quanterios
Get started
Trust Center

How Quanterios protects your data, your code, and your AI.

Region-pinned EU data planes. ISO 27001-aligned security controls. GDPR-anchored privacy. A responsible-AI framework built into the product itself, not bolted on after the fact.

EU
Data residency
Frankfurt · Dublin · Zurich
ISO 27001
Aligned controls
Audit-ready · in progress
GDPR
Anchored
DPO · €-based · CET / GMT
0-trust
Architecture
Region-pinned · least-privilege
Section 01 · Data residency

Your data stays in the region you choose.

Quanterios runs three EU data planes, Frankfurt (primary, DACH), Dublin (failover, EU west), and Zurich (sovereign, CH residency). All customer data, CBOM contents, AIBOM contents, evidence packets, audit trails, is region-pinned at write time and never crosses regional boundaries.

  • No transatlantic data egress · ever
  • Failover stays inside the EU · GDPR-clean
  • Optional CH residency for sovereign workloads
  • Region-pinned backups · region-pinned logs
Live · region health
3 of 3 healthy
DE
Frankfurt
Primary · DACH delivery
latency12 ms p50
uptime · 90d99.97%
50.1°N8.7°E
IE
Dublin
Failover · EU west
latency12 ms p50
uptime · 90d99.97%
53.3°N6.3°W
CH
Zurich
Sovereign · CH residency
latency12 ms p50
uptime · 90d99.97%
47.4°N8.5°E
Section 02 · Security

Controls, not promises.

Quanterios is built on a zero-trust architecture with cryptographic service identity, region-pinned data planes, and ISO 27001-aligned operational controls. Every claim below is either evidenced in our internal SOC 2 readiness package or verifiable in the product itself.

Control area · 01
Identity & access
  • SSO via SAML 2.0 / OIDC with major IdPs (Okta, Azure AD, Keycloak, Google Workspace)
  • Role-based access control with least-privilege defaults
  • Hardware-backed MFA enforced on all admin paths
  • Session boundaries · audit log on every privilege change
Control area · 02
Data protection
  • TLS 1.3 in transit · ML-KEM-768 hybrid available (we eat our own dog food)
  • AES-256 at rest · per-tenant data keys · KMS in region
  • Customer-data isolation by tenant · no cross-tenant queries
  • Backups encrypted, region-pinned, lifecycle-controlled
Control area · 03
Network & runtime
  • Zero-trust network access · private VPC · no public ingress to control plane
  • Mutual TLS between services · cryptographic service identity
  • Web Application Firewall · DDoS protection · bot detection
  • Container hardening · CIS-aligned base images · minimal attack surface
Control area · 04
Operations
  • Continuous vulnerability scanning · CVE patching SLA
  • Penetration tests annually + on major release
  • Incident response plan · 24×5 on-call rotation
  • ISO 27001 alignment in progress · audit-ready
Section 04 · Privacy

GDPR is the floor. Not the ceiling.

Quanterios was designed for GDPR from the first commit, not retrofitted. EU-based DPO, signed Data Processing Agreement available on request, no transatlantic data egress, and no training on customer data, full stop.

Where is my data stored?

In the EU region you select at signup, Frankfurt, Dublin, or Zurich. Data is region-pinned at write time and never moves between regions automatically. Region selection is enforced at the API gateway layer.

Who has access to my data?

Only the named customer team and Quanterios engineers explicitly authorised under your DPA. All access is logged with the requester's identity, the data accessed, and the operational reason. Customer data access by Quanterios staff is rare and only happens for support cases you initiate.

Is my data used to train models?

No. Quanterios does not train models on customer data. The Decision Engine is grounded in our proprietary migration-outcomes corpus, which uses anonymised aggregate signals, never raw customer content. Opt-in granular contributions to the corpus are explicitly negotiated per customer.

How long is data retained?

Customer-controlled. Default retention windows are configurable per data class (CBOM scans, AIBOM events, audit logs). On contract termination, all data is deleted within 90 days unless you instruct otherwise; you can also export everything in machine-readable form before that.

What about subprocessors?

Public list maintained at the bottom of this page. Every subprocessor sits in the EU, is GDPR-compliant, and is contractually bound by our DPA terms. We notify you 30 days before any subprocessor change.

Note for the operator of this site

The above is a plain-language summary, not a legal-grade privacy notice. Before this page goes to production, please have a German DPO and a privacy lawyer review and sign off on this content, the Data Processing Agreement template, and the subprocessor list. The same applies to any Terms of Service and DPA documents linked elsewhere on the site.

Section 05 · Responsible AI

Six principles. Applied to our own product first.

Quanterios sells AI governance. We have to live the discipline ourselves. The six positions below shape how the AI Decision Engine is built, deployed, and audited.

Principle · 01
Cited reasoning, every output

Every risk score, every migration playbook, every runtime block carries the source evidence with it. We do not ship un-cited model output.

Principle · 02
Deterministic where it matters

Risk scoring is rule-based + XGBoost, auditable, reproducible, never hallucinated. LLM reasoning sits on top, not underneath.

Principle · 03
Customer data is not training data

We do not fine-tune our models on customer content. Our migration-outcomes corpus uses anonymised aggregate signals only.

Principle · 04
Human-in-the-loop for irreversible actions

Crypto Agility API algorithm swaps require explicit policy authorisation. AI Runtime denials are auditable and customer-overridable.

Principle · 05
EU AI Act risk-tier discipline · applied to ourselves

We classified the platform's own AI components against the EU AI Act risk tiers. Where high-risk obligations apply, we meet them, transparency, human oversight, post-market monitoring, technical documentation.

Principle · 06
Pre-trained model provenance

We use third-party LLMs (Claude, OpenAI fallback) with fully signed contracts, EU data-residency where available, and no-training agreements. Model versions are pinned in our AIBOM.

Section 06 · Subprocessors

The full list. Updated continuously.

Every third party that processes any data on behalf of Quanterios is listed below. Customers are notified 30 days before any change to this list. All subprocessors are contractually bound by our DPA terms.

Subprocessor
Role
Region
Purpose
Hetzner Cloud
Primary infrastructure
EU · DE
Compute, storage, networking for production data planes
Cloudflare
Edge / DDoS / WAF
Global · EU traffic
Public-facing edge, DDoS mitigation, WAF for marketing surfaces
Anthropic (Claude)
LLM inference
EU residency available
AI Decision Engine reasoning layer · no-training contract
OpenAI
LLM inference fallback
EU residency available
Fallback inference path · no-training contract
Stripe
Billing
EU · IE
Invoice processing, subscription management
Linear
Engineering ops
EU residency
Internal issue tracking · no customer data

Need our security, privacy, or DPA package?

Procurement, security review, vendor risk assessment, we have a packet ready. Email trust@quanterios.com and we'll respond within one business day.