Security
Security claims must be measurable. We do not use “100% secure” or “quantum-proof” as marketing labels.
Security programme
- Asset and data inventory
- Threat modelling
- Least-privilege IAM
- MFA and privileged-access controls
- Secrets and key lifecycle management
- SBOM and dependency provenance
- Vulnerability management
- Backup and restore testing
- Incident response
- Independent testing where required
Post-quantum readiness
We are designing for crypto-agility and hybrid post-quantum migration. Each connection and component will be tracked separately; only verified implementations will be described as active.
QUARK Security Principle
Zero-trust applies to models and tools as well as users and networks. QUARK treats prompt injection and untrusted content as tainted inputs, scopes tool capabilities, and rejects the idea that a persuasive model output is itself security evidence.