SOC 2 Type 1
In progressControl design and operating evidence collection underway. Report available under NDA after completion.
Request audit report →Procurement and security-review checklist — what is in place today, what is in progress, and what is on the roadmap. Quantlix is not SOC 2 or ISO 27001 certified today.
Readiness, not legal compliance
Quantlix provides runtime policy enforcement and exportable evidence on supported production paths to help teams build EU AI Act readiness and broader AI governance workflows. It is not legal advice, a conformity assessment, CE marking, or a guarantee of regulatory compliance. Risk classification, DPIAs, and legal interpretation remain your responsibility.
Control design and operating evidence collection underway. Report available under NDA after completion.
Request audit report →Information security management system certification planned after SOC 2 Type 1.
Data subject export, deactivation, and erasure flows with audit logging. Standard DPA available.
Data Processing Agreement →Managed Quantlix cloud runs on EU infrastructure (Hetzner). Self-hosted Kubernetes available for stricter boundaries.
SOC 2 Type 1 examination is in progress. Report available under NDA after completion — register interest.
Managed Quantlix cloud runs on EU infrastructure (Hetzner). Self-hosted Kubernetes available for stricter boundaries. Quantlix is operated by Navego AB, Stockholm, Sweden.
AUDIT_SIGNING_KEY is configured.Technical reference: Security & compliance docs.
Report vulnerabilities: responsible disclosure or security@quantlix.ai.
Data Processing Agreement → · Full subprocessor list · JSON API
| Party | Role | Regions | Data categories | Notes |
|---|---|---|---|---|
| Source code hosting and CI | US, EU | source_code, ci_metadata | — | |
| Cloud infrastructure (managed Quantlix hosting) | EU | customer_payloads, operational_logs, account_metadata | — | |
Model providers you configure Customer-configured | Inference (OpenAI, Anthropic, Azure OpenAI, Bedrock, etc.) | varies | prompts, completions, embeddings | Customer-selected; data flows per deployment provider binding and DPA. |
| Secondary blockchain timestamp for trace chain Merkle roots | global | sha256_merkle_root_digests | Optional redundancy alongside Rekor; digest-only submissions. | |
| Transparency log for trace chain Merkle roots (hashedrekord; digest only) | US, EU | sha256_merkle_root_digests | Enterprise trace chain anchoring when TRACE_CHAIN_ANCHOR_ENABLED is on. No tenant identifiers in public log entries. | |
| Payment processing and billing | EU, US | billing_pii, payment_metadata | — | |
| Customer-configured | Embeddings and semantic retrieval | US | text_for_embedding | Only when used for RAG or semantic cache. |
Quantlix's tamper-evident trace model gives security and audit teams independently verifiable runtime records — without asking reviewers to trust our word alone.
@quantlix/verify CLI — verify integrity proofs without Quantlix API credentials.HOW_TO_VERIFY.txt).Cryptographic chaining attests to ledger continuity, not business truth or legal compliance. Pre-cutover events may be marked pre-chain and are outside the ledger.
Security questionnaires & reviews
Email security@quantlix.ai for procurement packs. General product questions: support@quantlix.ai.