SECURITY

Security

How we protect your data and systems

01INFRASTRUCTURE

Infrastructure

QuantumVerifi runs on hardened cloud infrastructure with security built into every layer.

All communication encrypted via TLS 1.3 (HTTPS everywhere)
Data encrypted at rest using AES-256
Infrastructure hosted in UK data centres with Cloudflare edge protection
DDoS mitigation and Web Application Firewall (WAF) via Cloudflare
Container images scanned for vulnerabilities before deployment
02EXECUTION ISOLATION

Execution isolation

All test generation and execution runs in fully isolated sandbox environments.

Each analysis runs in a dedicated, ephemeral container with no shared state
Sandboxes are destroyed immediately after execution completes
Network access is restricted — sandboxes cannot reach internal infrastructure
Resource limits (CPU, memory, time) enforced per sandbox
Six sandbox providers available including microVM isolation for high-security workloads
03MULTI-TENANT ISOLATION

Multi-tenant isolation

QuantumVerifi is a multi-tenant platform with strict data isolation between customers.

Row-level security (RLS) enforced at the database layer — queries are scoped to your tenant
Per-tenant API keys with scoped permissions
Organisation-level role-based access control (Owner, Admin, Member, Viewer)
Audit logging for sensitive operations
Per-tenant model adapters are isolated — your training data is never shared
04AUTHENTICATION

Authentication

Authentication managed by Clerk with OAuth 2.0 (Google, Microsoft, GitHub)
JWT-based session tokens with automatic rotation
API key authentication available for programmatic access
No passwords stored — delegated entirely to identity providers
05COMPLIANCE EVIDENCE

Compliance evidence

For regulated industries, QuantumVerifi provides tamper-evident compliance records.

SHA-256 hashed evidence chains linking every test execution event
Canonical JSON serialisation ensures tamper detection
Compliance reports available in JSON, HTML, and PDF formats
Five report types: test execution, coverage, security, evidence chain, end-of-test audit
06DATA HANDLING

Data handling

Source code is cloned temporarily during analysis and is not stored permanently
Analysis results are retained for 90 days, then automatically purged
We do not use your code to train general-purpose AI models
Payment data is handled entirely by Stripe — we never see card details
Full data export and account deletion available under GDPR Articles 17 and 20
07RESPONSIBLE DISCLOSURE

Responsible disclosure

We take security seriously. If you discover a vulnerability in QuantumVerifi, please report it responsibly. We will investigate promptly and keep you informed.

Report vulnerabilities to: [email protected]

Please include a description, reproduction steps, and potential impact
Do not publicly disclose vulnerabilities until we have had reasonable time to address them
We will acknowledge receipt within 48 hours
08CONTACT

Contact

QuantumLayer Platform Ltd (Company No. 16381947)
86-90 Paul Street, London, EC2A 4NE

Security: [email protected]
Privacy: [email protected]

← Back to homeTrust Centre →