Certification
Quantum Computing Certification
Approximate methods return estimates. The question that decides whether a result can be used is how far from the truth it might be, and that quantity is measured on every run rather than assumed.
ZCC-v0.1
Simulation accuracy
A finished job can be exported as a certificate: a self-contained record of which circuit ran, which method produced the answer, and how accurate that answer is. It carries no account or billing information, so it can be published alongside a result and checked by anyone.
The example shown is a 24-qubit QAOA MaxCut ring at depth p=3 on the certified matrix product state path, at a bond dimension of 48. The cap binds during this run, so compression genuinely discards weight rather than representing the state exactly. The discarded weight is 5.617e-09 and the resulting bound on any single outcome probability is 1.06e-04.
Open a live certificate
The failure mode is silent
A matrix product state simulator run with insufficient bond dimension does not raise an error. It returns a normalized probability distribution that looks entirely plausible and is quietly wrong. A Pauli propagation run with an overly aggressive truncation threshold behaves the same way. Unlike a routine that diverges or a program that crashes, the truncated simulation converges to a confident answer that happens to be incorrect.
Real quantum processors present the same problem from the other direction. A device returns measured counts with no statement of how closely those counts track the ideal answer. Any accuracy framework has to be built to detect exactly this quiet, self-consistent kind of error.
Three statements, never blurred together
Each protocol answers a different question, and each is labelled for what it is. A measured bound is not a hardware fidelity, and a variational ceiling is a third thing again: unconditional where the others are conditional on a measurement.
ZCC-v0.1 · simulation accuracy
- protocol
- "ZCC-v0.1"
- method
- "MPS, discarded-weight bound"
- truncation_weight
- 3.2e-08
- error_bound
- 2.5e-04
- certified
- true
An error bound read from the weight discarded during simulation, measured in one run rather than extrapolated
ZHF-v0.1 · hardware fidelity
- protocol
- "ZHF-v0.1"
- device
- "IonQ Forte-1"
- fidelity_mode
- "direct"
- fidelity
- 0.9774
Real hardware counts measured against the exact ideal distribution, not a self-reported device spec
Neural · ground-state ceiling
- protocol
- "ZCC-Estimate-v0.2"
- method
- "nnqs.vmc"
- energy_variance
- 5.53e-04
- ground_state_ceiling
- -10.2499758
- ground_state_floor
- -10.2819442
- floor_method
- "weinstein"
- floor_is_conditional
- true
Two figures of unequal strength, reported separately rather than as one interval. The ceiling is unconditional, from the variational principle, widened by five standard errors. The floor holds only while the trial state lies nearer the ground state than the first excited state, which a run cannot check about itself
Convergence is evidence
Every approximate method exposes a resource parameter: bond dimension for MPS, coefficient cutoff for Pauli propagation. Running a circuit at resource level chi and again at 2chi, then measuring the change in the reported observables, shows directly whether the approximation has saturated. If doubling the resource leaves the result unchanged, the extra representational capacity found nothing new. If the result moves, that movement is itself a quantified warning.
This is the default for the tensor-network engine. It is strong evidence, and it is not a proof. It shows the answer stopped moving, not that it cannot move. We never describe it as a certified bound.
A measured single-run bound
Passing certified=True selects a stronger path. The circuit is built with state renormalization disabled, so the squared norm of the final state records exactly how much weight every singular-value decomposition discarded. Writing eps for that accumulated weight, eps equals one minus the squared norm. Each truncation is optimal by the Eckart-Young theorem, and eps is measured rather than estimated. The error on any single outcome probability is reported as the square root of twice eps.
Pauli propagation is the stricter case. Its bound is an additive triangle inequality over discarded coefficient mass, and needs no such assumption.
Where the bound stops holding
The square-root figure is tight when the individual truncation errors accumulate incoherently. That condition is not always satisfied. Across N sequential truncations the adversarial accumulation is the sum of the square roots of the individual eps values, which can exceed the square root of twice their total. In deep circuits the accumulated eps has been measured understating the true infidelity by as much as a factor of nine.
The reported bound is therefore an empirical result rather than a consequence of that derivation. Across 334 runs at sizes where the exact answer is computable, 290 of them constructed specifically to falsify it, the figure was never exceeded, coming closest at 49 percent of its value. Those checks need an exact reference and so reach 20 qubits. Beyond that size no direct verification is available, and we say so rather than implying the evidence extends further. Where a hard ceiling is required, use an exact or stabilizer engine.
We tried to claim more than this, and could not
The bound is stated for the error on any single outcome probability, which is the weakest of several things it might have bounded. In September 2026 we tested whether a stronger statement covering the whole distribution was defensible, across 1,543 runs to 24 qubits over six circuit families, three of them built specifically to break the incoherence assumption rather than to exercise it. 965 of those runs produced a bound below 1 and were therefore capable of failing.
| Quantity compared against the bound | Exceeded | Closest approach |
|---|---|---|
| Error on any single outcome probability | 0 of 965 | 26% |
| Total variation distance | 23 of 965 | 139% |
| State infidelity | 15 of 965 | 117% |
The claim we publish held and never came within three quarters of failing. Both stronger claims failed outright. Every violation came from the family built to maximise the number of small truncations, which is exactly the adversarial case the derivation warns about. The wording on the certificate is therefore not house style, it is the strongest statement the evidence supports. Those violations also grow with circuit size, from 1.30 times the bound at 12 qubits to 1.39 at 24, and 24 qubits is where exact verification stops being possible. We cannot see past the point where the evidence runs out.
ZHF-v0.1
Hardware fidelity
A quantum processor returns its own measured counts, so the relevant statement is device fidelity rather than approximation error. That is a different claim, and it carries its own protocol rather than being folded into ZCC-v0.1.
Where a circuit is small enough to also simulate exactly, ZHF-v0.1 reports the measured fidelity between the hardware counts and that exact ideal distribution, computed directly rather than taken from a vendor specification sheet. Where the circuit is too large for an exact reference, the certificate says direct verification is unavailable instead of reporting a figure it cannot support.
Two representative runs, submitted through the same API as a simulator job and reported exactly as measured. These are raw counts, with no error mitigation, post-selection, or readout correction applied. Any deviation from the ideal is the physical noise of the device.
| Device | Circuit | Measured |
|---|---|---|
| Rigetti Cepheus-1 | 3-qubit GHZ, 50 shots | 45/50 in the GHZ states |
| IonQ Forte-1 | 2-qubit Bell, 100 shots | 98/100 in the Bell states |

ZQEC-v0.1
Logical error rate
The other two protocols answer how far a result is from a known answer. This one answers a different question: how well a code holds a logical qubit, and therefore how many physical qubits one logical qubit costs at a given physical error rate.
A logical qubit is prepared in a code, held for a number of rounds of syndrome extraction under circuit-level noise, then measured. The syndrome is decoded and the shot counts as a failure if the logical value came back flipped anyway. The certificate reports how often that happened, out of how many attempts.
The interval is the assertion, not the rate. A logical error rate is a proportion estimated from a finite number of shots, so at a hundred thousand shots with no failures it reads exactly zero, and no finite experiment establishes that a code never fails. Every certificate carries a Wilson score interval, which stays correct at zero where the textbook interval collapses to [0, 0] and claims a perfect code.
- protocol
- "ZQEC-v0.1"
- code
- "surface"
- distance
- 5
- rounds
- 5
- physical_error
- 0.001
- logical_errors
- 4
- shots
- 20000
- logical_error_rate
- 2.0e-04
- confidence_interval_95
- [7.78e-05, 5.14e-04]
- decoder
- "minimum-weight perfect matching"
The decoder is part of the claim. A logical error rate is a property of a code and its decoder together, so a better decoder on the same data returns a lower number. Colour and qLDPC codes are refused rather than decoded by matching, because matching is the wrong decoder for them and a wrong decoder returns a plausible number rather than an error.
The hash excludes the shot count. It covers the code and the noise model, so the same experiment measured to a different precision hashes the same, and a narrower interval is visibly more shots rather than a different setup.
Memory, not computation. Prepare, hold, read out. No logical gates and no lattice surgery, so this does not bound the error of a computation performed on that qubit.
Several certified runs at different distances give the suppression factor: how much each two steps of code distance divide the logical error rate. From it follow the distance and the physical qubit count that reach a target. Those answers state which half was measured and which was extrapolated along the measured slope, and at or above threshold the answer is that no number of physical qubits reaches the target until the physical error rate falls, which is a result rather than a failure.
Why a certificate, and what is in one
An error bound printed in a terminal is only as trustworthy as the person who ran the job. Once a number leaves that session and enters a paper, a slide deck, or a client report, its provenance is gone. A reader has no way to confirm which circuit was actually run, which method produced the figure, or whether the number was transcribed correctly. An unverifiable number is an assertion rather than a result.
Every result carries this, and the certificate has a permanent public URL. Run one yourself
- The exact circuit, identified by a SHA-256 hash of its source, so a certificate cannot be silently attached to a different computation
- The method and its parameters: which engine ran the job and, where relevant, the resource budget used
- The accuracy verdict: a measured bound, a convergence-based estimate, or a measured hardware fidelity, labelled according to which it is
- A public verification link, backed by a record containing no account, billing, or personal information
A simulation whose own error bound would be vacuous is refused rather than returned, with a diagnostic stating what would make the circuit tractable.
Checkable without us
A certificate issued by the party that produced the result is a claim, not evidence. zcc-verify is an open-source checker that recomputes a certificate’s declared bound from the measurement the certificate reports, and requires the two to agree. It has no dependencies, needs no account, and does not call this service.
It establishes that a certificate is well formed and self-consistent. It does not establish that the underlying measurement was honestly made, and states as much. Verifying a certificate is not the same as trusting its issuer.
$ pip install zcc-verify$ zcc-verify df1d4c698a954051certificate df1d4c698a954051 (ZHF-v0.1)[ok] protocol recognised: ZHF-v0.1[ok] carries no account or circuit data[ok] circuit identified by SHA-256[ok] measured outcomes: 3 outcomes, 100 shots shown[ok] fidelity mode declared: direct[ok] fidelity within [0, 1]: 0.977442consistent: the stated bound follows from the stated measurement
A reproducible example
A 192-qubit GHZ circuit measured with an all-Z observable on the pauli.cpu engine returns an expectation value of exactly +1, carrying a certified ZCC-v0.1 error bound of 0 because no Pauli terms were discarded during propagation. A statevector simulator cannot reach this size, since 192 qubits would demand more memory than exists on Earth, yet the run completed in under a minute for $0.0001. Its certificate is public and independently verifiable at api.zksf.org/certify/5b8b2c4309d44d41, and the three lines of SDK code that reproduce it are in the documentation.
A second example, where the estimate is wrong and the certificate still holds
An 8-spin transverse-field Ising ring on neural.tpu, on a Google TPU v5e. 60.4 seconds of variational Monte Carlo returned a ceiling of -10.2499758 on the true ground-state energy. The exact answer for that Hamiltonian, computed independently on the same machine, is -10.2516623, so the ceiling holds.
The interesting part is the point estimate. It came out at -10.2522907, which is 0.00063 below the true ground state, a place the variational principle forbids the real expectation value from being. It is there because a Monte Carlo mean has sampling noise, and 0.00063 is 1.4 standard errors of it. Had we certified the estimate, we would have published a number that violates the principle we sell. We certify the ceiling, which carries that noise inside it by construction, and the certificate is right where the headline number is not.
Three independent restarts agreed to 1.1e-3 and the Markov chains mixed, R-hat 1.0014. Neither of those is what makes the ceiling true; they are the evidence for the conditional floor, and they travel with the certificate so you can weigh it yourself. It is public at api.zksf.org/certify/66e9fabc9e784425.
For practitioners and reviewers
When reviewing a manuscript, it is worth asking what accuracy evidence accompanies a classical simulation baseline, and specifically what a second run at doubled resources would show. For a hardware result, the equivalent question is what the fidelity was measured against, and whether that was computed directly or asserted by the vendor. The same questions apply when procuring simulation or hardware access. A convergence record, a measured truncation bound, and a measured hardware fidelity are all inexpensive to produce and straightforward to verify, and their absence is itself informative.
Read further
The specification paper
Derivations, validation methodology, and the adversarial falsification search. Archived on Zenodo, DOI 10.5281/zenodo.21851381
The methodology write-up
The longer article, with code samples, reproducible benchmarks, and sample certificates
The documentation
How to request a certified bound, export a certificate, and read every field
Run a certified circuit
Open the console and produce a certificate of your own