Security and data control
Security alone is not enough. Enterprise organizations require demonstrable control: over every access, every analysis, every output. Quvant is designed for this.
Where your data lives
Analysis data is stored on MongoDB Atlas, AWS eu-south-1 (Milan), EEA, within the European Economic Area. Encrypted at rest, 3-node replica set for high availability, automated continuous backup with point-in-time recovery. Application infrastructure operates in the EU on Railway EU West (Amsterdam). Transfers to extra-EEA LLM sub-processors, where applicable, are governed by DPA/SCC and disclosed in the sub-processor list; we do not claim absence of extra-EU transfers without instrumental proof per workload.
Each customer operates in a logically isolated space. Analyses, evidence packs, and logs of one organization are never accessible to another.
Enterprise plan: BYOC (Bring Your Own Cloud) on roadmap H2 2026 — analysis execution within the customer's own cloud, with full control over data residency and access.
Proof
- AWS region in the EEA
- Encryption at rest
- Multi-tenant isolation
Audit trail and SHA-256 hash-chain
Evidence records are SHA-256 hash-chained to make subsequent alteration detectable. An independent digital signature is not currently applied.
RFC 3161 TSA (Enterprise): exported PDF evidence is RFC 3161 timestamped by an external Time Stamp Authority — verifiable by third-party auditors with no dependency on Quvant. Broader evidence-pack manifest anchoring is on the roadmap.
Proof
- Vault SHA-256
- Audit trail append-only
- SHA-256 hash-chain
Compliance and certifications
- GDPR: we process data necessary to deliver the service under a legal basis and DPA; we do not declare 'no personal data by design' as an absolute guarantee.
- The underlying MongoDB Atlas infrastructure is SOC 2 and ISO 27001 certified (Atlas sub-processor certifications, not Quvant's).
- Security controls are designed with reference to ISO/IEC 27001. Quvant holds no ISO 27001 certificate and has not completed a SOC 2 audit.
- Security controls are designed with reference to ISO/IEC 27001. Quvant holds no ISO 27001 certificate and has not completed a SOC 2 audit.
Proof
- GDPR · DPA / SCC
- Atlas SOC 2 · ISO 27001
Authentication and access
- Access via email and password, with optional additional factor verification (MFA). Passwordless access via one-time magic link, valid 15 minutes, is also available.
- SSO/SAML for Enterprise plan: in implementation Q3 2026.
- Optional 2FA on Professional plan, mandatory on Enterprise plan.
Proof
- One-time magic link
- 2FA on Professional/Enterprise
- SSO/SAML, Q3 2026
Sovereignty Scale
| Model | Plan | Data residency | Control |
|---|---|---|---|
| Managed EU | Free / Starter / Pro | EEA (AWS region) | Standard |
| BYOC, on roadmap H2 2026 | Enterprise | Customer's cloud | Full |
| Single-tenant, on roadmap | Enterprise+ | Dedicated tenant | Maximum |
BYOC and single-tenant options are on the roadmap and available on the Enterprise plan.
Compliance Roadmap
Our path toward third-party attestations. Self-assessed items reflect the current internal posture; certifications in progress are subject to independent audit.
| Certification | Status | Target |
|---|---|---|
| SOC 2 Type I | Not certified — no audit completed | — |
| ISO 27001 | Not certified — ISO/IEC 27001 reference | — |
| DORA Compliance | Self-assessed (roadmap) | Ongoing |
| EU AI Act | Self-assessed (roadmap) | Ongoing |
Vendor Security Assessment
A pre-filled Vendor Security Assessment Questionnaire (VSAQ) is available for procurement evaluations and vendor onboarding.
Data Processing Agreement
Download our standard DPA (template v1.0) for your legal team to review before signing any MSA.
Security architecture
- Per-tenant isolated inference in dedicated containers.
- The Evidence Pack™ hash is computed server-side with SHA-256 hash chaining.
- No training on customer data.
- Audit log retention for 7 years (DORA Art. 17).
Responsible AI commitments
- The Validator runs blind and prevents groupthink by design.
- Every HALT is logged with the full Dissent Record.
- The confidence score is always visible, no black-box output.
Trust posture
No declared certifications we can't prove. Each item shows its real status.
- GDPR Art. 28 compliant DPA, ready to signlive
/legal/dpa-v1.0.md (downloaded from /security)
Verify this claim - DORA-ready architecturelive
/security#security-architecture
Verify this claim - EU AI Act Art. 9 self-assessment completedself-assessed
/security#responsible-ai
Verify this claim - SHA-256 hash-chainedlive
deliberation_engine.py; verify_chain in evidence_chain.py
Verify this claim - No training on customer datalive
/security#security-architecture
Verify this claim - Audit log retention 7 years (DORA Art. 17)live
DORA Art.17, /security#security-architecture
Verify this claim - Security controls designed with reference to ISO/IEC 27001 — not certifiedcontrol reference
Annex A mapping in progress; no certificate
Verify this claim - SOC 2 Type II sub-processors (Railway, Vercel, Resend)via provider
/legal/subprocessors (Railway, Vercel SOC2 TypeII, Resend)
Verify this claim - SHA-256 hash-chainedlive
trust/evidence-manifest-spec.md, backend/app/services/evidence_manifest.py, backend/app/services/evidence_chain.py (verify_chain)
Verify this claim - Security controls designed with reference to ISO/IEC 27001 — not certifiedin progress
landing/app/[locale]/security/page.tsx, landing/app/[locale]/trust/page.tsx
Verify this claim - No SOC 2 audit completedin progress
landing/app/[locale]/security/page.tsx#compliance
Verify this claim - Blind Validator, prevents groupthink by designlive
trust/claims.yaml#architecture, backend/app/services/deliberation_engine.py
Verify this claim - Decision Support System, the final decision is humanlive
landing/app/[locale]/trust/page.tsx#dss, trust/claims.yaml#legal_framing
Verify this claim
Every claim above is recorded in our Trust Ledger and verified automatically in CI: the site shows only what is provable. The same principle as the Evidence Pack™, applied to our own marketing.
Frequently asked questions
- Do incident data leave the EU?
- Primary storage is on MongoDB Atlas in an AWS region within the EEA. Some LLM inference may involve extra-EEA subprocessors; where transfers apply they are covered by DPA/SCC and disclosed. On Enterprise with a dedicated tenant, localization is contractually configurable. Do not treat 'no data leaves the EU' as a product guarantee without instrumental proof.
- Is Quvant ISO 27001 certified?
- Security controls are designed with reference to ISO/IEC 27001. Quvant holds no ISO 27001 certificate and has not completed a SOC 2 audit.
Demonstrable control, from your first analysis.
Evaluate Quvant on your data and verify every piece of evidence before proposing the budget.