Skip to content

Trust

A first-pass security review should not need a phone call. Everything a reviewer needs to decide whether to proceed is on this page, including the gaps.

Client data held
None
Modules run inside your environment
Encryption keys held
None
Your storage, your key management
Incident notice
72 hours
Shorter window can be agreed
Client audit
Before signature
Written into the agreement
1.0Status

What you can get today

What a reviewer can obtain today, and the certification status underneath it
ItemStatusDetail
Security questionnaireOn requestYour CAIQ, SIG Lite or equivalent completed and returned under NDA, within two business days, with gaps marked rather than left blank.
Client auditInvitedThe right to audit is written into the agreement, and an audit can be scheduled before contract signature rather than after.
Technical documentationWith deliveryDocumentation delivered with the software. Covers architecture, change control records, test evidence and handover material.
Third-party certificationNot heldNo SOC 2, ISO 27001 or CSA STAR report exists to send. What is offered instead is the row above: inspection, before you sign.
2.0Data

Architecture and data handling

Scroll the diagram sideways

YOUR ENVIRONMENTQuantscopeholds no client dataCHANGECONTROLSOFTWARE RELEASESModulesCDTSGLTRCGAUYour storageyour keysYour identity provideryour access modelCLIENT DATA NEVER LEAVES
Figure 1. The preferred deployment boundary. A software release is the only thing that crosses it, and it enters through your change control.
Encryption
At rest under your storage encryption and key management, with Quantscope holding no key. In transit under your certificate authority.
Access
Access is scoped to what the engagement requires and deprovisioned when it ends.
Training boundary
A contractual term that no client data trains, tunes or evaluates anything outside that client's own engagement.
3.0Change

Software development and change control

Version control
Every change enters through a reviewed commit. The full release history is available to a client audit.
Automated checks
Dependency and vulnerability scanning on every change. A failure blocks the change rather than raising a ticket.
Change record
Request, impact assessment, risk evaluation, test evidence, approval and rollback plan.
Audit trail
Who, what, when, previous value, new value and reason. Every change is attributable, timestamped, and reviewable.

The architecture documentation describes how a deployed instance is configured, versioned and separated from development.

4.0Processors

Subprocessors

Where the modules run in your environment, no subprocessor processes your data at all. For a hosted deployment, the subprocessor list is fixed in the data processing agreement before any data moves, with additions notified in advance and an opportunity to object.

5.0Continuity

Continuity and incident response

Incident notice
Written notice of a confirmed security incident within 72 hours, and without undue delay in any case.
Recovery objectives
Recovery time and recovery point objectives are agreed upfront against workflow criticality and written into the agreement.
Escrow and handover
Source escrow and documented handover are available as terms, which is the structural answer to key-person risk at this company size.
6.0Audit

Audit and disclosure

An audit gets access to the development practice, the change control records, the release history and the evaluation records, with findings answered in writing. To schedule one, or to report a security finding, write to security@quantscope.ai.

Available on request under NDA, within two business days: architecture and data flow documents for a specific deployment, and the change control procedure.

7.0Next step

Start with the data

A reviewer who has read this far has the security picture. The commercial one starts with the data type, the volume, and what currently has to be processed by hand.

Request a technical sessiongoes to info@quantscope.ai · response within two business days