Trust Center
How we protect your data
Security, privacy and governance across AI Workspace, repository analysis, agents and compliance. Every item on this page describes a control in operation, with its scope and limits stated.
01Principles
Privacy by purpose
AI Workspace processes what you submit. Usage and cost telemetry is kept apart from content. Telemetry connectors read counts and cost, never prompts or responses.
Isolation by organization
Every access is bound to an organization and a role. AI Workspace enforces isolation in the database itself, per organization and per person. Conversations and attachments open only for the person who created them.
Stated region
The platform runs on AWS in us-east-1 (N. Virginia). The region of each AI processing path is in section 03, and your organization can restrict providers and regions.
Explicit authorization
Your organization authorizes each integration, with separate scopes for reading, code changes and administration. No agent merges.
02Infrastructure and hosting
The application (app.scalequality.io) and the APIs run in ScaleQuality's AWS account, in us-east-1.
03Where each piece of data is processed
The region of each data type and each inference path. A provider's global endpoint does not guarantee processing in a specific country.
| Data or processing | Where | Note |
|---|---|---|
| Platform data, database and backups | AWS us-east-1 | Multi-AZ within the same region |
| AI Workspace history and attachments | AWS us-east-1 | Encrypted by the application before storage |
| Diagnosis and agents | Amazon Bedrock, US | Claude models through AWS cross-region inference profiles within the US |
| SQ Auto with Amazon Nova models | Amazon Bedrock, us-east-1 | Alternative in the light and medium tiers |
| AI Workspace managed catalog | Set by the model provider | Routed by OpenRouter to the provider that runs the selected model |
| Your connections (BYOK) | The region you choose | Amazon Bedrock in any AWS region. Provider APIs follow your contract with that provider |
| Transactional email | Amazon SES, us-east-1 | Invitations, alerts and digests |
| Payments | Stripe | Card data does not pass through our servers |
The region is your decision. In AI Workspace, Protection, the administrator sets the allowed providers and regions. A call outside that policy is refused before it reaches the model.
04Encryption and keys
In transit
TLS 1.2 or higher on every external connection. TLS with certificate verification between AI Workspace and the database.
At rest
Amazon RDS storage encrypted with keys managed by AWS KMS. Backups inherit the same encryption.
Conversations and attachments
AES-256-GCM in the application, with a random 96-bit nonce per write and authenticated data binding organization, owner, conversation, revision and key. The keyring supports rotation without losing older content and has no plaintext path.
Provider and connector keys
AES-256-GCM with a random IV per value. Never returned in any API response or written to logs. Rotation, disconnection and connection tests without exposing the secret.
Signed policies
Every published protection policy is signed with Ed25519 and verified on each call. Every policy expires within 30 days; once expired it blocks traffic instead of allowing it.
Verifiable evidence
Compliance dossiers carry a SHA-256 hash per file and an Ed25519 signature, verifiable with our public key without relying on the platform.
05Identity and access
06AI Workspace
More than 500 models in one place, under your organization's rules. Content, usage and inference are each handled according to their purpose.
Inference paths
Managed catalog, routed by OpenRouter to the provider that runs the model. SQ Auto, which picks among approved models by task complexity. Your connections, with your key, your invoice and your contract. Private execution, on your infrastructure.
Protection before the model
Secrets and API keys, CPF, email, card numbers and IBAN detected on input and output, with a redact or block action. Up to 20 custom rules by term or format. Optional semantic inspection in your AWS account.
Inspected responses
In Chat, the answer is released only after the complete response passes inspection and is recorded. In Code, the answer streams as it is written, like a coding tool, and the same inspection is recorded as evidence; when the organization's AI Protection sets rules for output text, Code also waits for the inspection before showing it.
Administrator controls
Allowed providers and regions, human approval for tools, models allowed per person, token limits, concurrency and monthly budget.
No training on your data
Every managed catalog call forbids use of the data for training, and the organization's AI Protection rules apply to what is sent before it reaches the provider. The provider's retention applies, always without training. The endpoint is pinned per call, with no silent provider switch.
Content-free telemetry
The gateway records usage, cost and policy decisions, without message text. Only the history you choose to keep is stored, and it is encrypted.
07In your coding tools
SQ Auto in Claude Code, Codex and Cursor
A connection generated in AI Workspace brings SQ Auto and the allowed catalog into the tool, with the same protection rules, the same balance and the same measurement. Works with any client compatible with the OpenAI APIs (Chat Completions and Responses) or the Anthropic API (Messages).
MCP in Claude Code, Codex, Cursor, VS Code, Gemini CLI and Windsurf
Authorized through OAuth in your organization. The assistant reads the repository's real measurement and dispatches agents. The agent opens a pull request with evidence and never merges.
08Your source code
Repository access, analysis and code changes follow the permissions your organization grants.
09Sub-processors
Third parties that process data on ScaleQuality's behalf. The applicable list and change conditions are set out in the data processing agreement.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Amazon Web Services | Hosting, database, storage, authentication (Cognito), email (SES) and firewall (WAF) | All platform data | us-east-1 |
| Amazon Bedrock | Inference for diagnosis, agents and SQ Auto's Amazon Nova models | Authorized code excerpts and messages sent to those models | US |
| OpenRouter | Routing of AI Workspace managed catalog calls to the model provider | Content of managed catalog calls | Set by the provider |
| Provider of the selected model | Runs the model selected in the managed catalog, such as OpenAI, Anthropic, Google, DeepSeek or Mistral | Content of the call | Set by the provider |
| Stripe | Payments and billing | Billing data | Global |
| Brave Search | Web search used by studies with cited sources | Search terms, never source code or credentials | US |
| Vercel | Marketing site hosting | Site browsing data | Global |
| Tally | Contact forms on the site | What you enter in the form | EU |
Your own connections (BYOK) and repository integrations are contracted by you; their provider acts under your contract, not as a ScaleQuality sub-processor.
10AI telemetry connectors
When your organization connects a usage and cost source, we read counts, tokens and cost. No connector reads prompts, responses or request logs. The credential is stored with AES-256-GCM and is never returned.
| Connector | Credential you create | What we read |
|---|---|---|
| Anthropic (Claude, Claude Code) | Organization Admin API key | Usage and cost per workspace |
| OpenAI (Codex and API) | Organization admin key | Cost and usage reports per project |
| Cursor | Team admin API key | Members, 30-day spend and per-event tokens |
| GitHub Copilot Business | Token with manage_billing:copilot and read:org, or a GitHub App | The organization's Copilot usage and seats |
| Google Workspace (Gemini) | Service account with domain-wide delegation, scope admin.reports.usage.readonly | Aggregated usage reports |
| Amazon Bedrock | AWS connection role with Cost Explorer and CloudWatch read access | Invoice and per-model counters |
| Azure AI Foundry | App with Cost Management Reader and Monitoring Reader | Billed cost and token counters |
| Google Vertex AI | Service account with Monitoring Viewer and read access to the billing export | Tokens per model and billed cost |
| OpenRouter | Management key | Account activity |
| LiteLLM | Key for a proxy_admin_viewer user | Daily spend and tokens per model and key |
| Cloudflare AI Gateway | Token with Account Analytics and AI Gateway, read only | Counts, tokens and cost |
| Portkey | Workspace admin API key | Daily cost and usage per model |
| Kong AI Gateway | The node's Status API address | AI Prometheus counters |
| Databricks | Service principal with SELECT on system.billing and system.ai_gateway | Billing and gateway system tables |
| Snowflake | Service user with a key pair and SELECT on the usage views | ACCOUNT_USAGE and ORGANIZATION_USAGE views |
Databricks and Snowflake run the read on a warehouse in your account, so it appears on your bill. Kong publishes counters, not history: each read measures what happened since the previous one.
11External security, cloud and intelligence
External Security measures authorized domains and configurations in connected cloud accounts. Each reading states its scope, coverage, date and methodology; an incomplete reading does not receive a full grade.
Domains require administrator authorization and DNS proof before active measurement. Public certificate and web-search discovery identifies candidate names; it does not prove IP ownership or complete inventory.
AWS uses a read role with an External ID. Azure and Google Cloud use credentials restricted to the isolated scanner. Published cloud collection results exclude secret values, object contents and raw logs.
Discovery sends the domain name to crt.sh and, when configured, Brave Search. Intelligence sends public advisory identifiers to OSV and CVE identifiers to FIRST; the CISA KEV catalog is queried without sending organization data. These queries do not send source code or cloud credentials to those sources.
CISA KEV records known exploitation of a vulnerability and EPSS estimates its exploitation somewhere in the next 30 days. These signals guide prioritization without establishing company compromise or production exposure of a package.
Network reputation is matched locally against public IP lists. We do not send the queried domain or IPs to that list provider. We retain the source, date and attribution; absence from a list does not establish absence of compromise.
Security scorecards and reports remain within the authorized organization scope. Generating a report or dossier does not publish findings in the Trust Center. Remediation requires new evidence and follows the platform review workflow.
External Security scope reviewed on September 18, 2026.
12Evidence for your security and compliance reviews
Bring together findings, inventories, access records and technical artifacts in the context of your organization. Share evidence with the people responsible for governance, risk and audit.
Continuous code security analysis, findings with CWE
Secure development and code vulnerability analysis (ISO 27001 Annex A, SOC 2, NIST SSDF)
Live inventory of vulnerable components, including container image CVEs
Third-party and software supply-chain vulnerability management (ISO 27001, EU CRA, CMN Res. 4.893)
CycloneDX SBOM per repository, when produced by the analysis
The supply-chain artifact asked for by name (FDA 524B, EO 14028, EU CRA documentation)
CI quality gate, subject to pipeline execution and repository protections
Enforcement depends on required checks and configured branch protection
Agents propose fixes with validation evidence; review and merge stay in your provider
The organization defines human approval requirements in its source provider
AI usage inventory and measured cost, with audit export (JSON, provenance-tagged)
Corporate AI inventory and monitoring (NIST AI RMF, ISO/IEC 42001, EU AI Act)
Content compliance reviews anchored to your registered rules, exported as PDF
Auditable regulatory content review (finance, health, advertising)
Platform audit trail with export, role-based access, SSO/SAML on Enterprise
Traceability and identity management (ISO 27001 logging, SOC 2, LGPD technical measures)
Versioned catalog of technical and manual controls, with scope and evidence per reference
Includes regimes and frameworks with different capabilities; a catalog entry does not establish complete coverage
Exception with an owner, a deadline and a justification when risk is knowingly accepted
Formal risk acceptance, with a maximum validity and reopening on expiry. An exception never reads as compliant
Who opened and who approved every merged change, PR by PR, with the commit
Segregation of duties in change (SOC 2 CC8.1, ISO 27001 A.8.32, CMN 4.893)
Dossier with hashes, per-source scope and attestation identifying its algorithm
Public-key verification for Ed25519 signatures; each source declares its available observation window
Compliance events delivered over a signed webhook, and the same reading through the API
Your GRC tool consumes the evidence straight from the source, with no manual collection
Each evidence source identifies its scope, reference and observation period to support the reviewer’s assessment.
13Retention and deletion
| Data | Retention |
|---|---|
| Conversations and attachments | Until you delete them. Deleting removes the content from active storage immediately |
| Database backups | 7 days. They may contain rows already deleted, always encrypted, until they expire |
| AI Workspace logs | 30 days, without message content |
| Usage, cost and billing | Kept for billing and audit, separate from content |
| Code findings and measurements | For as long as the project exists in your organization |
Your data does not train ScaleQuality models. Data subject requests take backups and legal retention obligations into account.
Security team
Security reviews, questionnaires, compliance requirements and the data processing agreement. To report a vulnerability, use the same channel: we respond and follow through to the fix.
Last reviewed: September 23, 2026