Trust Center

Security you can show a CISO.

The sandbox plane runs inside your own cloud account, so the data plane is yours; Quome operates only the control plane that schedules and monitors it.

Compliance status

Exactly where we stand. Every document below is delivered to your security team through the security review pack.

SOC 2 Type I

In progress

Audit in progress.

Controls matrix and auditor engagement letter available under NDA. Type II observation period follows the Type I report.

HIPAA

BAA available (Enterprise)

HIPAA-aligned platform. Business Associate Agreement available on the Enterprise plan for the services listed on our HIPAA Eligible Services page.

Interactive sandboxes, MCP tools and the model gateway are not HIPAA Eligible Services today. Do not place PHI in them.

Penetration testing

On request

Third-party penetration test summary available under NDA on request.

Request it with the security review pack.

Subprocessors

Published

Current list published at legal/subprocessors.

30-day notice of changes.

Data Processing Agreement

On request

Available on request.

Request the DPA →

Security questionnaire

Under NDA

Pre-filled questionnaire (CAIQ-Lite / SIG-Lite format) available under NDA.

Request the questionnaire →

Where your data lives

Quome uses a Bring Your Own Service Account (BYOSA) model. The microVMs, the VPC, the storage and the logs live in your GCP, AWS or Azure project. There is no Quome-side data plane to breach.

Your account

Data plane
  • MicroVMs — one hardware-isolated VM per run, destroyed when the run ends
  • VPC — per-run VPC isolation inside your own project, bounded by your policies
  • Storage — inputs, outputs and anything the agent writes stay in your buckets
  • KMS keys — AES-256-GCM with keys you control; secrets from your Secret Manager or Key Vault
  • Audit logs — commands, egress attempts, secret access and lifecycle events, written to logs you own

Quome control plane

Control plane
  • Scheduling metadata — which sandbox to start, where, and with which policy
  • Telemetry — only what is needed to operate and secure the service
  • Access to your cloud — federated, scoped, logged and revocable by you in seconds

Not held by Quome: your inputs, outputs, secrets and logs. They stay in your account.

Quome control plane Your cloud account Workload Identity Federation scoped · logged · revocable

What's inside the wall

Every control below is on by default for every sandbox. Nothing here is an enterprise add-on.

01

MicroVM per run

Hardware-isolated microVMs, not shared-kernel containers. One run, one VM, no neighbors.

Default
02

Network policy: isolated / outbound / full

Pick per sandbox. Isolated means no outbound path at all — there is no filter to tunnel through.

Isolated by default
03

Ephemeral by design

Sandboxes carry a TTL and are destroyed when the run ends. Nothing persists unless the agent writes to your storage.

Default
04

Your VPC, your account

Per-run VPC isolation inside your own GCP, AWS or Azure project. The blast radius is bounded by your policies, not a vendor's.

BYOSA
05

Zero stored credentials

Workload Identity Federation end to end. Secrets are injected at runtime from your Secret Manager or Key Vault and revoked on exit.

Default
06

Customer-owned encryption

AES-256-GCM with KMS keys you control. Dedicated database and cache per organization.

Default
07

Audit log for every run

Commands, egress attempts, secret access and lifecycle events, written to logs you own. Fine-grained authorization via SpiceDB.

Default
08

Scanned, signed supply chain

Container scanning, SBOMs for every image, and SLSA Level 3 signing so what runs in the box is what you approved.

Default
09

Compliance posture built in

HIPAA-aligned platform with a BAA on Enterprise, SOC 2 controls, MFA / WebAuthn and SSO. A pre-filled security questionnaire is ready for your review.

Enterprise

Shared responsibility

Security is shared between Quome, you and your cloud provider. This is who owns what.

Area Quome Customer Cloud provider
MicroVM isolation Provisions one hardware-isolated microVM per run and destroys it when the run ends Sets the TTL and reviews sandbox configuration Hypervisor and physical host security
Network policy Enforces the isolated / outbound / full policy chosen for each sandbox; isolated by default Chooses the policy per sandbox and owns VPC and firewall rules in the account VPC networking fabric
Identity & keys Workload Identity Federation end to end; secrets injected at runtime and revoked on exit; no stored credentials Owns KMS keys, Secret Manager / Key Vault contents and IAM policies; can revoke Quome's access at any time KMS, IAM and secret-store services
Data & backups Holds scheduling metadata and telemetry only; never your inputs, outputs, secrets or logs Owns the storage agents write to, plus retention and backup of that data Durability and availability of storage services
Agent code & prompts Runs what you submit inside the sandbox; scans, SBOMs and signs the images it ships Authors and reviews agent code, prompts, tool permissions and any data the agent is given —
Audit log retention Writes commands, egress attempts, secret access and lifecycle events to logs in your account Sets retention, export and SIEM forwarding for those logs Logging service availability
Cloud account security Uses only federated, scoped, logged and revocable access to the account Account hardening, MFA, organization policies and billing controls Physical, regional and platform infrastructure

If a control you care about is not in this table, ask before you assume. The security review pack includes the full controls matrix.

Responsible disclosure and contacts

If you believe you have found a vulnerability in Quome, report it privately to security@quome.site. We acknowledge every report within 2 business days, keep you informed as we work through it, and will not pursue legal action against researchers acting in good faith.

Vulnerability reports

Private reports from security researchers and customers

security@quome.site
Send Email →

Audit and questionnaire requests

Security review pack, controls matrix, DPA and BAA requests

compliance@quome.site
Send Email →

Incident response

Active incidents affecting your sandboxes or account

incident@quome.site
Send Email →

Bring your security team to the demo.

Our forward-deployed engineers walk through the isolation model, deploy the sandbox plane into your VPC and deliver the security review pack.