Security

We run inside the rules you set.

Before you sign us off you need four answers: where Q-Risk runs, which model it uses, what the guardrails forbid, and what the run record keeps.

01

You choose where Q-Risk runs.

Q-Risk is the same product in all five hosting options. The only change is where your data sits and who operates the boundary.

DeploymentOur boundaryYour boundary
  • Multi-tenant SaaSShared platform we operate
  • Dedicated instanceYour instance, we operate
  • Your own VPCYour network and your keys
  • Your private cloudYour cloud, your control
  • Fully on-premYour site, no data leaves

02

The engine runs on any model you pin.

Which model drives a run is a setting you choose when you deploy. Q-Risk records the pinned version on every figure.

  • Hosted frontier model
  • Local open-weight model
  • A model you bring

03

The model cannot cross these limits.

The policy layer sits in the engine, between the model and your estate. Nothing reaches your systems until that layer clears it.

  • Reachable systemsThe run cannot leave the list you signed off.
  • Allowed actionsIt can show damage, but it cannot cause an outage.
  • Readable dataThe engine proves access without copying contents.
  • Recorded actionsEvery attempted action is kept, whether it worked or failed.

04

The run leaves a full record.

The run record stores every action taken, every path that failed, and every path that worked. It also shows how each pound figure was built.

05

The estate data a run needs.

Q-Risk reads how systems are arranged, who can reach them, and which processes they serve.

What it reads

  • Configuration
  • Topology
  • Identities
  • Dependencies
  • Process maps

What it never reads

  • Customer records
  • Datastore contents
  • Document bodies

06

Answers for DORA and the FCA.

Supervisors ask what you tested and what it would cost. The run record answers both.

  • DORATest your own ICT resiliencePaths proved against your live estate
  • DORAKnow the impact of ICT failurePounds of impact per business process
  • FCAOwn operational risk with evidenceA dated record of every attack tried

Send us the questions that block sign-off.