Skip to content
Quantum Trust Center

Governed AI begins with controlled access,
clear authority, and traceable action.

Quantum is designed around dealer-controlled authorization, least privilege, consent-aware communication, tenant isolation, human ownership, data minimization, and auditable system activity.

Security, privacy, agent governance, and operational trust in one place.

Quantum publishes only current, verifiable security and compliance information. Certifications and formal attestations are listed only after completion.

Governed by design

Every consequential action should answer six questions.

  1. 01

    Identity

    Which dealership, user, buyer, vehicle, opportunity, and agent are involved?

  2. 02

    Authority

    What is the actor allowed to read, recommend, change, or communicate?

  3. 03

    Consent

    Which channel, purpose, timing, and disclosure are permitted?

  4. 04

    Ownership

    Who currently controls the customer conversation or operational decision?

  5. 05

    Evidence

    Which verified facts support the action?

  6. 06

    Audit

    What happened, why, through which system, and with what result?

The AI model does not decide its own permissions. Quantum evaluates authority before the model can use a consequential tool.

The dealership defines the boundary

Access is activated, scoped, monitored, and revocable.

Dealer controls may include

  • 01Authorized dealer group and rooftops
  • 02Approved systems and accounts
  • 03Permitted users and departments
  • 04Data categories
  • 05Read permissions
  • 06Write permissions
  • 07Communication channels
  • 08Allowed agent actions
  • 09Operating hours and quiet hours
  • 10Retention requirements
  • 11Activation date
  • 12Expiration
  • 13Suspension and revocation

Quantum uses the least access required for the approved workflow and records the dealership’s current authorization.

Dealer approval does not bypass vendor terms, API requirements, platform controls, or applicable law.

The right actor. The right tenant. The right action.

Every human, service, connector, and agent receives a defined identity.

Access controls

  • 01Unique user identity
  • 02Role-based access
  • 03Dealer and rooftop scope
  • 04Service-to-service identity
  • 05Short-lived credentials where supported
  • 06Multi-factor authentication where available
  • 07Environment separation
  • 08Least-privilege tool access
  • 09Session expiration
  • 10Credential rotation
  • 11Access review
  • 12Revocation

Shared personal employee credentials should not be used for production integrations. Quantum favors vendor-permitted service identities and dealer-controlled activation.

Dealership data stays in its boundary

Every request is evaluated against the authorized dealer and rooftop.

Quantum separates dealership records through tenant-aware data access, scoped credentials, role rules, and audit context.

Authorized dealer + rooftop boundary

  • Organizations and rooftops
  • Users and roles
  • Customers and opportunities
  • Vehicles and listings
  • Conversations and recordings
  • Appointments
  • Consent
  • Recommendations
  • Outcomes
  • Integration credentials
  • Knowledge sources
  • Audit records

Isolation applies to every record class above, in every request path.

An agent never receives unrestricted cross-dealer context. The authorized tenant and opportunity are assembled for each execution.

Protect data in transit and at rest

Sensitive access belongs in managed security controls, not prompts or workflow notes.

Controls

  • 01TLS for data in transit
  • 02Encryption at rest through approved cloud services
  • 03Managed secret storage
  • 04Credential separation by environment
  • 05Restricted production access
  • 06Secret rotation
  • 07No credentials in source code
  • 08No credentials in public documents
  • 09Sensitive-field redaction
  • 10Encrypted backups
  • 11Access and change logging

Quantum does not publish passwords, API keys, tokens, certificates, or dealer credentials in agent instructions, support messages, or shared documents.

Defined identity. Limited authority.

Hannah and Coach share context, not permissions.

Buyer-facing

Hannah

May communicate with the buyer only through approved channels and only while buyer-facing authority is active.

Rep-facing

Coach

May advise the salesperson or manager. Coach does not contact the buyer.

Evaluated before either agent acts

  1. 01Current identity
  2. 02Dealer scope
  3. 03Opportunity
  4. 04Official CRM state
  5. 05Operational evidence
  6. 06Consent
  7. 07Ownership
  8. 08Allowed tools
  9. 09Action authority
  10. 10Escalation rule

If required context is missing, stale, conflicting, or outside authority, the agent asks, waits, or escalates.

Clear control of customer data

Document what is collected, why it is used, and when it is deleted.

Published for every deployment

  • 01Data categories collected
  • 02Purpose of processing
  • 03Source systems
  • 04Dealer and Quantum roles
  • 05Storage locations
  • 06Retention periods
  • 07Deletion process
  • 08Export process
  • 09Backup retention
  • 10Legal hold behavior
  • 11Anonymization
  • 12Service provider involvement
  • 13Post-termination handling

Dealership and customer data is not used for unrelated purposes or model training unless the applicable agreement, authorization, disclosure, and provider controls explicitly permit it.

Exact cloud regions, storage and backup locations, cross-border processing, and the retention schedule by data category are provided in writing during security review and in the applicable agreement. They are published here only once finalized as customer-facing commitments.

Read the Privacy Policy
Model capability inside Quantum control

The model reasons. Quantum controls the context, tools, policy, and record.

Governance controls

  • 01Approved model providers
  • 02Model and prompt versioning
  • 03Structured inputs and outputs
  • 04Authorized context assembly
  • 05Sensitive-data redaction
  • 06Tool-level permissions
  • 07Cost and latency limits
  • 08Fallback behavior
  • 09Human escalation
  • 10Quality evaluation
  • 11Unsupported-claim detection
  • 12Provider retention settings
  • 13Change testing before release

Quantum may use different models for voice, chat, recommendation, extraction, or evaluation. Agent identity and dealership authority remain inside Quantum’s governed layer rather than depending on one model provider.

A model response is not a completed action. Consequential actions require policy approval, tool execution, destination confirmation, and audit.

Explain what happened

Every important system and agent event should leave evidence.

Audit record

  • 01Actor
  • 02Dealer and rooftop
  • 03Buyer and opportunity
  • 04Vehicle
  • 05Action
  • 06Source system
  • 07Policy result
  • 08Consent state
  • 09Ownership state
  • 10Tool used
  • 11Timestamp
  • 12Destination result
  • 13Retry or reconciliation
  • 14Correlation ID

A customer-facing audit view answers

  • Who acted?
  • What changed?
  • Why was it allowed?
  • Which system confirmed it?
  • What happened next?

Quantum may redact sensitive content while preserving the evidence required for support, customer review, incident analysis, reconciliation, and applicable compliance obligations.

Prepare before something fails

Detect, contain, communicate, recover, and learn.

  1. 01

    Detect

    Receive alerts from system health, security monitoring, customer reports, or operational reconciliation.

  2. 02

    Classify

    Determine severity, affected tenants, data, systems, workflows, and customer impact.

  3. 03

    Contain

    Pause affected connectors, credentials, communications, or agent authority.

  4. 04

    Investigate

    Preserve evidence, identify cause, and determine scope.

  5. 05

    Communicate

    Notify internal owners and affected customers according to contract and applicable requirements.

  6. 06

    Recover

    Restore safely, rotate credentials, reconcile data, and verify normal operation.

  7. 07

    Improve

    Document root cause, corrective actions, ownership, and follow-up testing.

Security contact: security@quantumconnectai.com

Designed to fail safely

A system problem should reduce authority, not create uncontrolled action.

Continuity controls

  • 01Encrypted backups
  • 02Documented restore process
  • 03Environment separation
  • 04Connector safe pause
  • 05Workflow retry
  • 06Dead-letter handling
  • 07Provider fallback where approved
  • 08Communication shutdown controls
  • 09CRM reconciliation
  • 10Recovery testing
  • 11Customer notification process
  • 12Manual operating procedure

Safe-failure behavior

  • Stale inventoryHold vehicle-specific claims
  • CRM unavailablePreserve events and queue approved writes
  • Ownership uncertainBlock buyer-facing outreach
  • Communication provider degradedStop duplicate retries
  • Model unavailableUse approved fallback or escalate
  • Consent unavailableBlock contact
View system and integration status
Report a security concern

Give researchers and customers a clear path to notify Quantum.

If you believe you identified a security vulnerability affecting Quantum, report it privately with the affected system, reproduction steps, potential impact, and safe contact information.

Disclosure program elements

  • Security email
  • Expected acknowledgement time
  • Testing boundaries
  • Prohibited testing
  • Counsel-approved safe-harbor language
  • Disclosure coordination process

Published today

  • Security email: security@quantumconnectai.com
  • Reports are acknowledged by a named owner before a formal acknowledgement window is published.
  • Formal safe-harbor terms and testing boundaries are published once approved by counsel.
Report a Security Concern
Accurate, current, and verifiable

Do not turn security intent into a certification claim.

Language we use

  • Designed around least privilege
  • Dealer-controlled authorization
  • Consent-aware communication
  • Audit-ready event history
  • Encrypted through approved cloud services
  • Configurable retention controls
  • Compliance-support workflows

Claims we do not make unless formally true

  • SOC 2 certified
  • ISO 27001 certified
  • HIPAA compliant
  • PCI compliant
  • Fully compliant in all 50 states
  • Certified by a CRM vendor
  • Independently penetration tested
  • Zero risk
  • Guaranteed security

Current certification and audit status

  • SOC 2 Type IINo audit completed. Controls described on this page are implemented today.
  • ISO/IEC 27001No certification completed.
  • Independent penetration testNo published third-party test report.
  • HIPAA / PCINot applicable to the current product scope.

Status is maintained from a single source of truth. When an audit, certification, assessment, or legal review is complete, its exact scope, date, issuer, and current status are published here.

When an audit, certification, assessment, or legal review is complete, Quantum publishes its exact scope, date, issuer, and current status.

Questions

Trust Center FAQ

Does Quantum train public AI models on dealership data?+

Quantum does not use dealership or customer data for unrelated model training unless the applicable agreement, authorization, disclosure, and provider controls explicitly permit it. The answer in your deployment matches your actual product configuration and contract.

Who owns dealership data?+

The dealership retains its rights in dealership and customer data. Quantum processes data only for documented services, subject to the applicable agreement and law.

Can a dealership revoke Quantum’s access?+

Yes. Every production connection has a documented suspension and revocation process.

Does Quantum have SOC 2 certification?+

No SOC 2 audit has been completed. The controls described on this page are implemented today, and no certification is implied. When an audit is complete, its exact scope, date, issuer, and status are published here.

How does Quantum handle opt-outs?+

Consent and suppression state are evaluated before approved buyer-facing communication. Opt-out events are recorded and written back where the connection supports it.

Where is data stored?+

Exact cloud regions, storage and backup locations, cross-border processing, and the retention schedule by data category are provided in writing during security review and in the applicable agreement. They are published here only once finalized as customer-facing commitments.

How long is data retained?+

Exact cloud regions, storage and backup locations, cross-border processing, and the retention schedule by data category are provided in writing during security review and in the applicable agreement. They are published here only once finalized as customer-facing commitments.

How are Hannah and Coach controlled?+

Each agent has a separate identity, context, tools, permissions, audience, and escalation model. Neither agent decides its own authority.

Review Quantum with your team

Bring security, IT, legal, and dealership operations into the same conversation.

Quantum can map the proposed systems, data categories, permissions, communication workflows, agent authority, retention, and incident responsibilities before deployment.

Clear access. Clear authority. Clear evidence.