Quinn Defense SystemsNexus Prism Request access

Security claims — and what we won't claim

Every claim we make comes with a code path, a configuration file and a verification recipe. You can audit them without an NDA call.

What we claim

What we explicitly do NOT claim

A CJIS v5.9.5 gap analysis is complete and available under NDA. A security questionnaire is available on request.

Why publish the limits

Because a buyer who catches one oversell correctly stops believing everything else. The fastest way to be trusted with the hard claims is to be visibly unwilling to make the easy ones.

A control, and the first thing it caught

We built an automated scan that reads our published spreadsheets before release and refuses any file containing identifiers that should not leave the estate. It clears roughly 1.6 million cells across the public datasets on every build.

The first thing it caught was us. An early build of one workbook carried full Bitcoin addresses belonging to parties no government has designated and no court has named. They are truncated now, and the incident is written up in the dataset's own README rather than quietly fixed.

A control that has never caught anything is a control nobody has tested.

Responsible disclosure

If you find a vulnerability in anything we publish or operate, we want to hear about it and we will not threaten you for telling us.

Write to security@quinndefensesystems.com. Tell us what you found and how to reproduce it. We will acknowledge within two business days and keep you informed until it is closed.

Terms of Service Privacy Policy