractable, not less.

Scope & Discipline

What the pipeline is —
and the lines we hold.

What it is

Demonstrated, reproducible, pre-registered
  • An end-to-end provenance trail: preflight context → execution → postflight verdict
  • A validated invariant detector — simulation ground truth, then real hardware
  • Frozen, hash-bound contracts with verdicts recomputable from the provider's own data
  • A pipeline that flags its own reference-model faults before blaming hardware
  • Preflight qubit selection demonstrated end-to-end on a third party's published protocol
  • Architecturally end-to-end today; unified single-command runner in integration
Boundaries we hold

We attribute discrepancies conservatively — never to hardware without isolating the cause. No detected anomaly is claimed unless the mundane explanations are ruled out first.

We state IP precisely. QuantaCore™ and Eigenspectrum™ are filed trademark applications (Eigenspectrum on an intent-to-use basis) — described as filed, never as registered.

Status · Research Prototype
Pipeline: end-to-end architecture demonstrated stage by stage on real IBM hardware; unified single-command runner in integration. IP status: QuantaCore™ and Eigenspectrum™ trademark applications filed; public materials describe only reproducible validation workflows.

Built on evidence, bound by provenance.

Quantum Clarity is an end-to-end assurance pipeline for quantum operations — preflight context capture through postflight, contract-bound verdicts, every figure reproducible from the provider's own output. We are open to technical evaluation, research collaboration, and shadow-mode validation partnerships.

Or contact directly: info@quantum-clarity.com