Trust
A first-pass security review should not need a phone call. Everything a reviewer needs to decide whether to proceed is on this page, including the gaps.
Current status
| Item | Status | Detail |
|---|---|---|
| SOC 2 Type II | Not held | Not held. No report exists, and Quantscope will not describe itself as SOC 2 compliant, which is not a state a company can be in. |
| SOC 2 Type I | Not held | Not held. |
| ISO 27001 | Not held | Not held, and not in an audit process. |
| CSA STAR Level 1 | Not filed | Not filed. |
| Security questionnaire | On request | Your CAIQ, SIG Lite or equivalent completed and returned under NDA, with gaps marked rather than left blank. |
| Validation package | With delivery | Written during the engagement to your document standards and handed over with the software. |
| Client audit | Invited | The right to audit is written into the agreement, and an audit can be scheduled before contract signature. |
Architecture and data handling
The preferred deployment runs the modules inside your environment, against your storage, under your identity provider. Quantscope holds no client data and initiates no inbound connection, so the security question narrows from data custody to source code and change control. Where a hosted deployment is required, region, retention and deletion are set in the agreement rather than left to a default.
- Encryption
- At rest under your storage encryption and key management, with Quantscope holding no key. TLS 1.2 or above in transit, under your certificate authority.
- Access
- Least privilege and multi-factor authentication, with access deprovisioned at the end of an engagement.
- Training boundary
- A contractual term that no client data trains, tunes or evaluates anything outside that client’s own engagement.
Software development and change control
- Version control
- Reviewed and recorded commits, on every change.
- Automated analysis
- Dependency and static analysis on every change, where a failure blocks the change rather than raising a ticket.
- Change record
- Request, impact assessment, risk evaluation, test evidence, approval and rollback plan.
- Audit trail
- Who, what, when, previous value, new value and reason.
- Model versioning
- Model identity and configuration are part of the release record, scored by Baseline before release.
The architecture documentation describes how a deployed instance is configured, versioned and separated from development.
Subprocessors
Where the modules run in your environment, no subprocessor processes your data at all. For a hosted deployment, the subprocessor list is fixed in the data processing agreement before any data moves, with additions notified in advance and an opportunity to object. The list for a specific deployment is supplied during qualification.
This website itself is served by Vercel Inc., which processes standard server request data, including IP address, to serve the page. The site sets no cookies, runs no analytics and contains no form.
Continuity and incident response
- Incident notice
- Written notice of a confirmed security incident within 72 hours, and without undue delay in any case. A shorter window can be set in the agreement.
- Recovery objectives
- Recovery time and recovery point objectives are agreed per engagement against workflow criticality and written into the statement of work.
- Escrow and handover
- Source escrow and documented handover are available as terms, which is the structural answer to key-person risk at this company size.
Client audit programme
Quantscope holds no certification to point at, so the alternative is offered directly: inspection. The right to audit is written into the agreement, and an audit can be scheduled before contract signature rather than after. An audit gets access to the development practice, the change control records, the release history and the evaluation records, with findings answered in writing.
To schedule one, write to security@quantscope.ai.
Responsible disclosure and documents
Security findings about this website or the software are read and answered at security@quantscope.ai. Good-faith research is welcome; no marketing follows a report.
Available on request under NDA, within two business days: completed security questionnaires, validation deliverables, architecture and data flow documents for a specific deployment, and the change control procedure.