Skip to content
Quantscope

Trust

A first-pass security review should not need a phone call. Everything a reviewer needs to decide whether to proceed is on this page, including the gaps.

1.0Status

Current status

Certification and assurance status, including what is not held
ItemStatusDetail
SOC 2 Type IINot heldNot held. No report exists, and Quantscope will not describe itself as SOC 2 compliant, which is not a state a company can be in.
SOC 2 Type INot heldNot held.
ISO 27001Not heldNot held, and not in an audit process.
CSA STAR Level 1Not filedNot filed.
Security questionnaireOn requestYour CAIQ, SIG Lite or equivalent completed and returned under NDA, with gaps marked rather than left blank.
Validation packageWith deliveryWritten during the engagement to your document standards and handed over with the software.
Client auditInvitedThe right to audit is written into the agreement, and an audit can be scheduled before contract signature.
2.0Data

Architecture and data handling

The preferred deployment runs the modules inside your environment, against your storage, under your identity provider. Quantscope holds no client data and initiates no inbound connection, so the security question narrows from data custody to source code and change control. Where a hosted deployment is required, region, retention and deletion are set in the agreement rather than left to a default.

Encryption
At rest under your storage encryption and key management, with Quantscope holding no key. TLS 1.2 or above in transit, under your certificate authority.
Access
Least privilege and multi-factor authentication, with access deprovisioned at the end of an engagement.
Training boundary
A contractual term that no client data trains, tunes or evaluates anything outside that client’s own engagement.
3.0Change

Software development and change control

Version control
Reviewed and recorded commits, on every change.
Automated analysis
Dependency and static analysis on every change, where a failure blocks the change rather than raising a ticket.
Change record
Request, impact assessment, risk evaluation, test evidence, approval and rollback plan.
Audit trail
Who, what, when, previous value, new value and reason.
Model versioning
Model identity and configuration are part of the release record, scored by Baseline before release.

The architecture documentation describes how a deployed instance is configured, versioned and separated from development.

4.0Processors

Subprocessors

Where the modules run in your environment, no subprocessor processes your data at all. For a hosted deployment, the subprocessor list is fixed in the data processing agreement before any data moves, with additions notified in advance and an opportunity to object. The list for a specific deployment is supplied during qualification.

This website itself is served by Vercel Inc., which processes standard server request data, including IP address, to serve the page. The site sets no cookies, runs no analytics and contains no form.

5.0Continuity

Continuity and incident response

Incident notice
Written notice of a confirmed security incident within 72 hours, and without undue delay in any case. A shorter window can be set in the agreement.
Recovery objectives
Recovery time and recovery point objectives are agreed per engagement against workflow criticality and written into the statement of work.
Escrow and handover
Source escrow and documented handover are available as terms, which is the structural answer to key-person risk at this company size.
6.0Audit

Client audit programme

Quantscope holds no certification to point at, so the alternative is offered directly: inspection. The right to audit is written into the agreement, and an audit can be scheduled before contract signature rather than after. An audit gets access to the development practice, the change control records, the release history and the evaluation records, with findings answered in writing.

To schedule one, write to security@quantscope.ai.

7.0Disclosure

Responsible disclosure and documents

Security findings about this website or the software are read and answered at security@quantscope.ai. Good-faith research is welcome; no marketing follows a report.

Available on request under NDA, within two business days: completed security questionnaires, validation deliverables, architecture and data flow documents for a specific deployment, and the change control procedure.