A public summary of the Quantum Connect AI dealer group security program: what we process, how the platform and managed appliances are secured, where our independent assurance work stands today, and what each dealership owns.
Quantum Connect AI, LLC operates an AI revenue layer for automotive retail covering marketplace automation, AI lead response through our assistant Hannah, managed on-premises appliances, and dealer-approved CRM or inventory integrations. This page summarizes the security program that governs those services.
Data is classified before it is processed, and each class carries its own handling rules.
| Class | Examples | How it is used |
|---|---|---|
| Public | Public vehicle details and vehicle photos. | Marketplace posting, vehicle information, and lead-response context. |
| Confidential | Dealer operational data, inventory rules, and pricing rules. | Approved posting, business rules, and rooftop-specific workflows. |
| Restricted | Lead contact information, marketplace and messaging content, CRM activity, dealer user records, device information, and access tokens. | Lead response, approved CRM activity, support, access management, and audit records. |
| Highly Restricted | Social security numbers, credit applications, payment card data, banking information, and driver license images. | Not collected or processed through marketplace or AI messaging workflows. These requests are routed to the dealership’s approved secure workflow or a trained employee. |
Highly restricted finance and identity data is out of scope by design. If a shopper raises a finance, payment, identity, credit application, or document request in a messaging channel, the workflow routes that person to the dealership's approved secure process or a trained employee.
Each dealer group and rooftop is treated as a distinct tenant. Dealer data, user access, device identity, credentials, workflows, and audit records are designed to stay inside the correct dealer boundary. One rooftop deployment must not create a path to another dealership’s network or data.
Unique named accounts are required and shared administrative accounts are prohibited. Role-based access control and least privilege limit personnel, integrations, and devices to the access needed for approved work. Multifactor authentication is required for workforce and administrative accounts, privileged access is reviewed quarterly, and access is removed the same day it is no longer authorized.
The program requires encryption in transit using TLS 1.2 or higher, preferably TLS 1.3, and encryption at rest for applicable databases, storage, backups, device storage, and sensitive logs. API keys, certificates, and service credentials are held in an approved secrets manager and are never embedded in source code, device images, browser profiles, logs, screenshots, or support tickets.
Protected source control, peer review, separated development, testing, staging, and production environments, security scanning, release approval, rollback planning, and staged appliance updates.
Device, application, identity, administrative, integration, and AI activity is logged. Monitoring covers suspicious authentication, unusual device or network behavior, configuration changes, privilege changes, token activity, and AI actions.
The incident program covers detection, containment, investigation, recovery, evidence preservation, dealer communications, credential revocation, appliance isolation, and integration disablement, with tabletop exercises at least annually. Specific notification timelines are set in the dealer agreement.
Where a Quantum appliance, the Qbox, is deployed at a rooftop, it is a managed on-premises device. It is not a general-purpose computer and not a pathway into dealership systems. Full terms are on the Qbox appliance terms page.
Hannah operates inside dealer-approved policy. Automated actions are limited to approved workflows, and exceptions escalate to a person.
The model does not decide its own permissions. Authority is evaluated before an action runs, and every consequential action is written to an append-only event history.
Data is kept only for an approved business, security, contractual, legal, or recovery purpose. Retention rules by record category are below. Exact periods are set per dealership in the applicable agreement rather than published as a blanket schedule.
| Record category | Retention rule |
|---|---|
| Public vehicle listing data | Retained only while needed for authorized listing, audit, operational, or contractual purposes. |
| Dealer configuration and pricing rules | Retained while active and for the approved post-change, audit, or contractual period. |
| Lead contact information and messages | Retained only for the authorized dealer workflow, contractual requirement, or security investigation. |
| CRM activity and integration records | Retained per the dealer agreement, the authorized workflow, and the system schedule. |
| AI inputs, outputs, and audit records | Retained only as needed for authorized service operation, quality review, and security investigation. |
| Identity and access records | Retained for account lifecycle, access review, audit, and incident investigation. |
| Device inventory and health records | Retained while the device is active and through the approved post-decommissioning audit period. |
| Security logs | Retained for monitoring, investigation, audit, legal, and contractual needs. |
| Backups | Retained under the approved backup schedule and recovery requirements, then aged out on the normal cycle. |
On offboarding we revoke accounts, integration tokens, and device certificates, then delete or return dealer data under the agreement. Deletion preserves the integrity of other dealer tenants, and backups age out on their normal cycle. See the Data Processing Addendum for the contractual commitments.
| Program | Current position |
|---|---|
| FTC Safeguards Rule and GLBA alignment | Operating compliance program in progress. This is not an FTC certification. |
| SOC 2 Type II | Planned. SOC 2 Type II is an independent attestation report, not a certification. No report exists today. |
| ISO/IEC 27001 | Planned certification target once the core information security management system is operating. |
| ISO/IEC 27701 | Planned privacy extension for evaluation after or alongside ISO/IEC 27001. |
| PCI DSS | Designed to be out of scope because our workflows do not handle payment card data. Scope is reassessed if that ever changes. |
| Independent penetration test | No published third-party test report. |
| State privacy requirements | Applicability is determined with counsel for each applicable state framework. |
Security depends on both parties. The split below is confirmed during onboarding.
Before deployment we agree with the dealership on the connectivity model, appliance location, approved integrations, access scope, incident contacts, and AI escalation path.
We organize security materials for dealer due diligence and answer vendor security questionnaires from verified records. Distribution depends on sensitivity.
Routine evidence never includes credentials, API keys, raw logs, IP addresses, unredacted testing findings, or another dealership's information.
For a security review, a completed questionnaire, or the current subprocessor information, contact legal@quantumconnectai.com. To report a suspected vulnerability, follow the responsible disclosure process.