Docs · FAQ

AI governance & evidence — direct answers

The questions buyers, security reviewers, and auditors actually ask — answered the way Quantlix answers everything: evidence, never verdicts.

Can software perform or issue a SOC 2 report?

No. A SOC 2 report can only be performed and issued by a licensed CPA firm under AICPA standards — no software platform can attest, including Quantlix. What software can do is produce the evidence the auditor samples. Quantlix produces the runtime evidence for the AI slice of a SOC 2 examination: boundary enforcement, monitoring, change management, processing integrity, and confidentiality records captured per request on gatewayed AI traffic.

SOC 2 runtime evidence

What SOC 2 evidence can Quantlix produce for AI systems?

Nine Trust Services Criteria groups map to the AI runtime, honesty-tagged: runtime-evidenced where a stored field backs the criterion (system boundaries CC6.6–6.7, monitoring CC7.1–7.2, change management CC8.1, processing integrity PI1, confidentiality C1), mixed where runtime records meet an attested process (incident management, availability), and requires-attestation where the judgment is organizational (the access review, risk and vendor programs). A SOC 2 audit bundle adds a criterion-mapping section a CPA firm's workpapers can cite.

The full criterion mapping

Does Quantlix replace Vanta, Drata, or Secureframe?

No — it complements them. A readiness platform covers the organization: laptops, people, policies, org-wide controls. It cannot see inside AI runtime traffic. Quantlix evidences that slice — the requests, redactions, policy decisions, and approvals on gatewayed AI traffic. Two different evidence surfaces, one audit; HR, endpoints, physical security, BCP, and org-wide vendor management remain readiness-platform territory, and Quantlix states that boundary in the product and in every SOC 2 bundle.

Does Quantlix make my company EU AI Act compliant?

No platform can. Compliance determinations require qualified legal counsel and, for certain high-risk systems, a conformity assessment by a notified body. Quantlix produces runtime readiness evidence: enforcement records with pinned policy versions (Art. 9), redaction events (Art. 10), hash-chained record-keeping (Art. 12), approval gates and stop controls (Art. 14), and adversarial-input detection (Art. 15). Its status language is deliberate — evidence captured, controls active — never compliant.

EU AI Act readiness evidence

How do auditors verify Quantlix evidence without trusting Quantlix?

Every CSV and PDF audit-bundle export ships with bundle.json, HOW_TO_VERIFY.txt, and a standalone verify_audit_bundle.py script. The script recomputes the manifest content digest and, where trace-chain anchoring is active, confirms segment Merkle roots against the public Sigstore Rekor transparency log — no Quantlix software, account, or API access required.

How proof works

Can Quantlix govern AI coding assistants like Claude Code?

Yes — the gateway is OpenAI- and Anthropic-compatible, so coding assistants (Claude Code, Codex CLI, IDE extensions) route through the control plane with one API key per developer. Policy is enforced before the provider sees the prompt, blocked and redacted events are recorded per request, and by default only decision-level records are retained — developer prompts are not persisted unless explicitly opted in.

Integrations

Is Quantlix itself SOC 2 certified?

Not yet, and we say so plainly: SOC 2 Type II preparation is underway, the observation window opens November 2026, and the report follows the examination, available under NDA. We deliberately skipped Type I. Meanwhile, EU-hosted and self-hosted deployment options shrink the vendor-risk surface a security review must assess.

Trust center

Capabilities described as of August 2026. Not legal advice, an attestation, or a compliance assessment. SOC 2 reports are issued exclusively by licensed CPA firms; EU AI Act conformity determinations require qualified counsel.

AI Governance & Evidence FAQ — Quantlix — Quantlix