Security claims — and what we won't claim
Every claim we make comes with a code path, a configuration file and a verification recipe. You can audit them without an NDA call.
What we claim
- Encryption at rest and in transit
- Identity enforced at the network edge, before application code
- Fail-closed egress
- Encrypted DNS end to end
- Tenant isolation at the database row level
- Provenance stamps on every row
- Audit logging of analyst actions
What we explicitly do NOT claim
- We do not claim FedRAMP, SOC 2 or ISO 27001. We hold none of them.
- We do not claim an air gap for the hosted service
- We do not claim defence against a nation-state adversary with simultaneous visibility across multiple networks
- We do not vouch for third-party policies we cannot audit
- We do not say "anonymous" about anything, because we cannot prove it
A CJIS v5.9.5 gap analysis is complete and available under NDA. A security questionnaire is available on request.
Why publish the limits
Because a buyer who catches one oversell correctly stops believing everything else. The fastest way to be trusted with the hard claims is to be visibly unwilling to make the easy ones.
A control, and the first thing it caught
We built an automated scan that reads our published spreadsheets before release and refuses any file containing identifiers that should not leave the estate. It clears roughly 1.6 million cells across the public datasets on every build.
The first thing it caught was us. An early build of one workbook carried full Bitcoin addresses belonging to parties no government has designated and no court has named. They are truncated now, and the incident is written up in the dataset's own README rather than quietly fixed.
A control that has never caught anything is a control nobody has tested.
Responsible disclosure
If you find a vulnerability in anything we publish or operate, we want to hear about it and we will not threaten you for telling us.
Write to security@quinndefensesystems.com. Tell us what you found and how to reproduce it. We will acknowledge within two business days and keep you informed until it is closed.