Legal

Security & Procurement

Status

This document has been drafted and is being finalised with counsel. The settled version will be published on this page before general availability, and account holders will be notified of the effective date. Until then, nothing on this page is a contractual term.

What it will cover

The Security & Procurement page will give procurement and security teams the specifics they need: architecture summary (where the application, corpus and vector store run; how tenant data is separated and entity scoping enforced), encryption in transit and at rest, production access control and logging, the full subprocessor list with purpose and location, data residency, AI-processing and model-training position, backups and recovery, audit trails, certifications, and the professional indemnity position.

Our practice today

  • All traffic is served over TLS; data is encrypted at rest.
  • Access to production systems is restricted and authenticated; organisation data is scoped per account, and cross-tenant access is denied at the API layer.
  • Certifications: we hold no SOC 2 or ISO 42001 certification today, and we do not imply otherwise.
  • To report a suspected vulnerability, see the Vulnerability Disclosure page.

Questions in the meantime: hello@qanun.ai

← Back to qanun.io

Subprocessors

The complete subprocessor list (each with purpose and location) is being verified with counsel and will be published here before general availability. We will not publish a partial or unverified list.

Data residency

The data-residency statement (hosting countries for application, corpus and vector-store infrastructure) is being verified with counsel and will be published here. We will not publish an unverified statement.

Verification methodology and live coverage: Methodology & Corpus Governance · System status