Security and data control

Security alone is not enough. Enterprise organizations require demonstrable control: over every access, every analysis, every output. Quvant is designed for this.

Where your data lives

Analysis data is stored on MongoDB Atlas, AWS eu-south-1 (Milan), EEA, within the European Economic Area. Encrypted at rest, 3-node replica set for high availability, automated continuous backup with point-in-time recovery. Application infrastructure operates in the EU on Railway EU West (Amsterdam). Transfers to extra-EEA LLM sub-processors, where applicable, are governed by DPA/SCC and disclosed in the sub-processor list; we do not claim absence of extra-EU transfers without instrumental proof per workload.

Each customer operates in a logically isolated space. Analyses, evidence packs, and logs of one organization are never accessible to another.

Enterprise plan: BYOC (Bring Your Own Cloud) on roadmap H2 2026 — analysis execution within the customer's own cloud, with full control over data residency and access.

Proof

  • AWS region in the EEA
  • Encryption at rest
  • Multi-tenant isolation

Audit trail and SHA-256 hash-chain

Evidence records are SHA-256 hash-chained to make subsequent alteration detectable. An independent digital signature is not currently applied.

RFC 3161 TSA (Enterprise): exported PDF evidence is RFC 3161 timestamped by an external Time Stamp Authority — verifiable by third-party auditors with no dependency on Quvant. Broader evidence-pack manifest anchoring is on the roadmap.

Proof

  • Vault SHA-256
  • Audit trail append-only
  • SHA-256 hash-chain

Compliance and certifications

  • GDPR: we process data necessary to deliver the service under a legal basis and DPA; we do not declare 'no personal data by design' as an absolute guarantee.
  • The underlying MongoDB Atlas infrastructure is SOC 2 and ISO 27001 certified (Atlas sub-processor certifications, not Quvant's).
  • Security controls are designed with reference to ISO/IEC 27001. Quvant holds no ISO 27001 certificate and has not completed a SOC 2 audit.
  • Security controls are designed with reference to ISO/IEC 27001. Quvant holds no ISO 27001 certificate and has not completed a SOC 2 audit.

Proof

  • GDPR · DPA / SCC
  • Atlas SOC 2 · ISO 27001

Authentication and access

  • Access via email and password, with optional additional factor verification (MFA). Passwordless access via one-time magic link, valid 15 minutes, is also available.
  • SSO/SAML for Enterprise plan: in implementation Q3 2026.
  • Optional 2FA on Professional plan, mandatory on Enterprise plan.

Proof

  • One-time magic link
  • 2FA on Professional/Enterprise
  • SSO/SAML, Q3 2026

Sovereignty Scale

ModelPlanData residencyControl
Managed EUFree / Starter / ProEEA (AWS region)Standard
BYOC, on roadmap H2 2026EnterpriseCustomer's cloudFull
Single-tenant, on roadmapEnterprise+Dedicated tenantMaximum

BYOC and single-tenant options are on the roadmap and available on the Enterprise plan.

Compliance Roadmap

Our path toward third-party attestations. Self-assessed items reflect the current internal posture; certifications in progress are subject to independent audit.

CertificationStatusTarget
SOC 2 Type INot certified — no audit completed
ISO 27001Not certified — ISO/IEC 27001 reference
DORA ComplianceSelf-assessed (roadmap)Ongoing
EU AI ActSelf-assessed (roadmap)Ongoing

Vendor Security Assessment

A pre-filled Vendor Security Assessment Questionnaire (VSAQ) is available for procurement evaluations and vendor onboarding.

Data Processing Agreement

Download our standard DPA (template v1.0) for your legal team to review before signing any MSA.

Security architecture

  • Per-tenant isolated inference in dedicated containers.
  • The Evidence Pack™ hash is computed server-side with SHA-256 hash chaining.
  • No training on customer data.
  • Audit log retention for 7 years (DORA Art. 17).

Responsible AI commitments

  • The Validator runs blind and prevents groupthink by design.
  • Every HALT is logged with the full Dissent Record.
  • The confidence score is always visible, no black-box output.

Trust posture

No declared certifications we can't prove. Each item shows its real status.

  • GDPR Art. 28 compliant DPA, ready to signlive
  • DORA-ready architecturelive
  • EU AI Act Art. 9 self-assessment completedself-assessed
  • SHA-256 hash-chainedlive
  • No training on customer datalive
  • Audit log retention 7 years (DORA Art. 17)live
  • Security controls designed with reference to ISO/IEC 27001 — not certifiedcontrol reference
  • SOC 2 Type II sub-processors (Railway, Vercel, Resend)via provider
  • SHA-256 hash-chainedlive
  • Security controls designed with reference to ISO/IEC 27001 — not certifiedin progress
  • No SOC 2 audit completedin progress
  • Blind Validator, prevents groupthink by designlive
  • Decision Support System, the final decision is humanlive

Every claim above is recorded in our Trust Ledger and verified automatically in CI: the site shows only what is provable. The same principle as the Evidence Pack™, applied to our own marketing.

Frequently asked questions

Do incident data leave the EU?
Primary storage is on MongoDB Atlas in an AWS region within the EEA. Some LLM inference may involve extra-EEA subprocessors; where transfers apply they are covered by DPA/SCC and disclosed. On Enterprise with a dedicated tenant, localization is contractually configurable. Do not treat 'no data leaves the EU' as a product guarantee without instrumental proof.
Is Quvant ISO 27001 certified?
Security controls are designed with reference to ISO/IEC 27001. Quvant holds no ISO 27001 certificate and has not completed a SOC 2 audit.

Demonstrable control, from your first analysis.

Evaluate Quvant on your data and verify every piece of evidence before proposing the budget.