Trust Center · boundaries
What this site does not claim.
No company-held SOC 2, ISO 27001, FedRAMP, or CMMC certification is claimed here. Public pages stop at health endpoints, the signing key, legal record, and a controlled diligence path.
Trust and procurement room
Follow the buyer question to the public record or one controlled request.
Public artifacts stay public. Buyer-specific questionnaires, architecture, and customer-authorized material use one governed diligence path.
Certification boundary
Not claimed
Qtonic Quantum does not claim company-held SOC 2, ISO 27001, FedRAMP, CMMC, or equivalent certification on the public site.
Inspect evidence boundaryLab proof health
Public endpoint
The Lab health endpoint exposes current public proof-service liveness. No synthetic uptime percentage is published without an auditor-attested measurement window.
Probe Lab healthQStrike health
Public endpoint
The QStrike endpoint exposes runtime health. It does not imply connected quantum hardware, live provider execution, or a client-key break.
Probe QStrike healthProof signing key
Active Ed25519 public key
The active Ed25519 public key is published in machine-readable form so Lab proof signatures can be independently checked.
Open public keyLegal record
Public policies
Privacy, data-processing, terms, subprocessors, vulnerability disclosure, and related legal boundaries are indexed in one public legal surface.
Review legal recordControlled diligence
Buyer-specific review
Security questionnaires, architecture evidence, customer-authorized references, and environment-specific material move through controlled diligence—not public marketing.
Request diligenceSecurity maturity
Bug bounty status lives next to trust facts
Coordinated disclosure and bounty posture are part of how buyers evaluate operational maturity. See the current public status and scope.
Open bug bounty status →