Verified customer deployment case study
Customer-approved account of a production deployment with independently supportable architecture, outcome, and evidence scope.
TrustHub
Security due diligence should not require interpreting marketing language. This hub identifies what QNSI publishes, what each artifact demonstrates, how it can be accessed, and where independent validation has not been completed.
Every artifact carries a status, scope boundary, access class, and review date.
Role-based diligence
Architecture, cryptography, engineering, audit, and procurement reviews use one evidence vocabulary and one public/private boundary.
Trust boundaries, request flow, service planes, deployment axes, and customer/QNSI responsibilities.
Reference architectures →Security and cryptographyConformance runners, benchmark data, provider boundaries, capability maturity, and explicit gaps.
Verification hub →Platform engineeringSDKs, CLI, MCP, agents, request lifecycle, local examples, and governed migration contracts.
Developer platform →Risk, audit, and complianceControl mappings, audit-event contracts, evidence status, public artifacts, and independent-assessment gaps.
Compliance mappings →Procurement and technical diligenceCapability registry, security package index, licensing, status, disclosure, provenance, and request paths.
Diligence index →One-stop assurance
Start with the area relevant to your review. TrustHub keeps public assurance material and its stated evidence boundary in one navigable place.
Security practices, shared responsibility, controls, incident response, and disclosure.
Framework mappings, control coverage, audit boundaries, and assessment status.
Public cryptographic evidence, conformance results, benchmarks, and verification.
Privacy terms, processing commitments, retention, deletion, and sub-processors.
Service availability, operational telemetry, continuity, and support commitments.
Binding terms, policies, contractual documents, and governance commitments.
Evidence taxonomy
These labels prevent a control mapping, operating statement, or standards implementation from being mistaken for an independent certification.
A published artifact with a stated verification method and scope.
A QNSI statement or mapping, not an independent auditor conclusion.
Counsel, assessor, or customer-scope review remains outstanding.
No completed external artifact is available; QNSI does not claim otherwise.
Assurance registry
Filter mentally by category or access class; every entry below uses the same disclosure contract.
Cloud, VPC-peered, private-endpoint, on-premises, and air-gapped reference flows with trust, responsibility, and qualification boundaries.
Public architecture, security, cryptographic evidence, operations, legal, licensing, provenance, and known-gap references for technical evaluation.
Private source revision, export inventory, and SHA-256 checksum file for the reviewed public repository surface.
Shared responsibility, data handling, access-control, key-management, and incident-response statements.
Engineering mappings for SOC 2, ISO 27001, GDPR, PCI DSS, HIPAA, PDPA, and MAS TRM.
Re-runnable test-vector results for the cryptographic providers and algorithms identified on the evidence page.
Published methodology and results for supported post-quantum operations.
Documented randomness sources, standards references, and deployment-specific boundaries.
Privacy Policy, Data Processing Addendum, retention policy, and sub-processor disclosure.
Terms of Service, privacy and processing terms, governance policies, security commitments, and operating policies.
Current availability telemetry for QNSI Cloud services.
Customer-approved account of a production deployment with independently supportable architecture, outcome, and evidence scope.
Independent testing of the migrated production endpoints and resulting remediation evidence.
Independent auditor examination and resulting report.
Scoped security responses and architecture material for active procurement reviews.
Legal & governance
23 published documents are indexed here directly from QNSI's legal source of truth. Review status and effective dates remain governed by each document.
The contract governing use of QNSI.
Effective 2026-06-01How HEOSSI handles personal data as controller.
Effective 2026-06-01Processor terms for Customer Data, including the sub-processor disclosure.
Effective 2026-06-01Cookies, analytics, and consent controls.
Effective 2026-06-01Who the data controller legally is, its Singapore UEN, and the designated Data Protection Officer's business contact - as required by the PDPA and GDPR.
The current, complete list of third parties that process Customer Data on QNSI's behalf, their purpose, region, and cross-border transfer mechanism.
QNSI is offered internationally, subject to applicable export-control, sanctions, end-use, and licensing requirements.
QNSI contracts are governed by Singapore law. Disputes are resolved by arbitration in Singapore under the SIAC Rules - a neutral, globally enforceable forum.
What you may not do with QNSI Cloud - and what happens if you do. Applies to every plan, including the free tier.
How to report a security vulnerability in QNSI, what we commit to in return, and the safe harbour that protects good-faith research.
Whether QNSI trains models on your data (it does not), how customer AI workloads are isolated, and what leaves the enclave.
How long QNSI keeps each class of data, what happens when you delete something or close your account, and the limits of deletion in a tamper-evident system.
How QNSI detects, contains, and communicates a security incident - including the notification timelines we commit to.
How QNSI is architected to survive failure, how we recover, and what we do not yet promise.
QNSI's accessibility commitment, the standard we build to, known gaps, and how to report a barrier.
How subscriptions renew, how cancellation works, when fees or credits may be refunded, and what happens to data after a downgrade or termination.
The shared-responsibility boundary for accounts, keys, applications, users, integrations, and regulated workloads.
Support scope, severity handling, maintenance notices, and the difference between response targets and contractual guarantees.
Availability measurement, exclusions, service credits, claim procedure, and the plans eligible for contractual SLA coverage.
How HEOSSI evaluates legal demands for customer information and when customers are notified.
How rights holders can report alleged infringement and how customers can respond.
Consent, identification, opt-out, and Singapore Do Not Call requirements for QNSI marketing.
HEOSSI's business-conduct commitments - the ones enterprise and government procurement will ask you to evidence.
Procurement
QNSI can route security questionnaires, architecture requests, contractual documents, and audit-evidence questions through one intake. Requested material is only represented as available when it actually exists.