Security overview

How we handle your systems, your data, and our own product.

The short version, for anyone deciding whether to talk to us. Component-level architecture, control scope, assessment evidence, and configuration detail are shared with qualified parties during diligence, under agreement.

In client engagements

Authorized, minimal, recorded.

Authorization
All work is authorized defensive work. Adversarial modules run only under written scope with named systems, approved test identities, stop conditions, and evidence-handling rules. We do not test systems we are not contracted to test. The template we sign.
Access
Only what the rules of engagement list. Work starts passive: architecture, configuration, logs, and telemetry. Anything not listed is out of scope.
Your data and secrets
Minimum proof only. Secrets are shown as an identifier or last four characters. Evidence goes to storage you approve, with a classification, encryption method, and retention period written into the rules of engagement. No third-party AI service receives your data unless you approve it in writing.
What we publish
Nothing about a client without written consent. Client names, outcomes, and case studies are not published.
In qore

Where the boundary is, and what is not there yet.

Inside your boundary
Model inference, retrieval, agent memory, and audit records stay on the host. There is no hosted model, no analytics, and no update check in the product. Optional enrichment tools reach outside only when an administrator enables them.
Identity and policy
Named accounts or OpenID Connect sign-in with an enforced second factor. Roles and deny-wins policies over who may run which agents with which tools, with every decision recorded. Enforcement is switched on by an administrator; it ships in audit mode.
Encryption
Agent memory, retrieval stores, and canvases are encrypted at rest. License tokens and export bundles use post-quantum algorithms with signatures verified on import. Other components, including the forensic log's key wrapping and artifact signing, use classical cryptography today and are on the migration list. Transport is the TLS your reverse proxy terminates.
Records
Every access decision and agent run is recorded. The operational log is hash-chained with sealed checkpoints; the forensic log is encrypted and checksummed but not yet chained or signed, and has no export route yet.
Not yet
No third-party assessment, penetration-test summary, SOC 2 report, or validated cryptographic module exists. Compliance references on this site mean alignment or design intent, never certification. A validated hardware matrix is not published.

Limitations to plan a pilot around

Report a vulnerability

In qore, or in this website.

Use the support route and mark the message as a security report. Describe the class of issue; do not include exploit details, secrets, or sensitive data in the first message. We acknowledge within two business days and agree a disclosure timeline with you. No advisories have been published to date.

Report an issue

Qualified diligence

The detail, under agreement.

Component-level architecture, security-control scope and deployment assumptions, compatibility and performance methodology with the measurements behind it, control mappings, licensing and continuity terms, and detailed direction are shared with evaluators before a decision, under an agreement that fits the conversation.