Partner-ecosystem data is sensitive — it touches revenue, relationships, and deal terms neither side wants exposed. QuarqAI is built to handle that data the way a CFO or general counsel would expect: encrypted, access-controlled, isolated per customer, and never used to train a model without permission.
This page summarizes the technical and organizational measures described in our Master Service Agreement and Data Processing Addendum. If your security team needs more detail, a security overview is available on request at security@quarq.ai.
Encryption
- Data is encrypted in transit using TLS 1.2 or higher.
- Data is encrypted at rest using AES-256 (or equivalent), managed through cloud-native key management.
- Secrets and credentials are never stored in plaintext.
Access control
- Single sign-on (SSO/SAML) and multi-factor authentication (MFA) are enforced for QuarqAI personnel accessing production systems.
- Access follows role-based and attribute-based controls (RBAC/ABAC) on a least-privilege, need-to-know basis.
- All access to production systems is logged and audited.
Tenant isolation
Every customer’s data, logs, embeddings, and caches are logically isolated per tenant. There is no cross-tenant indexing, analytics, or co-mingling of customer data — your partner data is never visible to, or blended with, another customer’s.
How we use AI
QuarqAI uses AI models to help calculate and explain partnership metrics.
- We only work with AI providers that are contractually prohibited from using your data to train their own general-purpose models, and from retaining it beyond what’s needed to return a result.
- Requests to AI providers are minimized and redacted to include only what’s necessary to generate the requested output.
- QuarqAI does not use customer data to train any foundation or generalized model without a customer’s prior written consent.
- Only de-identified, aggregated data may ever be used for cross-customer analytics or benchmarking.
Infrastructure
QuarqAI’s platform runs on Google Cloud Platform (GCP), which provides certified physical and environmental security controls. Our data-integration pipeline is powered by Syncari.
Compliance and certifications
QuarqAI’s security program is aligned with SOC 2 and ISO 27001 control frameworks. As of July 2026, we have not yet completed formal certification under either framework — we’d rather say this plainly than imply a certification we don’t hold. A security overview is available to prospective and existing customers on request.
Data handling commitments
- Deletion: on request or contract termination, customer data is deleted — including backups — within 30 days, unless we’re legally required to retain it.
- Breach notification: if we confirm a data breach involving customer data, we notify affected customers within 48 hours with what we know at the time, so you can meet your own regulatory obligations.
- Data minimization: we collect what’s needed to run the Service and nothing more.
- Sub-processors: a current list of sub-processors who may touch customer data is available in our Data Processing Addendum.
Reporting a security issue
If you believe you’ve found a security vulnerability in QuarqAI’s Site or Services, please report it to security@quarq.ai before disclosing it publicly. We’ll acknowledge reports within 5 business days and keep you updated as we investigate.