Quantum treats security as engagement-specific operating work. This page describes the current procurement approach without claiming a certification, audit, or control that is not evidenced.
Before a pilot
Fit and scope identifies the business owner, data, systems, integrations, model providers, countries, legal requirements, success measure, and the security decisions that can block production use.
Access and infrastructure
Repository location, cloud ownership, account access, secrets, environments, backups, review, logging, and offboarding are agreed for each engagement. This public website does not promise customer-controlled accounts or a particular control framework unless the signed scope says so.
Data handling
The engagement data map records what data enters the system, where it moves, which providers process it, who can access it, and what retention and deletion decisions apply. A DPA or transfer terms are agreed where the parties determine they are required.
AI systems
Evaluation, guardrails, human checkpoints, failure behavior, cost controls, and observability are scoped around the use case. Model-provider terms and any customer-data training setting must be reviewed for the selected provider rather than assumed from generic marketing language.
Incident and questionnaires
Incident contacts, notice expectations, responsibilities, and security-questionnaire support are set in the engagement terms. The current public site does not claim 24/7 monitoring, an SLA, or penetration testing.
Claims not made
Quantum does not claim SOC 2, ISO 27001, HIPAA compliance, GDPR compliance, EU hosting, 24/7 support, a standard SLA, or independent penetration testing on this site.
Contact and disclosures
Security questions can be sent to admin@quantumai-solutions.com. See DPA, Subprocessors, and Data retention and deletion.
