Skip to main content
Enterprise Sales

Procurement Pack

Everything your procurement, security, and legal teams need to evaluate QCOS. Download technical documentation or request a custom briefing.

Technical Documentation

Download detailed documentation for your evaluation process

Executive Summary

One-page overview of QCOS value proposition for C-suite

PDF245 KB

Security Architecture

Security model, data flow, and the exact compliance position (see status table below)

PDF1.2 MB

Deployment Options

Cloud, self-hosted, and air-gapped deployment architectures

PDF890 KB

RBAC & Audit Logging

Role-based access control, audit logs, and export formats

PDF560 KB

Integration Checklist

SSO, API, CI/CD, and observability integration requirements

PDF420 KB

Pricing & Licensing

Detailed pricing tiers, volume discounts, and licensing terms

PDF180 KB

Compliance & Certifications

QCOS maintains industry-standard certifications for enterprise security requirements

Not started

SOC 2 Type II

Valid until:

No audit engaged and no report exists. We will not claim otherwise.

Not started

ISO 27001

Valid until:

No certification held. Roadmap item; ask us for the current position.

Compliant

GDPR

Valid until: Ongoing

EU-based (Estonia), EU data residency, DPA available on request

Implemented, not certified

Post-quantum signatures

Valid until:

ML-DSA-65 (FIPS 204) via liboqs. No CAVP/ACVP algorithm certificate and no CMVP module validation — the implementation is standards-based, not validated.

Certification reports available under NDA. Request access →

Security Features

Enterprise-grade security built into every layer

Data Protection

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Customer-managed encryption keys (BYOK)
  • Data residency controls (EU, US, APAC)

Access Control

  • SAML 2.0 / OIDC SSO integration
  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA)
  • API key rotation and expiry

Audit & Compliance

  • Immutable audit logs (90-day retention)
  • Export to SIEM (Splunk, Datadog, etc.)
  • Evidence bundles SEALED with a SHA-256 Merkle root; signed when the Trust Plane attests
  • Chargeback tags for FinOps

Infrastructure

  • Azure-hosted (Microsoft holds the data-centre certifications, we do not)
  • Geographic redundancy (multi-region)
  • DDoS protection and WAF
  • Independent penetration test: not yet commissioned

Deployment Options

Choose the deployment model that fits your requirements

QCOS Cloud

Fully managed SaaS platform

  • Zero infrastructure management
  • Automatic updates and scaling
  • Uptime target 99.9% (no contractual SLA credits offered yet)
  • 24/7 enterprise support

Best for: Teams wanting fastest time-to-value

Self-Hosted

Deploy in your own infrastructure

  • Kubernetes or VM deployment
  • Full data sovereignty
  • Custom network policies
  • Bring your own monitoring

Best for: Organizations with strict data residency requirements

Air-Gapped (QuantumLock)

Offline enforcement for HPC/classified

  • No network dependency
  • Cryptographic license tokens
  • Periodic sync for updates
  • PKCS#11 HSM custody option (no FIPS validation held)

Best for: Government, defense, and classified environments

Request Custom Procurement Brief

Get a tailored brief for your organization with specific compliance requirements, pricing, and technical architecture recommendations.

By submitting this form, you agree to our Privacy Policy. We'll respond within 1 business day.

Ready to evaluate?

Request a technical deep-dive with our solutions team