SOC 2 Type 1
In progressControl design and operating evidence collection underway. Report available under NDA after completion.
Request audit report →Quantlix · Trust center
Security, compliance posture, and data-flow transparency for procurement and security reviews.
Readiness, not legal compliance
Quantlix provides runtime policy enforcement and exportable evidence on supported production paths to help teams build EU AI Act readiness and broader AI governance workflows. It is not legal advice, a conformity assessment, CE marking, or a guarantee of regulatory compliance. Risk classification, DPIAs, and legal interpretation remain your responsibility.
Control design and operating evidence collection underway. Report available under NDA after completion.
Request audit report →Information security management system certification planned after SOC 2 Type 1.
Data subject export, deactivation, and erasure flows with audit logging. Standard DPA available.
Data Processing Agreement →Managed Quantlix cloud runs on EU infrastructure (Hetzner). Self-hosted Kubernetes available for stricter boundaries.
Encryption, access, incidents, and vulnerability management for reviewers.
Live list of infrastructure and service providers.
Current operational status of Quantlix services.
Report vulnerabilities to our security team.
Download our standard DPA or request execution.
Request SOC 2 evidence when available.
| Party | Role | Regions | Data categories | Notes |
|---|---|---|---|---|
| Source code hosting and CI | US, EU | source_code, ci_metadata | — | |
| Cloud infrastructure (managed Quantlix hosting) | EU | customer_payloads, operational_logs, account_metadata | — | |
Model providers you configure Customer-configured | Inference (OpenAI, Anthropic, Azure OpenAI, Bedrock, etc.) | varies | prompts, completions, embeddings | Customer-selected; data flows per deployment provider binding and DPA. |
| Payment processing and billing | EU, US | billing_pii, payment_metadata | — | |
| Customer-configured | Embeddings and semantic retrieval | US | text_for_embedding | Only when used for RAG or semantic cache. |
Company & hosting
Quantlix is operated by Navego AB, Lillängsvägen 21, 131 41 Nacka, Stockholm, Sweden.
Questions for security or compliance reviews: security@quantlix.ai