Qeino is deployed as a private-instance system inside the customer's perimeter. Counsel-reviewed positioning available under NDA.
The deployment model is the security model.
Qeino runs inside your perimeter. Source code, telemetry and model weights do not leave the building. Air-gapped, on-premises, or EU-sovereign — your choice, evidenced in the deployment itself, not asserted in a policy document.
Data never leaves the perimeter.
The architecture is the control. Qeino is delivered as a private instance that runs inside the customer's network. Inbound read access only. No outbound channel to a vendor cloud. No telemetry phone-home.
- Status: Verified — Customer perimeter, no egress
- Status: Verified — Customer hardware
- Status: Verified — When customer-managed cloud
- Status: Verified — BYOK, HSM-backed
What is read. What is never touched.
Qeino reads engineering process signals. It does not read customer data, end-user data or production telemetry. The surface is documented and narrow by design.
- Read-only metadata. Never copied outside the perimeter.
- Build, test and deployment events. Read-only.
- Ticket metadata, transitions, timestamps. Read-only.
- Optional. Channel allow-list. Read-only.
- Not read. Not required.
- Never read. Never touched.
- Never exfiltrated. Stays inside the perimeter.
- Not read.
Evidenced, not asserted.
A calm, dated roadmap. We publish what is in place, what is in progress, and what is scheduled. Status is shown by icon and label — never by colour alone.
| Item | Status | Target | Note |
|---|---|---|---|
| Independent penetration test | Status: In place | Annual cadence | Report available under NDA |
| Vulnerability disclosure programme | Status: In place | Continuous | See /.well-known/security.txt |
| SOC 2 Type II | Status: In progress | 2027 | Controls implemented; observation window in progress |
| ISO 27001 | Status: Scheduled | 2027–2028 | Aligned to ISO 27001:2022 controls |
| Source-code escrow | Status: In place | On request | Independent escrow agent, customer-triggered release conditions |
Counsel-reviewed positions.
The positions below are counsel-reviewed. Detailed memoranda are available under NDA. Qeino is not legal advice; we work with your compliance and legal teams.
Air-gapped and on-prem deployment options support obligations on supply-chain risk, access control and incident reporting.
For medical-device manufacturers: Qeino does not touch device firmware, patient data or production telemetry. Read-access scope documented for technical files.
Financial-services deployments are designed for ICT third-party risk requirements, with escrow and exit provisions.
Continuity, in writing.
Sovereign deployments outlast vendors. We document continuity in writing, not in marketing.
Independent escrow agent holds a current build of the Qeino platform and deployment runbooks. Release conditions are agreed in the customer contract — typically insolvency, material breach, or sustained failure to maintain the platform.
A financial-viability pack — cap table, runway, banking, governance — is available under NDA to procurement and risk teams. We send it before contracting, not after.
"Security is not a feature you bolt on. It is the deployment decision you make on day one. Everything else is consequence."
Bring the deployment model to your security review.
The Security Overview is a short, factual document for your CISO and procurement team. Request it directly.