What we do with your data,
and what we have not earned yet
Dealerships get asked hard questions by their own compliance people. This page gives you the answers in writing, including the parts that are still gaps.
The rules the system runs under
These are enforced in the product, not written in a policy nobody reads.
Consent before contact
Every outbound message is checked against consent, suppression lists, and quiet hours before it sends. A record without consent does not get contacted.
Opt-out honored immediately
Stop requests are processed on receipt, applied across channels, and written back to the CRM so no rep re-contacts that customer by accident.
Written posting authorization
Inventory is posted only after an authorized dealership manager approves the inventory feed in writing. The feed into Quantum is one-way and read-only.
Everything written back
Messages, appointments, consent state, and outcomes are written to the CRM, so the activity record is auditable rather than living in a private inbox.
Least-privilege access
Row-level security and per-action policies on customer data, credentials held as managed secrets, and no shared administrator logins.
Escalation over guessing
Pricing, credit outcomes, trade values, and legal answers are never given by the assistant. They escalate to a person at your store.
Current audit status, stated plainly
If a vendor will not tell you what they do not have, ask harder questions.
- SOC 2 Type IINo audit completed. Controls described on this page are implemented today.
- ISO/IEC 27001No certification completed.
- Independent penetration testNo published third-party test report.
- HIPAA / PCINot applicable to the current product scope.
Exact cloud regions, backup locations, cross-border processing, and the retention schedule by data category are provided in writing during security review and in the applicable agreement. See the Trust Center and security program.
TCPA, Safeguards, GLBA, 10DLC, state AI disclosure
Each rule, what it covers, and the control we already run against it. Reviewed September 9, 2026.
| Rule | What it covers | What we run |
|---|---|---|
| TCPA | Federal rules on calling and texting consumers, including consent, revocation, and time-of-day limits. Consent practice is currently unsettled after the FCC one-to-one consent rule was vacated in January 2025 and subsequently repealed. | Consent is captured with evidence of when and how it was given, checked before every send, and revocation is applied across channels on receipt. Quiet hours are enforced per store and per state. |
| FTC Safeguards Rule | Mandatory since June 9, 2023 for dealers that extend or arrange credit. Assessors ask about vendor access, access control, MFA, and how a vendor is cut off. | Least-privilege access with per-action policies, no shared administrator logins, credentials held as managed secrets, and the QConnect appliance running outbound-only with a documented revocation path. |
| GLBA | Protection of nonpublic personal information collected in connection with a financial product or service. | Highly restricted data is out of scope for the assistant. Credit, applications, and finance details are routed to a person at the store rather than handled in an automated conversation. |
| 10DLC and A2P registration | Carrier registration for business text messaging in the United States. Unregistered traffic gets filtered or blocked. | Messaging runs on registered brand and campaign records with the dealership named, opt-out keywords honored, and message content aligned to the registered use case. |
| Utah AI Policy Act | Disclosure duties in consumer transactions, effective May 7, 2025. | The assistant discloses that it is an AI assistant. Disclosure wording and version are recorded per store, so you can show what was said and when it changed. |
| California SB 243 | Chatbot disclosure obligations effective January 1, 2026, part of a wave of state chatbot laws. | Same disclosure control, configured per state. Where a state requires specific wording, that wording is set at the store level rather than assumed nationally. |
| Colorado ADMT statute | Colorado repealed and replaced its AI Act in 2026 with a narrower automated decision-making statute effective January 1, 2027. | The assistant makes no credit, pricing, or eligibility decision. Every consequential decision stays with a person at the dealership. |
Summary of how our controls line up with rules dealerships ask about, current as of the review date above. It is not legal advice, and it does not make your dealership compliant on its own. Confirm your obligations with your own counsel.
Straight answers
Do you have a SOC 2 report?+
No. There is no completed SOC 2 Type II audit, no ISO 27001 certification, and no published third-party penetration test. The controls described on this page are implemented today. We would rather tell you that than imply an audit that does not exist.
Who owns the data?+
The dealership does. Inventory and customer data stay yours, the feed into Quantum is read-only, and activity is written back into your CRM so your system of record stays the system of record.
How is text messaging handled?+
Consent is captured and stored with evidence of when and how it was given. Quiet hours and opt-outs are enforced before send. Opt-out rate and compliance exceptions are tracked as reported metrics, not hidden.
How do vehicles get posted to Marketplace?+
Through a one-way inventory feed from your inventory management system, set up only after a dealership manager approves it in writing, and posted on the accounts named in that approval. Listings update with current pricing and sold status.
Where do I report a security issue?+
Email security@quantumconnectai.com. Reports are acknowledged by a named owner. Our responsible disclosure page has the details.
Bring your security questionnaire.
We will answer it on the call, including anything this page does not cover.
Talk to sales