Security

Security claims must be measurable. We do not use “100% secure” or “quantum-proof” as marketing labels.

Security programme

  • Asset and data inventory
  • Threat modelling
  • Least-privilege IAM
  • MFA and privileged-access controls
  • Secrets and key lifecycle management
  • SBOM and dependency provenance
  • Vulnerability management
  • Backup and restore testing
  • Incident response
  • Independent testing where required

Post-quantum readiness

We are designing for crypto-agility and hybrid post-quantum migration. Each connection and component will be tracked separately; only verified implementations will be described as active.


QUARK Security Principle

Zero-trust applies to models and tools as well as users and networks. QUARK treats prompt injection and untrusted content as tainted inputs, scopes tool capabilities, and rejects the idea that a persuasive model output is itself security evidence.