Skip to content
Theos Quantum Θ mark

Assurance Center

The evidence we can show today, and the dated commitments for what we cannot.

We are an early-stage company and have not completed a third-party audit of any kind. Every section below either states a control we genuinely operate, or marks the fact as a placeholder — never the other way around.

Where we actually are

Theos Quantum is a five-person, early-stage company. No SOC 2 report, no ISO/IEC 27001 certificate, and no other independent audit opinion exists over us today. Rather than stay quiet about that or reach for a badge we have not earned, this page publishes the control register, the framework mapping, and the live posture facts we can actually stand behind — with every fact we cannot yet verify written as an explicit [PLACEHOLDER: …] rather than a guess.

Control register · at a glance

Counted plainly, including what is not finished.

Every control below sits in exactly one of four states — Implemented, Partial, Planned, or Not applicable — or is written as its own placeholder where the status depends on a fact we have not confirmed. Nothing is hidden from this count.

Implemented

8

Partial

1

Planned

1

Not applicable

1

Unconfirmed

22

Register size

33 controls tracked today. Most read Unconfirmed, not Implemented — that is an honest reflection of a five-person company's current maturity, not a rendering error.

The control register

Every control, its status, and where it maps.

Grouped into eleven families — governance, access control, cryptography, software supply chain, infrastructure and network, data handling and retention, logging and monitoring, vulnerability management, business continuity, incident response, and personnel — condensed here into the eight operating domains below. Filter by domain or by the framework you are checking against.

Governance & riskAccess & identityCryptography & key managementEngineering & product securityData handling & privacyResilience & continuityThird parties & supply chainPeople & awareness

Filter by domain

Filter by framework mapping

33 of 33 controls
IDControlStatusFramework mapping
TQ-GOV-01A single, versioned assessment methodology (theos-method-v1.0) defines how every exposure score the product produces is calculated, and is published in full rather than kept proprietary.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-GOV-02Executive accountability for the security and privacy program is assigned to a named individual and documented.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0DPDP 2023
TQ-GOV-03Security and privacy risks to the product and the company are assessed on a defined cadence, and the results feed the roadmap.Unconfirmed
SOC 2NIST 800-53NIST CSF 2.0
TQ-GOV-04Management reviews the company's security posture on a fixed schedule and records the outcome.Unconfirmed
SOC 2NIST 800-53NIST CSF 2.0
TQ-ACC-01The product enforces role-based access control so a workspace member sees only the projects and data their role grants.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-ACC-02A customer workspace can authenticate through the customer's own identity provider by single sign-on rather than a Theos-managed password.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-ACC-03Administrative access to internal production infrastructure requires multi-factor authentication.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-ACC-04Access entitlements to internal systems are reviewed on a defined cadence and revoked promptly on role change or departure.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-CRY-01The product implements NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for the post-quantum algorithms it evaluates and recommends.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-CRY-02Data in transit between a customer, the AutoPQC application and its APIs is encrypted with TLS.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-CRY-03Customer data at rest is encrypted, and the key-management approach behind that encryption is documented.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-CRY-04Cryptographic keys used by internal systems are generated, rotated and retired under a documented key-management standard.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-ENG-01Changes to the product go through code review before release.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-ENG-02Material releases run through automated security scanning before shipping; manual security review coverage beyond that is inconsistent today.Partial
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-ENG-03An independent third party has tested the product for exploitable vulnerabilities.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-ENG-04A public channel exists for anyone to report a suspected vulnerability, and it is read and answered by a person.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-DAT-01Our data-handling practices — what we collect, why, and for how long — are published in full, not summarized behind a login.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0DPDP 2023
TQ-DAT-02Customer data is retained only as long as needed for the engagement, then deleted or anonymized on a defined schedule.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0DPDP 2023
TQ-DAT-03Cryptographic discovery is scoped to configuration and certificate metadata needed to build the inventory; it is not designed to require access to unencrypted business documents.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0DPDP 2023
TQ-DAT-04Any transfer of customer personal data outside its country of collection follows a documented legal transfer mechanism.Unconfirmed
ISO 27001SOC 2NIST CSF 2.0DPDP 2023
TQ-DAT-05AutoPQC is sold and operated as an enterprise B2B product; it is not directed at children and does not knowingly process a child's personal data, so child-specific consent safeguards do not apply to it.Not applicable
DPDP 2023
TQ-RES-01A documented incident response process defines how a security incident is triaged, contained and communicated.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0DPDP 2023
TQ-RES-02Platform data is backed up on a defined schedule, with recovery tested periodically.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-RES-03A business-continuity and disaster-recovery plan covers loss of key infrastructure or personnel.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-RES-04Roadmap. A public status page for ongoing incidents and scheduled maintenance is not yet live. [PLACEHOLDER: target date]Planned
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-TPR-01Every subprocessor that can reach customer data is listed on this page, with purpose, data category, jurisdiction and transfer basis, rather than referred to a generic sub-processor URL.Implemented
ISO 27001SOC 2NIST 800-53NIST CSF 2.0DPDP 2023
TQ-TPR-02New or changed subprocessors are announced in advance of go-live, with a stated notice period.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-TPR-03Vendors that can reach customer data sign a data-processing agreement before onboarding.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0DPDP 2023
TQ-TPR-04Vendor security posture is reassessed on a defined cadence, not only at onboarding.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-PPL-01Personnel with access to production systems or customer data undergo a background check before that access is granted.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-PPL-02All personnel complete security and privacy awareness training, refreshed on a defined cadence.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-PPL-03Access to internal systems is revoked on the day an employee's or contractor's engagement ends.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0
TQ-PPL-04Personnel and contractors with access to customer data sign confidentiality obligations before that access is granted.Unconfirmed
ISO 27001SOC 2NIST 800-53NIST CSF 2.0

Hover a framework chip for the specific clause it maps to.

Framework mapping

Cross-referenced against the frameworks a reviewer actually asks about.

Each control above carries a mapped clause where one applies. Hover a framework chip in the register for the exact reference.

ISO 27001

ISO/IEC 27001:2022, Annex A

SOC 2

SOC 2 Trust Services Criteria

NIST 800-53

NIST SP 800-53 Rev. 5

NIST CSF 2.0

NIST Cybersecurity Framework 2.0

DPDP 2023

India's Digital Personal Data Protection Act, 2023

A mapping is not a certification.

This is a mapping, not a certification. No accreditation body has reviewed these mappings, no auditor has tested them, and no audit opinion exists over any control below. Treat the framework column as a cross-reference for your own gap analysis, not as evidence of attainment.

[PLACEHOLDER: target date for any independent audit or certification attempt — none is committed to today]

Live posture panel

What we can state about our own posture, and how we know it.

Each tile is tagged with how the fact is known: self-reported (we checked our own repository), publicly verifiable (check it yourself), or an explicit placeholder. We checked next.config.mjs, middleware, and vercel.json directly rather than assuming a header we do not send.

Transport

Self-reported

Every route on this site is served over HTTPS; there is no HTTP-only page or asset.

Confirmed by inspecting the application's own routes. Whether the hosting layer additionally redirects a bare HTTP request is a platform behaviour outside this codebase.

HSTS (Strict-Transport-Security)

Self-reported

Not set by application code. This codebase defines no headers() rule and no middleware that emits a Strict-Transport-Security header.

Checked next.config.mjs, middleware.ts and vercel.json — none exist or none configure this header. Any HSTS header a browser sees today comes from the hosting platform's own default, not from a policy we set.

Security-header position

Self-reported

No Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy or Permissions-Policy header is configured in this codebase.

This is a genuine gap, not an oversight we are hiding. [PLACEHOLDER: date a header policy will be added and by whom]

Third-party trackers

Self-reported

None. No analytics, advertising or session-replay SDK ships in this codebase; optional analytics is a same-site, opt-in toggle with no default-on tracking.

Confirmed against package.json dependencies and the cookie-consent implementation — see the Cookie Policy for the full accounting.

RFC 9116 security.txt

Publicly verifiable

Published at /.well-known/security.txt, pointing to the disclosure policy at /security.

Fetch it directly rather than trusting this line.

Minimum TLS version served

Placeholder

[PLACEHOLDER: confirm the minimum TLS protocol version enforced at the hosting/CDN edge]

Our own crypto-agility stance

Self-reported

AutoPQC's ML-KEM, ML-DSA and SLH-DSA support sits behind a single internal interface so a future parameter or standard change does not require rewriting call sites across the product.

A design commitment we hold ourselves to; it has not been independently verified by a third party.

Posture history

A short, honest timeline — not a padded one.

This strip records only dated events we can substantiate: publication dates for the method and this site's own trust pages. There is not much history yet, because the company is new; we show that plainly rather than shading in months that had nothing happen. Dated changes going forward are recorded in full at the Signal Log.

CheckpointFeb 2026Mar 2026Apr 2026May 2026Jun 2026Jul 2026
Theos Method publication
Assurance Center published
Security & Disclosure channel published
Independent third-party audit
Certification attained

Two rows out of five have anything to show, and only in the most recent month — because that is when those things actually happened; we are not going to shade in earlier months to make the grid look busier.

See every dated change, including standards and site updates, at the Signal Log.

Subprocessor register

Every category of vendor that can reach customer data.

We do not publish vendor names on this page yet — each is marked as a placeholder below — but the categories are the true, necessary set for operating a hosted product: application hosting, transactional email, product analytics, support tooling, and error monitoring.

SubprocessorPurposeData category reachedJurisdictionTransfer basisDPA status
[PLACEHOLDER: cloud hosting provider name]Cloud hosting and compute for the AutoPQC applicationAccount data; cryptographic inventory metadata[PLACEHOLDER: hosting region/country][PLACEHOLDER: transfer mechanism, e.g. standard contractual clauses][PLACEHOLDER: DPA execution status]
[PLACEHOLDER: transactional email provider name]Transactional and account-notification email deliveryName; work email address; notification content[PLACEHOLDER: hosting region/country][PLACEHOLDER: transfer mechanism][PLACEHOLDER: DPA execution status]
[PLACEHOLDER: product analytics provider name]Product usage analytics to improve the applicationDe-identified usage events[PLACEHOLDER: hosting region/country][PLACEHOLDER: transfer mechanism][PLACEHOLDER: DPA execution status]
[PLACEHOLDER: support/ticketing provider name]Customer support and ticket handlingContact details; content of submitted support requests[PLACEHOLDER: hosting region/country][PLACEHOLDER: transfer mechanism][PLACEHOLDER: DPA execution status]
[PLACEHOLDER: error-monitoring/observability provider name]Application error monitoring and observabilityApplication error logs, which may include technical metadata[PLACEHOLDER: hosting region/country][PLACEHOLDER: transfer mechanism][PLACEHOLDER: DPA execution status]

Our commitment on subprocessor changes

We commit to announcing a new or changed subprocessor in advance of go-live, with a notice period of [PLACEHOLDER: advance-notice period for subprocessor additions or changes, in days]. Full data-handling detail — what we collect, why, and for how long — is published at our Privacy Policy.

Document room

The artefacts a reviewer asks for — honestly marked.

No portal, no login, no invented download link. Where a document does not exist yet, it says so.

DocumentWhat it would coverAvailabilityNote
Security & assurance overviewThis Assurance Center and the Security & Disclosure policy, together, are our overview today.PublishedSee /assurance and /security. A separate PDF whitepaper does not exist yet.
Architecture overview documentA written description of the AutoPQC application, data flow and hosting architecture, suitable for a security review.Not yet produced[PLACEHOLDER: target date and intended audience — NDA-gated or public]
Data processing addendum (DPA) templateA standard DPA a customer can execute alongside a master agreement.Not yet produced[PLACEHOLDER: whether a standard template exists yet or is drafted per deal]
Penetration-test summaryA summary of findings from an independent penetration test of the product.Not yet producedNo independent penetration test has been performed as of today — see control TQ-ENG-03.
Business continuity / disaster recovery summaryA summary of our plan for loss of key infrastructure or personnel.Not yet producedSee control TQ-RES-03.
Certificate of insuranceEvidence of cyber and/or errors-and-omissions insurance coverage.Not yet produced[PLACEHOLDER: confirm whether a policy is in place and who can issue a certificate]
Completed CAIQ or SIG questionnaireA standard vendor-security questionnaire, filled in against the control inventory on this page.On request under NDAWe will complete a CAIQ or SIG directly from the control register above rather than a separately maintained answer set — request one through /contact.

Request anything above, or ask a question we have not anticipated, at Contact. Vulnerability reports go to Security & Disclosure instead.

Security questionnaires

What we will do, and what we will not.

Typical turnaround for a completed questionnaire: [PLACEHOLDER: standard turnaround time for a completed questionnaire, in business days].

We will

  • Confirm in writing which controls in the inventory above are implemented, partial, planned or not applicable, as of the date we answer — not as of whenever the page was last edited.
  • Hand over the subprocessor and data-flow table above in a portable format on request.
  • State plainly where we do not yet meet a requirement, instead of leaving the field blank.
  • Point to the exact clause of theos-method-v1.0 behind any scoring or exposure claim you are checking.

We will not

  • Sign a questionnaire attestation for a control we have not implemented.
  • Claim a certification — SOC 2, ISO/IEC 27001 or otherwise — that we do not hold.
  • Invent an uptime figure, an audit date or a subprocessor name to fill a field. If we do not know it yet, we mark it [PLACEHOLDER] and tell you so directly.

What we do not claim

The strongest section on this page.

These are not gaps we forgot to fill. They are deliberate limits we hold ourselves to, in our marketing, our reports, and any conversation a member of our team has with you.

No completed third-party audit

No SOC 2 report, ISO/IEC 27001 certificate, or other independent audit opinion exists over Theos Quantum or AutoPQC today. Nothing on this site should be read as implying one does.

No bug-bounty payouts

There is no paid bug-bounty program, so there are no payouts to report. The only disclosure channel today is the one described at /security.

We do not claim anyone becomes "quantum-safe"

Buying or running AutoPQC does not make an organisation quantum-safe, for us or for any customer. We measure, prioritise and prove performance impact; migration itself is what changes an estate's posture, and it is carried out by the customer's own engineers.

We do not guarantee complete discovery

A discovery run finds what its detectors are built to find, across the surface it was pointed at. It does not claim to find every cryptographic instance in an estate, and it says nothing about systems outside its scope.

Scores are decision aids, not verdicts

An exposure score, a risk tier and a Posture Attestation each rank or describe measured conditions at a point in time under a named method version. None of them is a determination that a system is safe, compliant, or free of vulnerability.

No published uptime SLA

We do not publish an uptime percentage or a response-time service level commitment on this site. Any commitment made to a specific customer lives in that customer's contract, not here.

The full standard we hold our language to — including the countdown clocks and invented statistics we refuse to use — is published at Claims we refuse to make. To report an issue with anything above, use Security & Disclosure.

Also still missing today

  • No SOC 2 or ISO/IEC 27001 certification. We have not completed or attained either. If a future report exists, its date and scope will replace this line — not a certification badge added quietly elsewhere on the site.
  • No published independent penetration test. No third-party test result for the product is available today. The control row above records this as a placeholder rather than a checkmark.
  • No bug-bounty program. The disclosure channel at /security is the only route for reporting a vulnerability today; there is no paid bounty program behind it.
  • No public status page. Ongoing incidents and maintenance windows are not yet communicated through a dedicated public status page. This is on the roadmap, with no date to publish until we can commit to one.
  • No dedicated security or compliance hire. Accountability for the security and privacy program currently sits at founder level, not with a dedicated in-house security or compliance function.
  • No published data-residency guarantee. Hosting region and cross-border transfer specifics are marked [PLACEHOLDER] above until we can confirm and commit to them in writing.
  • No published SLA. We do not publish an uptime or response-time service level agreement today. Any commitment made to a specific customer lives in that customer's contract, not on this page.
  • Most control statuses below are placeholders, not checkmarks. A large share of the control inventory above reads [PLACEHOLDER: confirm …] rather than “implemented.” We would rather show that gap than fill it in early.

Ask us the question this page did not answer.

If a control, a document, or a subprocessor detail is not covered above, tell us directly rather than guessing from the page.