Built for vendor review.
Defensible by design.
Procurement, model risk, and compliance teams evaluate QGI on replayability, data boundaries, and deployment sovereignty — not marketing claims. This page covers principles, deployment models, data handling, and our certification roadmap.
SR 11-7 aligned narrative — replay, not post-hoc explanation.
Model risk teams need to reproduce a decision against the rule versions in force on the decision date. QGI exports reasoning graphs with seven Hilbert-Space Compacting (HSC) signals — including explicit Conflict and Coverage — before any generation step.
Same inputs and data versions yield identical reasoning graphs. The audit trail is the runtime artifact, not a narrative written after the fact.
- — Bit-for-bit replay against encoded rulebooks and loan files
- — JSON-LD and SIEM export for GRC platforms
- — Model cards standardized across the stack (2026 commitment)
- — Human-in-the-loop gates at defined decision points
What tier-1 vendor review typically asks — and where we are.
SOC 2 Type II
In progress
Report target Q4 2026
Deployment models
Available
Managed · VPC · on-prem
Audit replay
Core product
JSON-LD · SIEM export
Data handling
Documented
No training on customer data without agreement
Full security questionnaire responses, DPA, and EU SCCs are available on request during vendor review. Send a security inquiry through the contact form.
Four non-negotiables.
Principle 01
Deterministic by construction
Same inputs and data versions produce identical reasoning graphs. No temperature knob changes the chain you defend.
Principle 02
Inspectable before generation
Seven HSC signals — Relevance, Conflict, Coverage, and more — surface as first-class artifacts before a decision letter is written.
Principle 03
Provenance preserved end-to-end
Every fact, rule, and document carries source, version, and temporal scope. Decisions replay against the rules in force on that date.
Principle 04
License-safe data
Customer data is never used for training without written agreement. Model and data sources are governed by the applicable deployment agreement.
Three ways to run the stack.
Choose a deployment model up-front. Control plane and data plane separation keeps residency and key ownership defensible at audit.
Deployment 01
QGI Managed
QGI-hosted for demos and evaluations. Single-tenant workspace isolation.
- US region
- Encryption in transit and at rest
- Per-workspace encryption keys
- Audit log export (JSON / SIEM)
Deployment 02
Customer VPC
Control plane by QGI; data plane in customer VPC. No regulated data leaves the tenant.
- Customer-owned keys (BYOK)
- Private networking
- Region-pinned to customer policy
- SSO, SCIM, and workspace RBAC
Deployment 03
On-premise / Air-gapped
Full-stack in customer environment for classified, HIPAA-critical, or sovereign data.
- Full data sovereignty
- Customer-driven upgrade cadence
- Offline model cards and replay tooling
- Air-gapped inference support
What we do with your data.
Training
Training
Customer data is never used to train QGI models without explicit written agreement.
Inference
Inference
Prompts and responses stay inside the tenant boundary under VPC and on-prem. Managed retains only per workspace retention policy.
Replay & audit
Replay & audit
Reasoning graphs export as JSON-LD, SIEM, or signed archive for your GRC platform.
Deletion
Deletion
Customer-initiated deletion removes records and reasoning graphs per agreed SLA.
Detailed policy lives in the current Privacy Policy and Terms of Service. Enterprise engagements are governed by a Master Service Agreement and Data Processing Addendum available on request.
What is committed. What is next.
A dated view of where compliance artifacts are today and where they will be when a demo moves to production.
Committed 2026
- SOC 2 Type II audit in progress (report target: Q4 2026)
- Model card and audit export standardization across the stack
- Data Processing Addendum and EU SCCs available on request
- Customer VPC deployment (AWS first, Azure next)
Planned
- HIPAA readiness for healthcare-vertical engagements
- FedRAMP Moderate path for government-vertical engagements
- ISO 27001 alignment
- On-premise / air-gapped reference deployment
Founder statement · On the record
I hold a PhD in formal verification — the discipline of proving, not hoping, that a system behaves correctly. A regulated decision that cannot be replayed and defended has no business being made by an AI system.
— Dr. Sam Sammane, Founder & Chief Executive Officer, Quantum General Intelligence Inc.
Evaluating QGI under an AI Governance framework?