Skip to content
SOC 2 status

No SOC 2 report yet,
and here is exactly where we stand

Vendors love to imply an audit they have not completed. This page tells you our real status, what our infrastructure providers cover, what controls run today, and what you can actually get in writing for your review.

Current status, reviewed September 9, 2026

Audit status in one table

If a line is not on this table as complete, treat it as not complete.

  • SOC 2 Type IINo audit completed. Controls described on this page are implemented today.
  • ISO/IEC 27001No certification completed.
  • Independent penetration testNo published third-party test report.
  • HIPAA / PCINot applicable to the current product scope.
Inherited infrastructure assurance

Our providers are audited. We are not.

This is the honest version of the claim other vendors stretch. The platforms underneath us hold their own reports. That is not a Quantum attestation.

Infrastructure providers and the reports they maintain
ProviderWhat it runs for usTheir report
SupabaseApplication database, authentication, and storageMaintains a SOC 2 Type II report, available from Supabase under their terms
CloudflareEdge hosting, TLS termination, and DDoS protectionMaintains SOC 2 Type II and ISO 27001 reports, available from Cloudflare
LovableBuild and deployment pipeline for the web applicationPublishes its own security and compliance posture, available from Lovable

Provider reports are obtained from those providers directly, under their terms. Quantum does not redistribute them and does not present them as evidence of a Quantum audit.

Controls running today

What is actually implemented

Implemented and enforced in the product. Not audited by a third party.

Access control

Row-level security with per-action policies on customer data, no shared administrator logins, and credentials held as managed secrets rather than in code.

Least privilege

Service roles are scoped to the actions they perform. Elevated database access is not used for ordinary reads and is never reachable from the browser.

Change management

Schema changes ship as reviewed migrations. Automated checks in CI verify grants and row-level security before a change is allowed through.

Auditability

Messages, appointments, consent state, and outcomes are written back to the dealership CRM, so activity is reviewable in your system of record rather than in a private inbox.

Recovery testing

Point-in-time restore procedures are documented and exercised as a drill rather than assumed to work.

Vulnerability reporting

A monitored security mailbox at security@quantumconnectai.com with a named owner and a published responsible disclosure process.

Timeline

No audit dates published

A timeline belongs here the day an auditor, a scope, and an observation window are committed. Until then this space stays empty on purpose.

When a readiness assessment is engaged, this page will publish the audit firm, the trust services criteria in scope, the observation window, and the expected report date, and those dates will be updated as they move. Nothing is listed here today because nothing has been scheduled.

What you can get in writing

A security package, not an attestation

There is no report to download, so we do not pretend to offer one. This is what a named owner will send you.

  • Controls summary covering access, encryption, change management, and recovery
  • Subprocessor list with the purpose of each
  • Data flow description covering what leaves your CRM and what is written back
  • Retention and deletion commitments by data category
  • Consent, opt-out, and quiet-hours handling for messaging
  • Line-by-line answers to your own security questionnaire

Request it from security@quantumconnectai.com, or read the compliance page and the security program.

Questions your security lead will ask

Straight answers

Is Quantum Connect AI SOC 2 certified?+

No. There is no completed SOC 2 Type I or Type II audit and no report to hand you. Anything you read on this site describing our controls describes what is implemented, not what an auditor has tested.

You say your vendors are SOC 2. Is that the same thing?+

It is not, and we will not let it be read that way. Supabase and Cloudflare hold their own audited reports covering their infrastructure. That covers the platforms underneath us. It says nothing about how Quantum operates on top of them. Vendor certification is inherited infrastructure assurance, not a Quantum attestation.

Can we get a report for our vendor review?+

Not a SOC 2 report, because one does not exist. What we can provide in writing is a controls summary, subprocessor list, data flow description, retention and deletion commitments, and answers to your security questionnaire. Email security@quantumconnectai.com and a named owner will respond.

When will the audit happen?+

No audit date has been committed publicly. We would rather show an empty timeline than publish a date we have not funded and scheduled with an auditor. When an observation window is set, it appears on this page with the firm, the scope, and the dates.

Can we still buy without SOC 2?+

Most of our dealership conversations end with a security review rather than a report request. Bring your questionnaire to the call and we will answer it line by line, including the questions where the honest answer is that we do not have the control yet.

Send this to your security reviewer

Bring the questionnaire.

We will answer it on the call, including the parts where the answer is that we do not have it yet.

Talk to sales