No SOC 2 report yet,
and here is exactly where we stand
Vendors love to imply an audit they have not completed. This page tells you our real status, what our infrastructure providers cover, what controls run today, and what you can actually get in writing for your review.
Audit status in one table
If a line is not on this table as complete, treat it as not complete.
- SOC 2 Type IINo audit completed. Controls described on this page are implemented today.
- ISO/IEC 27001No certification completed.
- Independent penetration testNo published third-party test report.
- HIPAA / PCINot applicable to the current product scope.
Our providers are audited. We are not.
This is the honest version of the claim other vendors stretch. The platforms underneath us hold their own reports. That is not a Quantum attestation.
| Provider | What it runs for us | Their report |
|---|---|---|
| Supabase | Application database, authentication, and storage | Maintains a SOC 2 Type II report, available from Supabase under their terms |
| Cloudflare | Edge hosting, TLS termination, and DDoS protection | Maintains SOC 2 Type II and ISO 27001 reports, available from Cloudflare |
| Lovable | Build and deployment pipeline for the web application | Publishes its own security and compliance posture, available from Lovable |
Provider reports are obtained from those providers directly, under their terms. Quantum does not redistribute them and does not present them as evidence of a Quantum audit.
What is actually implemented
Implemented and enforced in the product. Not audited by a third party.
Access control
Row-level security with per-action policies on customer data, no shared administrator logins, and credentials held as managed secrets rather than in code.
Least privilege
Service roles are scoped to the actions they perform. Elevated database access is not used for ordinary reads and is never reachable from the browser.
Change management
Schema changes ship as reviewed migrations. Automated checks in CI verify grants and row-level security before a change is allowed through.
Auditability
Messages, appointments, consent state, and outcomes are written back to the dealership CRM, so activity is reviewable in your system of record rather than in a private inbox.
Recovery testing
Point-in-time restore procedures are documented and exercised as a drill rather than assumed to work.
Vulnerability reporting
A monitored security mailbox at security@quantumconnectai.com with a named owner and a published responsible disclosure process.
No audit dates published
A timeline belongs here the day an auditor, a scope, and an observation window are committed. Until then this space stays empty on purpose.
When a readiness assessment is engaged, this page will publish the audit firm, the trust services criteria in scope, the observation window, and the expected report date, and those dates will be updated as they move. Nothing is listed here today because nothing has been scheduled.
A security package, not an attestation
There is no report to download, so we do not pretend to offer one. This is what a named owner will send you.
- Controls summary covering access, encryption, change management, and recovery
- Subprocessor list with the purpose of each
- Data flow description covering what leaves your CRM and what is written back
- Retention and deletion commitments by data category
- Consent, opt-out, and quiet-hours handling for messaging
- Line-by-line answers to your own security questionnaire
Request it from security@quantumconnectai.com, or read the compliance page and the security program.
Straight answers
Is Quantum Connect AI SOC 2 certified?+
No. There is no completed SOC 2 Type I or Type II audit and no report to hand you. Anything you read on this site describing our controls describes what is implemented, not what an auditor has tested.
You say your vendors are SOC 2. Is that the same thing?+
It is not, and we will not let it be read that way. Supabase and Cloudflare hold their own audited reports covering their infrastructure. That covers the platforms underneath us. It says nothing about how Quantum operates on top of them. Vendor certification is inherited infrastructure assurance, not a Quantum attestation.
Can we get a report for our vendor review?+
Not a SOC 2 report, because one does not exist. What we can provide in writing is a controls summary, subprocessor list, data flow description, retention and deletion commitments, and answers to your security questionnaire. Email security@quantumconnectai.com and a named owner will respond.
When will the audit happen?+
No audit date has been committed publicly. We would rather show an empty timeline than publish a date we have not funded and scheduled with an auditor. When an observation window is set, it appears on this page with the firm, the scope, and the dates.
Can we still buy without SOC 2?+
Most of our dealership conversations end with a security review rather than a report request. Bring your questionnaire to the call and we will answer it line by line, including the questions where the honest answer is that we do not have the control yet.
Bring the questionnaire.
We will answer it on the call, including the parts where the answer is that we do not have it yet.
Talk to sales