Partner-ecosystem data is sensitive — it touches revenue, relationships, and deal terms neither side wants exposed. QuarqAI is built to handle that data the way a CFO or general counsel would expect: encrypted, access-controlled, isolated per customer, and never used to train a model without permission.

This page summarizes the technical and organizational measures described in our Master Service Agreement and Data Processing Addendum. If your security team needs more detail, a security overview is available on request at security@quarq.ai.

Encryption

Access control

Tenant isolation

Every customer’s data, logs, embeddings, and caches are logically isolated per tenant. There is no cross-tenant indexing, analytics, or co-mingling of customer data — your partner data is never visible to, or blended with, another customer’s.

How we use AI

QuarqAI uses AI models to help calculate and explain partnership metrics.

Infrastructure

QuarqAI’s platform runs on Google Cloud Platform (GCP), which provides certified physical and environmental security controls. Our data-integration pipeline is powered by Syncari.

Compliance and certifications

QuarqAI’s security program is aligned with SOC 2 and ISO 27001 control frameworks. As of July 2026, we have not yet completed formal certification under either framework — we’d rather say this plainly than imply a certification we don’t hold. A security overview is available to prospective and existing customers on request.

Data handling commitments

Reporting a security issue

If you believe you’ve found a security vulnerability in QuarqAI’s Site or Services, please report it to security@quarq.ai before disclosing it publicly. We’ll acknowledge reports within 5 business days and keep you updated as we investigate.

Related documents