Skip to content
QConnect appliance

Hardware your IT team can
actually approve

Most vendors ask a dealership to open its network and trust them. QConnect is a managed appliance with no inbound access, no route into your internal systems, its own identity, and a shutdown path you can trigger on demand.

Posture

What the box can and cannot do

Written for the person who has to sign off on it, not for the person buying the software.

Nothing can dial in

The appliance accepts no inbound internet access. No public SSH, RDP, VNC, or web management interface. Connections are outbound only, encrypted, and to approved Quantum services.

Default deny on your network

It does not route, bridge, serve DHCP or DNS, or act as a Wi-Fi access point. It cannot reach your DMS, finance systems, file shares, cameras, printers, or point of sale unless that access is approved in writing.

One identity per box

Each appliance carries its own certificate or cryptographic key, issued after authenticated enrollment. Configuration and credentials are never baked into a shared image or copied between units.

Or skip your network entirely

QConnect can run on its own managed cellular router and business SIM, so it never touches the dealership network. The alternative is a dedicated vendor or IoT VLAN.

A kill switch your IT team can demand

We can revoke the device identity, invalidate tokens and integration credentials, cut egress, stop all appliance activity, and wipe Quantum-managed local data where the hardware supports it.

Tracked as an asset, not a mystery box

Serial number, MAC address, group and rooftop, location, installer, deployment date, support owner, connectivity type, and status. Fleet inventory and privileged device access are reviewed quarterly.

The prohibited list

Things QConnect is never allowed to do

These are the controls we hold ourselves to, published here rather than described on a call.

Prohibited

  • Inbound internet access to the appliance.
  • Public SSH, RDP, VNC, or web-based management interfaces.
  • Port forwarding, public IP exposure, or direct inbound remote control.
  • Network scanning, port scanning, or broad probing of dealer networks.
  • Routing, bridging, Wi-Fi access point operation, DHCP service, or DNS service.
  • Unapproved access to dealer internal subnets, DMS, finance systems, printers, file shares, cameras, or point of sale systems.
  • Use of the appliance as a shared gateway, remote access relay, or proxy for dealership personnel.

Baseline controls

  • One unique certificate, cryptographic key, or equivalent identity per appliance, issued after authenticated enrollment.
  • Dealer-specific configuration and credentials that are never embedded in a shared device image or copied between appliances.
  • Outbound-only encrypted connectivity to approved Quantum services, with default-deny access to dealer internal networks.
  • A supported, maintained operating system image carrying only the software required for approved workflows.
  • Disabled password-based SSH and root login, with administrative access only through an approved identity-aware path.
  • Asset inventory covering serial number, MAC address, dealer group and rooftop, location, installer, deployment date, support owner, connectivity type, and device status.
  • Patch management, health checks, configuration drift detection, tamper-evident enclosure, and telemetry to protected logging.
  • Quarterly review of fleet inventory and privileged device access.

How it connects

  • Dealer network deployment on a dedicated vendor or IoT VLAN, or a restricted SSID with internet-only access.
  • Independent cellular deployment using a managed LTE or 5G router and business SIM, which avoids the dealership network entirely.

If we need to shut it down

  • Revoke the appliance certificate or device identity.
  • Invalidate device tokens and integration credentials.
  • Disable associated proxy or egress access.
  • Stop the service from accepting or initiating appliance activity.
  • Trigger secure wipe of Quantum-managed local data where technically supported.
  • Place the appliance in a non-operational state pending investigation, replacement, or disposal.
Deployment

How a unit gets installed

Five steps, with your approval at the front of them.

  1. 01

    Your IT team reviews the posture first

    Before anything ships, we walk through the prohibited list, the connectivity options, and the shutdown path. You approve placement, connectivity model, and integration scope.

  2. 02

    The appliance is enrolled and identified

    It is issued a unique certificate at enrollment and added to the asset inventory under your rooftop. Password-based SSH and root login are disabled.

  3. 03

    It is placed where you decided

    A dedicated vendor or IoT VLAN, a restricted internet-only SSID, or an independent cellular connection that avoids the dealership network entirely.

  4. 04

    It is maintained and watched

    Patching, health checks, configuration drift detection, a tamper-evident enclosure, and telemetry to protected logging. Updates are staged, not pushed blind.

  5. 05

    You can shut it off at any time

    One request revokes the identity and stops the device. Return, replacement, and disposal are handled under the appliance terms.

For your security review

Where this fits a Safeguards conversation

The FTC Safeguards Rule has applied to dealers that extend or arrange credit since June 2023. Your assessor will ask about vendor access, access control, and how you cut a vendor off.

QConnect gives you a documented answer to three of those questions. Vendor access is outbound only with default-deny reach into your network. Access control is per device, issued at enrollment, never shared across units. Termination is a single revocation that stops the device and its credentials.

It does not make your dealership compliant on its own, and we do not claim that it does. It is one control with a written baseline you can hand to a reviewer.

Commercial and return terms for the hardware are covered in the QConnect appliance terms.

What is QConnect?+

A managed on-premises appliance placed at the dealership so that approved Quantum workflows can run locally under a default-deny network posture, instead of asking you to open your network to a vendor.

Can Quantum reach the rest of our network through it?+

No. Access to dealer internal subnets, DMS, finance systems, printers, file shares, cameras, and point of sale is prohibited unless it is specifically approved. The appliance cannot be used as a gateway, relay, or proxy for dealership staff.

Does it need a hole in our firewall?+

No. Inbound internet access to the appliance is prohibited, along with port forwarding and public IP exposure. All connectivity is outbound only.

Can we keep it off our network completely?+

Yes. It can run on a managed LTE or 5G router with a business SIM, which avoids the dealership network entirely.

Does QConnect mean you are SOC 2 certified?+

No. There is no completed SOC 2 Type II audit, no ISO 27001 certification, and no published third-party penetration test today. QConnect is a control, not a certification. The security program page states the current position in full.

Who is responsible for what?+

The dealership approves appliance placement, connectivity, and integration scope, and reports suspected incidents or lost hardware promptly. Quantum maintains the baseline image, asset tracking, enrollment, patching, and remote credential revocation.

Security review

Bring your IT lead to the session.

We will go through the posture, the connectivity options, and the shutdown path with the person who has to approve it.

Talk to sales