QNSI

TrustHub

Enterprise assurance, with the boundaries visible.

Security due diligence should not require interpreting marketing language. This hub identifies what QNSI publishes, what each artifact demonstrates, how it can be accessed, and where independent validation has not been completed.

Public assurance modelEvidence before claims

Every artifact carries a status, scope boundary, access class, and review date.

Role-based diligence

Start with the question your team is accountable for

Architecture, cryptography, engineering, audit, and procurement reviews use one evidence vocabulary and one public/private boundary.

One-stop assurance

Security, compliance, evidence, operations, and governance

Start with the area relevant to your review. TrustHub keeps public assurance material and its stated evidence boundary in one navigable place.

Evidence taxonomy

What the statuses mean

These labels prevent a control mapping, operating statement, or standards implementation from being mistaken for an independent certification.

Public evidence

A published artifact with a stated verification method and scope.

Operational / self-assessed

A QNSI statement or mapping, not an independent auditor conclusion.

Review required

Counsel, assessor, or customer-scope review remains outstanding.

Not verified / not completed

No completed external artifact is available; QNSI does not claim otherwise.

Assurance registry

Documents, evidence, and current gaps

Filter mentally by category or access class; every entry below uses the same disclosure contract.

  • Security
  • Compliance
  • Privacy
  • Reliability
  • Cryptography
  • Legal
SecurityOperational statement

Public reference architecture packet

Cloud, VPC-peered, private-endpoint, on-premises, and air-gapped reference flows with trust, responsibility, and qualification boundaries.

Evidence boundaryArchitecture and responsibility documentation. Only QNSI Cloud is the default public service; enterprise topologies require deployment-specific qualification.
Access: PublicReviewed: 2026-08-04
Open artifact
SecurityOperational statement

Enterprise diligence index

Public architecture, security, cryptographic evidence, operations, legal, licensing, provenance, and known-gap references for technical evaluation.

Evidence boundaryAn index of available public material, not an independent certification, audit opinion, or customer-specific security response.
Access: PublicReviewed: 2026-08-04
Open artifact
SecurityPublic evidence

Public source provenance and checksums

Private source revision, export inventory, and SHA-256 checksum file for the reviewed public repository surface.

Evidence boundaryProves the bytes and private source revision recorded by the exporter. It is not a signed build attestation or proof of hosted-service deployment.
Access: PublicReviewed: 2026-08-04
Open artifact
SecurityOperational statement

Security program overview

Shared responsibility, data handling, access-control, key-management, and incident-response statements.

Evidence boundaryPublished description of current operating practices; not an external audit report.
Access: PublicReviewed: 2026-07-29
Open artifact
ComplianceSelf-assessed

Framework control mappings

Engineering mappings for SOC 2, ISO 27001, GDPR, PCI DSS, HIPAA, PDPA, and MAS TRM.

Evidence boundaryControl mappings support assessment work; they are not certifications or legal opinions.
Access: PublicReviewed: 2026-07-29
Open artifact
CryptographyPublic evidence

PQC conformance evidence

Re-runnable test-vector results for the cryptographic providers and algorithms identified on the evidence page.

Evidence boundaryAlgorithm-level evidence only. It does not represent CMVP certification or prove every production path.
Access: PublicReviewed: 2026-07-29
Open artifact
CryptographyPublic evidence

Reproducible performance benchmarks

Published methodology and results for supported post-quantum operations.

Evidence boundaryEvidence applies to the recorded build, environment, and benchmark method.
Access: PublicReviewed: 2026-07-29
Open artifact
CryptographyOperational statement

Entropy-chain documentation

Documented randomness sources, standards references, and deployment-specific boundaries.

Evidence boundaryArchitecture documentation; provider and deployment qualification remains scope-specific.
Access: PublicReviewed: 2026-07-29
Open artifact
PrivacyPending counsel review

Privacy and processing terms

Privacy Policy, Data Processing Addendum, retention policy, and sub-processor disclosure.

Evidence boundaryPublished terms include documents whose review status is pending qualified counsel.
Access: PublicReviewed: 2026-07-29
Open artifact
LegalPending counsel review

Legal terms and policy register

Terms of Service, privacy and processing terms, governance policies, security commitments, and operating policies.

Evidence boundaryPublished documents are authoritative QNSI terms; documents marked pending counsel have not received qualified legal review.
Access: PublicReviewed: 2026-07-30
Open artifact
ReliabilityOperational statement

Service status

Current availability telemetry for QNSI Cloud services.

Evidence boundaryOperational telemetry is not an independent availability attestation or an SLA report.
Access: PublicReviewed: 2026-07-29
Open artifact
ReliabilityNot completed

Verified customer deployment case study

Customer-approved account of a production deployment with independently supportable architecture, outcome, and evidence scope.

Evidence boundaryNo customer deployment case study meeting QNSI's public proof standard is currently published. Reference scenarios are not represented as customer deployments.
Access: UnavailableReviewed: 2026-08-04
No artifact available
SecurityNot completed

Independent penetration test

Independent testing of the migrated production endpoints and resulting remediation evidence.

Evidence boundaryNo completed independent production-endpoint penetration-test report is published.
Access: UnavailableReviewed: 2026-07-29
No artifact available
ComplianceNot independently verified

SOC 2 examination

Independent auditor examination and resulting report.

Evidence boundaryQNSI does not currently publish a SOC 2 report or claim SOC 2 certification.
Access: UnavailableReviewed: 2026-07-29
No artifact available
SecurityOperational statement

Security questionnaire and architecture package

Scoped security responses and architecture material for active procurement reviews.

Evidence boundaryPrepared against the requested scope; claims remain subject to their stated evidence status.
Access: Request requiredReviewed: 2026-07-29
Start request

Procurement

Need a scoped assurance package?

QNSI can route security questionnaires, architecture requests, contractual documents, and audit-evidence questions through one intake. Requested material is only represented as available when it actually exists.