The sandbox plane runs inside your own cloud account, so the data plane is yours; Quome operates only the control plane that schedules and monitors it.
Exactly where we stand. Every document below is delivered to your security team through the security review pack.
Audit in progress.
Controls matrix and auditor engagement letter available under NDA. Type II observation period follows the Type I report.
HIPAA-aligned platform. Business Associate Agreement available on the Enterprise plan for the services listed on our HIPAA Eligible Services page.
Interactive sandboxes, MCP tools and the model gateway are not HIPAA Eligible Services today. Do not place PHI in them.
Third-party penetration test summary available under NDA on request.
Request it with the security review pack.
Pre-filled questionnaire (CAIQ-Lite / SIG-Lite format) available under NDA.
Request the questionnaire →Quome uses a Bring Your Own Service Account (BYOSA) model. The microVMs, the VPC, the storage and the logs live in your GCP, AWS or Azure project. There is no Quome-side data plane to breach.
Not held by Quome: your inputs, outputs, secrets and logs. They stay in your account.
Every control below is on by default for every sandbox. Nothing here is an enterprise add-on.
Hardware-isolated microVMs, not shared-kernel containers. One run, one VM, no neighbors.
DefaultPick per sandbox. Isolated means no outbound path at all — there is no filter to tunnel through.
Isolated by defaultSandboxes carry a TTL and are destroyed when the run ends. Nothing persists unless the agent writes to your storage.
DefaultPer-run VPC isolation inside your own GCP, AWS or Azure project. The blast radius is bounded by your policies, not a vendor's.
BYOSAWorkload Identity Federation end to end. Secrets are injected at runtime from your Secret Manager or Key Vault and revoked on exit.
DefaultAES-256-GCM with KMS keys you control. Dedicated database and cache per organization.
DefaultCommands, egress attempts, secret access and lifecycle events, written to logs you own. Fine-grained authorization via SpiceDB.
DefaultContainer scanning, SBOMs for every image, and SLSA Level 3 signing so what runs in the box is what you approved.
DefaultHIPAA-aligned platform with a BAA on Enterprise, SOC 2 controls, MFA / WebAuthn and SSO. A pre-filled security questionnaire is ready for your review.
EnterpriseIf you believe you have found a vulnerability in Quome, report it privately to security@quome.site. We acknowledge every report within 2 business days, keep you informed as we work through it, and will not pursue legal action against researchers acting in good faith.
Private reports from security researchers and customers
Security review pack, controls matrix, DPA and BAA requests
Active incidents affecting your sandboxes or account
Our forward-deployed engineers walk through the isolation model, deploy the sandbox plane into your VPC and deliver the security review pack.