Security at Quaneuron
This page outlines our high-level security posture and operational practices. It is intentionally non-technical and may evolve over time. For security questions or reports, email hello@quaneuron.com.
We reduce risk by collecting less
Quaneuron never stores your prompts or model outputs. We track cost, latency, errors, and patterns — not your data. Less sensitive data collected means less sensitive data to protect.
Principles
- Least privilege: access is limited to authorized users and necessary roles.
- Defense in depth: multiple layers of controls reduce single points of failure.
- Minimize sensitive data: avoid collecting or retaining what you don’t need.
- Transparency: clear, high-level policies and a direct path to reach us.
Data protection
We use standard safeguards to protect customer data and limit access. Security controls evolve as the product matures, but the baseline approach is consistent: keep data scoped to a workspace, restrict access, and log important actions.
- Encryption in transit: TLS for traffic between your systems and Quaneuron.
- Access controls: workspace-based permissions and authentication.
- Auditability: key changes and access events are logged where practical.
- Separation of concerns: production data access is restricted to required operational needs.
Operational security
We aim for sane operational practices that reduce breach and misconfiguration risk.
- Secure defaults: conservative settings and minimal exposure by default.
- Dependency hygiene: regular updates and monitoring for high-impact vulnerabilities.
- Environment separation: separate dev/staging/production workflows where practical.
Incident handling
We take security reports seriously. If you believe you have found a vulnerability or suspect a security issue, contact us promptly at hello@quaneuron.com.
- Include steps to reproduce (if applicable) and any supporting details.
- Please avoid sharing sensitive data in email when possible.
Partner and portfolio use
For accelerators, incubators, and investors, Quaneuron is intended to be founder-friendly. Teams control what is shared externally, and partners typically rely on trends and aggregates rather than raw event streams.