01INFRASTRUCTURE
Infrastructure
QuantumVerifi runs on hardened cloud infrastructure with security built into every layer.
—All communication encrypted via TLS 1.3 (HTTPS everywhere)
—Data encrypted at rest using AES-256
—Infrastructure hosted in UK data centres with Cloudflare edge protection
—DDoS mitigation and Web Application Firewall (WAF) via Cloudflare
—Container images scanned for vulnerabilities before deployment
02EXECUTION ISOLATION
Execution isolation
All test generation and execution runs in fully isolated sandbox environments.
—Each analysis runs in a dedicated, ephemeral container with no shared state
—Sandboxes are destroyed immediately after execution completes
—Network access is restricted — sandboxes cannot reach internal infrastructure
—Resource limits (CPU, memory, time) enforced per sandbox
—Six sandbox providers available including microVM isolation for high-security workloads
03MULTI-TENANT ISOLATION
Multi-tenant isolation
QuantumVerifi is a multi-tenant platform with strict data isolation between customers.
—Row-level security (RLS) enforced at the database layer — queries are scoped to your tenant
—Per-tenant API keys with scoped permissions
—Organisation-level role-based access control (Owner, Admin, Member, Viewer)
—Audit logging for sensitive operations
—Per-tenant model adapters are isolated — your training data is never shared
04AUTHENTICATION
Authentication
—Authentication managed by Clerk with OAuth 2.0 (Google, Microsoft, GitHub)
—JWT-based session tokens with automatic rotation
—API key authentication available for programmatic access
—No passwords stored — delegated entirely to identity providers
05COMPLIANCE EVIDENCE
Compliance evidence
For regulated industries, QuantumVerifi provides tamper-evident compliance records.
—SHA-256 hashed evidence chains linking every test execution event
—Canonical JSON serialisation ensures tamper detection
—Compliance reports available in JSON, HTML, and PDF formats
—Five report types: test execution, coverage, security, evidence chain, end-of-test audit
06DATA HANDLING
Data handling
—Source code is cloned temporarily during analysis and is not stored permanently
—Analysis results are retained for 90 days, then automatically purged
—We do not use your code to train general-purpose AI models
—Payment data is handled entirely by Stripe — we never see card details
—Full data export and account deletion available under GDPR Articles 17 and 20
07RESPONSIBLE DISCLOSURE
Responsible disclosure
We take security seriously. If you discover a vulnerability in QuantumVerifi, please report it responsibly. We will investigate promptly and keep you informed.
Report vulnerabilities to: [email protected]
—Please include a description, reproduction steps, and potential impact
—Do not publicly disclose vulnerabilities until we have had reasonable time to address them
—We will acknowledge receipt within 48 hours
08CONTACT
Contact
QuantumLayer Platform Ltd (Company No. 16381947)
86-90 Paul Street, London, EC2A 4NE
Security: [email protected]
Privacy: [email protected]