Trust
Security
How we secure our platforms, how we respond when something goes wrong, and how to report a vulnerability to us.
EFFECTIVE1 January 2026
VERSION2.0
ENTITYeQuantic Tech, Lda · Porto, Portugal
01
Our security posture
Security is an engineering property, not a certificate we buy. Every eQuantic platform is built on the same hardened foundation: isolated tenancy, least-privilege access, encrypted transport and storage, and audited change control.
02
Product-specific measures
PRODUCT
NOTABLE CONTROLS
eQuantic Space
Per-job runner isolation, ephemeral build environments, WireGuard mesh between control plane and fleet, signed appliance updates.
eQuantic Finance
Row-level tenant scoping, immutable audit log on every financial mutation, segregation of duties on approval flows.
eQuantic People
Encrypted payroll fields, jurisdiction-scoped access, bias and access auditing on AI matching, DPA with every client.
eQuantic Pass
Zero-knowledge architecture — AES-256-GCM encryption on device, ciphertext-only server, biometric unlock, automatic vault locking.
eQuantic OS Cleaner
Local-only operation, no telemetry by default, every destructive action confirmed and reversible where the OS permits.
03
Compliance and assurance
We are not currently SOC 2 or ISO 27001 certified. We say so plainly rather than implying otherwise — our controls map to those frameworks, and formal certification is on the 2026 roadmap.
04
Incident response
We maintain a documented incident response plan with a named on-call rotation and defined severity levels.
COMMITMENT
TARGET
Acknowledge a confirmed incident internally
Within 1 hour
Notify affected customers of a data breach
Within 72 hours, per GDPR Art. 33
Status page update during an active incident
Every 60 minutes until resolved
Published post-mortem for severity 1 and 2
Within 10 working days
Post-mortems are blameless, and we publish them for anything that materially affected customers — including what we got wrong.
05
Responsible disclosure
We welcome reports from security researchers and will not pursue legal action against anyone acting in good faith under this policy.
Email security@equantic.tech with a description, reproduction steps, affected versions or endpoints, and any proof-of-concept. Encrypt with our PGP key if the finding is sensitive — fingerprint 4A2F 8E1C 9D33 B07A 5E42.
06
Scope
Ready to ship something real?
Book a 30-minute discovery call. We'll tell you within the hour whether we're the right partner — or who is.
Ready to ship something real?
Book a 30-minute discovery call. We'll tell you within the hour whether we're the right partner — or who is.
© 2026 eQuantic Tech. All rights reserved.