Public statement · v1

Qlro Independence Statement

Last revised 2026-05-04 · Permanent URL: qlro.io/independence

Qlro is the third-party issuer of vendor-neutral quantum-device recommendations.

The recommendation engine is derived from the open WCPP framework (DOI 10.5281/zenodo.19785800) and the Metriq community snapshot of measured device performance. Qlro Inc. and its parent StockFolio Inc. do not receive payment, equity, referral commissions, or any other form of compensation from any of the quantum hardware vendors that appear in our rankings.

IBM QuantumIonQQuantinuumIQMRigettiOQCPasqalQuEraXanadu

✕ = no compensation received from this vendor. List is illustrative; the rule applies to every vendor we add to future snapshots.

Partners that embed Qlro recommendations in their own products (the Partner Programme) sign a contract clause prohibiting modification of recommendation output before display. The widget at qlro.io/embed/recommend is rendered server-side under the qlro.io origin; partners cannot intercept or modify the recommendation, only style the surrounding frame.

Structural defenses

Six load-bearing invariants

Defense is structural, not vibes. Every PR that touches a tenant-scoped or audit-grade surface is reviewed against these rules. The full text + verification checklists live in INVARIANTS.md.

  • I-1

    Outcomes never come from a freeform field

    No public surface accepts a user-typed observed-fidelity. Submissions only via authenticated SDK + signed device runs. The dataset external papers cite is signed-rows-only.

  • I-3

    Snapshot DOIs are content-hashed and never rewritten

    Once a Qlro snapshot is published it is frozen forever. Re-running on the same snapshot yields the same recommendation.

  • I-7

    Cross-tenant isolation

    Partner A cannot enumerate Partner B's customers. Customer X cannot read Customer Y's history. Failed attempts write to audit_log.

  • I-8

    Audit reports are immutable + signed

    Every audit PDF is signed with an Ed25519 keypair. Verify with `qlro verify <report.pdf>` against the public key at /.well-known/.

  • I-9

    Partners cannot tamper with output

    The widget iframe renders on qlro.io. Partner-name byline, snapshot DOI, 'Verified' badge are all server-rendered and cannot be CSS-hidden.

  • I-10

    Customer owns its citation lineage

    Citekeys embed the customer-org slug + ORCID. Switching partners doesn't strand any artifact. Your reputation is portable.

Auditability

Open methodology, open code

External audits or independent reviews are welcome — contact official@stockfolio.ai.

Partner contract clause (verbatim)

"Partner shall not modify, suppress, or selectively present any portion of the recommendation output produced by the Qlro engine. Partner shall not introduce intermediate logic that biases the displayed recommendation toward any vendor in which Partner has commercial interest. Breach of this clause is grounds for immediate termination of the Partner agreement and revocation of all issued widget keys, without refund."
Binding on every active partner. Attestation timestamps tracked per partner.