Request assessment
Security

System Boundaries First.

Qualimetrix documents where data is processed, who can reach it, how long artefacts are kept and what risk remains. It does not replace identity, endpoint, infrastructure or software-supply-chain security.

Deployment

Three boundaries, stated before contract.

Managed serviceQualimetrix operates the control plane; production records stay inside the customer cluster.
Private cloudThe suite is installed in the customer account and region, operated by the customer platform team.
On-premisesAir-gapped installation with signed artefacts and a release record produced locally.
Controls

What is documented per deployment.

Documented

Six things a reviewer asks for.

  • Where source data is processed
  • Who can access it
  • How long artefacts are retained
  • Which sub-processors are involved
  • How keys are held and rotated
  • What is logged, and for how long
Cryptography

Keys stay in customer custody.

Generation, rotation and revocation run against the customer KMS or HSM. The PQC Gateway holds no long-term private key of its own, and negotiation is recorded per zone.

Residual risk

Documented controls reduce risk; they do not remove it. Residual risk is stated per deployment, and a control that has not been tested is recorded as untested rather than as present.

Reporting

Responsible disclosure.

Read the policy

Reports go to compliance@qualimetrix.nl. Qualimetrix acknowledges a report, states whether it is in scope, and reports back on remediation. Certification status is stated plainly: ISO/IEC 27001 is in preparation and is not held today.

See how Continuum can change what your data has to travel as.

Bring the workload, data boundary and decision the evidence must support.

Custom assessmentEvidence-backed scopeClear next step