Security

Security Built Into Every Layer

SOC 2 Type II, FedRAMP pathway, FIPS 140-2 validated containers. Dedicated VPC with zero cross-customer leakage. Only anonymized 128-dimensional embeddings — no PII, no raw events. Per-customer LoRA isolation. Air-gap capable on NVIDIA Jetson. NeMo Guardrails prevent hallucinated CVEs. Phantex red-teams our own platform 24/7.

Security & Compliance

Enterprise-Grade Security at Every Layer

NVIDIA AI Enterprise provides FIPS 140-2 validated containers. Customer data never leaves your environment.

SOC 2 Type IIFedRAMP ModerateIEC 62443 SL2NERC CIPFIPS 140-2NIS2 (EU)

Customer Data Isolation

All telemetry processed in dedicated VPC. Only anonymized 128-dimensional embeddings leave customer environment.

Air-Gap Capable

Jetson Orin runs full inference pipeline with zero cloud dependency. GPIO relay operates independently of IP network.

Auditable Agent Actions

Every containment action logged with timestamps, confidence scores, and reversibility flags. Full forensic trail.

Compliance Certifications

SOC 2 Type II & FedRAMP Pathway

SOC 2 Type II from launch. FedRAMP Moderate ATO within 18-24 months with pre-authorized infrastructure and NIST 800-53 controls.

FIPS 140-2 Containers

FIPS 140-2 Level 1 validated cryptographic containers via NVIDIA AI Enterprise. All model inference and data processing use certified modules.

Dedicated VPC — Never Shared

Customer isolation: dedicated VPC, never shared infrastructure. Zero cross-customer data leakage risk by architectural design.

Anonymized 128-Dim Embeddings

Only anonymized 128-dimensional threat signal embeddings feed the foundation model — no PII, no raw events, no logs. Full transparency and audit rights.

End-to-End Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256-GCM). Per-customer LoRA adapters (20-50 MB) stored separately with cryptographic isolation.

IEC 62443 SL2 & NERC CIP

IEC 62443-4-2 Security Level 2 for operational technology. NERC CIP compliance packaging for electric utilities (CIP-002 through CIP-014).

Customer Isolation

Dedicated VPC — Never Shared Infrastructure

All raw telemetry stored in your dedicated VPC — never multi-tenant infrastructure. Zero cross-customer data leakage risk by architectural design. Customer data never crosses jurisdictional boundaries — US customers stay in US regions, EU customers in EU regions. For cloud deployments, only anonymized 128-dimensional threat signal embeddings (no PII, no raw events, no logs) feed the foundation model. Raw telemetry never leaves your environment. Retention policies are customer-controlled, and cryptographic deletion ensures data is irrecoverable when purged.

Per-Customer LoRA

Per-Customer LoRA Adapters — Isolated, Never Shared

Your behavioral model is yours — 20-50 MB LoRA adapter stored separately, never shared with other customers. Each adapter is cryptographically isolated with per-customer encryption keys. Opt-in threat intel contribution with full Data Processing Addendum (DPA) compliance for GDPR, CCPA, and PDPA. Customer audit rights: review exactly what data contributes to your model, inspect training lineage, and revoke contribution at any time. Model deletion is cryptographically verifiable — when you delete your data, it's irrecoverable.

AI Guardrails & Continuous Red-Teaming

Jetson Air-Gap: Full Inference with Zero Cloud

NVIDIA Jetson standalone deployment runs the complete inference pipeline with no cloud dependency. GPIO relay provides hardware interlock independent of IP network.

NeMo Guardrails: No Hallucinated CVEs

NeMo Guardrails prevent hallucinated CVEs, incorrect severity scoring, and unauthorized policy changes. Model outputs validated against known threat databases.

All Agent Actions: Logged, Timestamped, Reversible

Every agent action logged, timestamped, confidence-scored, and reversible. Mandatory human escalation for irreversible operations like system shutdowns.

Phantex Continuous Red-Teaming

Phantex red-team product continuously tests our own platform. Adversarial probes, privilege escalation attempts, and model poisoning exercises run 24/7.

Air-Gap Capable

Jetson Air-Gap: Zero Cloud Dependency

NVIDIA Jetson standalone deployment runs the complete inference pipeline with no cloud dependency — ideal for OT/ICS networks, critical infrastructure, and classified environments. GPIO relay provides hardware interlock independent of IP network: physical disconnect switch for emergency shutdowns. Full threat detection, model inference, and agent orchestration run locally on Jetson hardware. Model updates deployed via secure USB or air-gapped network, with cryptographic signature verification. Zero telemetry leaves the air-gapped network unless explicitly configured by customer policy.

Data Privacy by the Numbers

0 breaches

Security Incidents to Date

0 dim

Anonymized Embeddings Only

0 PII

Zero Raw Event Sharing

0%

Customer Audit Rights

Additional Compliance

NIS2, HIPAA, CMMC Support Paths

NIS2 (EU): NIS2 Directive compliance for EU essential services — incident response within 24 hours, supply chain risk management, cross-border threat reporting, and mandatory security audits. Pre-built reporting templates for national CSIRTs. HIPAA: Business Associate Agreement (BAA) available for healthcare organizations. PHI encryption, audit logging, access controls, and breach notification workflows meet HIPAA Security Rule requirements. CMMC: Support path for Department of Defense contractors requiring CMMC Level 2 (NIST 800-171) and Level 3 (NIST 800-172 subset). FedRAMP Moderate infrastructure provides foundation for CMMC certification.

OT/ICS Security

IEC 62443 & OT Hardware Interlocks

IEC 62443-4-2 Security Level 2 compliance for operational technology environments — 12-18 month competitive moat, as most vendors are 18-36 months behind. GPIO relay on NVIDIA Jetson provides hardware interlock independent of IP network: physical disconnect switch for emergency shutdowns, no software-only kill switch vulnerability. Full Purdue Model Level 0-3 support with air-gap capable deployment. NERC CIP for electric utilities (CIP-002 through CIP-014): asset identification, electronic security perimeters, change management, incident response, and recovery plans. All OT/ICS telemetry stays within designated security zones — never crosses into IT network without explicit customer policy.

Enterprise Deployment

Deploy Your Way. GPU at Every Layer.

From cloud SaaS to fully air-gapped Jetson Edge. Five deployment modes meet any compliance requirement — FedRAMP, IEC 62443, NERC CIP, or sovereign.

Cloud-Native SaaS

Managed GPU infrastructure. A100/H100 clusters. Multi-tenant Triton serving with per-customer isolation.

On-Premise (NIM + AI Enterprise)

Deploy on customer DGX/HGX hardware. NVIDIA AI Enterprise licensing. FIPS 140-2 validated containers.

Hybrid

Cloud model orchestration with on-premise Morpheus data processing. Data residency requirements met.

Edge-Only (Air-Gapped)

Jetson Orin standalone. Zero cloud dependency. Full inference pipeline with GPIO hardware interlock.

Infrastructure

Hardened GPU Infrastructure

Quellra runs on hardened, GPU-optimized infrastructure with runtime container isolation, immutable deployments, and cryptographically signed artifacts. All services communicate over mTLS with automated certificate rotation. Network segmentation enforces strict east-west traffic policies — no lateral movement between customer environments. Infrastructure deployed via GitOps with mandatory code review, automated SAST/DAST scanning, and supply chain integrity verification for every dependency. SBOM (Software Bill of Materials) generated for all container images. Vulnerability scanning runs continuously with automated patching for critical CVEs within 24 hours.

RequestOurSecurity&CompliancePackage

Download SOC 2 Type II report, FedRAMP compliance matrix, FIPS 140-2 validation certificates, IEC 62443 attestation, and NERC CIP compliance documentation.