Skip to content
SECURITY & COMPLIANCE

The deployment model is the security model.

Qeino runs inside your perimeter. Source code, telemetry and model weights do not leave the building. Air-gapped, on-premises, or EU-sovereign — your choice, evidenced in the deployment itself, not asserted in a policy document.

01 — DEPLOYMENT SECURITY

Data never leaves the perimeter.

The architecture is the control. Qeino is delivered as a private instance that runs inside the customer's network. Inbound read access only. No outbound channel to a vendor cloud. No telemetry phone-home.

Perimeter deployment — read-only inputs, no egress.
  • Air-gapped deploymentStatus: Verified — Customer perimeter, no egress
  • On-premises deploymentStatus: Verified — Customer hardware
  • EU-sovereign hostingStatus: Verified — When customer-managed cloud
  • Customer-controlled keysStatus: Verified — BYOK, HSM-backed
02 — DATA HANDLING

What is read. What is never touched.

Qeino reads engineering process signals. It does not read customer data, end-user data or production telemetry. The surface is documented and narrow by design.

READ — INSIDE THE PERIMETER
  • Source code repositories
    Read-only metadata. Never copied outside the perimeter.
  • CI / delivery pipelines
    Build, test and deployment events. Read-only.
  • Issue tracker (Jira, Azure DevOps)
    Ticket metadata, transitions, timestamps. Read-only.
  • Chat (Slack, Teams) — engineering channels
    Optional. Channel allow-list. Read-only.
NEVER TOUCHED
  • Production telemetry
    Not read. Not required.
  • Customer or end-user data
    Never read. Never touched.
  • Model weights and proprietary code
    Never exfiltrated. Stays inside the perimeter.
  • Identity systems beyond SSO claims
    Not read.
03 — CERTIFICATION ROADMAP

Evidenced, not asserted.

A calm, dated roadmap. We publish what is in place, what is in progress, and what is scheduled. Status is shown by icon and label — never by colour alone.

ItemStatusTargetNote
Independent penetration testStatus: In placeAnnual cadenceReport available under NDA
Vulnerability disclosure programmeStatus: In placeContinuousSee /.well-known/security.txt
SOC 2 Type IIStatus: In progress2027Controls implemented; observation window in progress
ISO 27001Status: Scheduled2027–2028Aligned to ISO 27001:2022 controls
Source-code escrowStatus: In placeOn requestIndependent escrow agent, customer-triggered release conditions
Certification timeline — dated, conservative, never aspirational.
04 — COMPLIANCE POSTURE

Counsel-reviewed positions.

The positions below are counsel-reviewed. Detailed memoranda are available under NDA. Qeino is not legal advice; we work with your compliance and legal teams.

EU AI ACT

Qeino is deployed as a private-instance system inside the customer's perimeter. Counsel-reviewed positioning available under NDA.

NIS2

Air-gapped and on-prem deployment options support obligations on supply-chain risk, access control and incident reporting.

MDR (MEDICAL DEVICES)

For medical-device manufacturers: Qeino does not touch device firmware, patient data or production telemetry. Read-access scope documented for technical files.

DORA

Financial-services deployments are designed for ICT third-party risk requirements, with escrow and exit provisions.

05 — VENDOR STABILITY

Continuity, in writing.

Sovereign deployments outlast vendors. We document continuity in writing, not in marketing.

SOURCE-CODE ESCROW

Independent escrow agent holds a current build of the Qeino platform and deployment runbooks. Release conditions are agreed in the customer contract — typically insolvency, material breach, or sustained failure to maintain the platform.

FINANCIAL-VIABILITY PACK

A financial-viability pack — cap table, runway, banking, governance — is available under NDA to procurement and risk teams. We send it before contracting, not after.

"Security is not a feature you bolt on. It is the deployment decision you make on day one. Everything else is consequence."
— QEINO CTO

Bring the deployment model to your security review.

The Security Overview is a short, factual document for your CISO and procurement team. Request it directly.

Request the Security Overview
Run a Foresight Pilot