Security and data control
Security alone is not enough. Enterprise organizations require demonstrable control: over every access, every analysis, every output. Quvant is designed for this.
Where your data lives
Primary database is configured on MongoDB Atlas with provider-declared region AWS eu-south-1 (Milan). Application hosting is configured on Railway with provider-declared region EU West (Amsterdam). Both are documentary provider configuration; W0-4 classifies them UNKNOWN until instrumental proof. Encrypted at rest, 3-node replica set, continuous backup with PITR. Transfers to extra-EEA LLM sub-processors, where applicable, are governed by DPA/SCC and disclosed in the sub-processor list; we do not claim EU-only processing or absence of extra-EU transfers without instrumental proof per workload.
Each customer operates in a logically isolated space. Analyses, evidence packs, and logs of one organization are never accessible to another.
Enterprise: BYOC (Bring Your Own Cloud) is on the roadmap — custom evaluation only; not a generally available feature today.
Audit trail and SHA-256 hash-chain
Evidence records are SHA-256 hash-chained to make subsequent alteration detectable. An independent digital signature is not currently applied.
RFC 3161 TSA (Enterprise): exported PDF evidence is RFC 3161 timestamped by an external Time Stamp Authority — verifiable by third-party auditors with no dependency on Quvant. Broader evidence-pack manifest anchoring is on the roadmap.
Compliance and certifications
- GDPR: we process data necessary to deliver the service under a legal basis and DPA; we do not declare 'no personal data by design' as an absolute guarantee.
- The underlying MongoDB Atlas infrastructure is SOC 2 and ISO 27001 certified (Atlas sub-processor certifications, not Quvant's).
- Quvant's security programme takes ISO/IEC 27001 controls and principles as a reference. Documentation of implementation status is available during enterprise evaluation.
- Quvant's security programme takes ISO/IEC 27001 controls and principles as a reference. Documentation of implementation status is available during enterprise evaluation.
Authentication and access
- Access via email and password, with optional additional factor verification (MFA). Passwordless access via one-time magic link, valid 15 minutes, is also available.
- SSO/SAML (Enterprise): on the roadmap; available via custom evaluation — not a standard self-serve feature.
- Optional 2FA on Professional plan, mandatory on Enterprise plan.
Sovereignty Scale
| Model | Plan | Data residency | Control |
|---|---|---|---|
| Managed (provider-declared EU regions) | Free / Starter / Pro | Atlas eu-south-1 configured (UNKNOWN until proven) | Standard |
| BYOC (roadmap / custom) | Enterprise (evaluate) | Customer-controlled (if offered) | Custom |
| Single-tenant (roadmap / custom) | Enterprise (evaluate) | Dedicated tenant (if offered) | Custom |
BYOC and single-tenant options are on the roadmap; contact Enterprise for custom evaluation.
Compliance Roadmap
Our path toward third-party attestations. Self-assessed items reflect the current internal posture; certifications in progress are subject to independent audit.
| Certification | Status | Target |
|---|---|---|
| SOC 2 Type I | Not certified — no audit completed | — |
| ISO 27001 | Not certified — ISO/IEC 27001 reference | — |
| DORA Compliance | Self-assessed (roadmap) | Ongoing |
| EU AI Act | Self-assessed (roadmap) | Ongoing |
Vendor Security Assessment
A pre-filled Vendor Security Assessment Questionnaire (VSAQ) is available for procurement evaluations and vendor onboarding.
Data Processing Agreement
Download our standard DPA (template v1.0) for your legal team to review before signing any MSA.
Security architecture
- No dedicated per-tenant compute is claimed.
- The Evidence Pack™ hash is computed server-side with SHA-256 hash chaining.
- No training on customer data.
- Audit log retention for 7 years (DORA Art. 17).
Responsible AI commitments
- The Validator runs blind and prevents groupthink by design.
- Every HALT is logged with the full Dissent Record.
- The confidence score is always visible, no black-box output.
Trust posture
Quvant does not claim certifications it does not hold.
- DPA covering GDPR Art. 28 processor obligations, ready to signlive
/legal/dpa-v1.0.md (downloaded from /security)
Verify this claim - EU AI Act Art. 9 self-assessment completedself-assessed
/security#responsible-ai
Verify this claim - SHA-256 hash-chainedlive
deliberation_engine.py; verify_chain in evidence_chain.py
Verify this claim - No training on customer datalive
/security#security-architecture
Verify this claim - Audit log retention 7 years (DORA Art. 17)live
DORA Art.17, /security#security-architecture
Verify this claim - SOC 2 Type II sub-processors (Railway, Vercel, Resend)via provider
/legal/subprocessors (Railway, Vercel SOC2 TypeII, Resend)
Verify this claim - SHA-256 hash-chainedlive
trust/evidence-manifest-spec.md, backend/app/services/evidence_manifest.py, backend/app/services/evidence_chain.py (verify_chain)
Verify this claim - ISO/IEC 27001 referencecontrol reference
landing/app/[locale]/security/page.tsx, landing/app/[locale]/trust/page.tsx
Verify this claim - No SOC 2 audit completedin progress
landing/app/[locale]/security/page.tsx#compliance
Verify this claim - Blind Validatorlive
trust/claims.yaml#architecture, backend/app/services/deliberation_engine.py
Verify this claim - Decision Support System, the final decision is humanlive
landing/app/[locale]/trust/page.tsx#dss, trust/claims.yaml#legal_framing
Verify this claim
Every claim above is recorded in our Trust Ledger and verified automatically in CI: the site shows only what is provable. The same principle as the Evidence Pack™, applied to our own marketing.
Frequently asked questions
- Do incident data leave the EU?
- Primary storage is configured on MongoDB Atlas with a provider-declared AWS EU region (eu-south-1); this is not an instrumental guarantee that data never leaves the EEA. Some LLM inference involves extra-EEA subprocessors; where transfers apply they are covered by DPA/SCC and disclosed. On Enterprise with a dedicated tenant, localization is contractually configurable. Do not treat 'no data leaves the EU' as a product guarantee without instrumental proof.
- Is Quvant ISO 27001 certified?
- Security controls are designed with reference to ISO/IEC 27001. Quvant holds no ISO 27001 certificate and has not completed a SOC 2 audit.
Demonstrable control, from your first analysis.
Evaluate Quvant on your data and verify every piece of evidence before proposing the budget.