Trust
A first-pass security review should not need a phone call. Everything a reviewer needs to decide whether to proceed is on this page, including the gaps.
- Client data held
- None
- Modules run inside your environment
- Encryption keys held
- None
- Your storage, your key management
- Incident notice
- 72 hours
- Shorter window can be agreed
- Client audit
- Before signature
- Written into the agreement
What you can get today
| Item | Status | Detail |
|---|---|---|
| Security questionnaire | On request | Your CAIQ, SIG Lite or equivalent completed and returned under NDA, within two business days, with gaps marked rather than left blank. |
| Client audit | Invited | The right to audit is written into the agreement, and an audit can be scheduled before contract signature rather than after. |
| Technical documentation | With delivery | Documentation delivered with the software. Covers architecture, change control records, test evidence and handover material. |
| Third-party certification | Not held | No SOC 2, ISO 27001 or CSA STAR report exists to send. What is offered instead is the row above: inspection, before you sign. |
Architecture and data handling
Scroll the diagram sideways
- Encryption
- At rest under your storage encryption and key management, with Quantscope holding no key. In transit under your certificate authority.
- Access
- Access is scoped to what the engagement requires and deprovisioned when it ends.
- Training boundary
- A contractual term that no client data trains, tunes or evaluates anything outside that client's own engagement.
Software development and change control
- Version control
- Every change enters through a reviewed commit. The full release history is available to a client audit.
- Automated checks
- Dependency and vulnerability scanning on every change. A failure blocks the change rather than raising a ticket.
- Change record
- Request, impact assessment, risk evaluation, test evidence, approval and rollback plan.
- Audit trail
- Who, what, when, previous value, new value and reason. Every change is attributable, timestamped, and reviewable.
The architecture documentation describes how a deployed instance is configured, versioned and separated from development.
Subprocessors
Where the modules run in your environment, no subprocessor processes your data at all. For a hosted deployment, the subprocessor list is fixed in the data processing agreement before any data moves, with additions notified in advance and an opportunity to object.
Continuity and incident response
- Incident notice
- Written notice of a confirmed security incident within 72 hours, and without undue delay in any case.
- Recovery objectives
- Recovery time and recovery point objectives are agreed upfront against workflow criticality and written into the agreement.
- Escrow and handover
- Source escrow and documented handover are available as terms, which is the structural answer to key-person risk at this company size.
Audit and disclosure
An audit gets access to the development practice, the change control records, the release history and the evaluation records, with findings answered in writing. To schedule one, or to report a security finding, write to security@quantscope.ai.
Available on request under NDA, within two business days: architecture and data flow documents for a specific deployment, and the change control procedure.
Start with the data
A reviewer who has read this far has the security picture. The commercial one starts with the data type, the volume, and what currently has to be processed by hand.
Request a technical sessiongoes to info@quantscope.ai · response within two business days