Skip to main content

Trust

Security

Overview of our security practices, controls, and compliance framework.

Overview

Qubitry is designed with security as a foundational requirement. Security is integrated into every layer of the platform architecture, from infrastructure and access controls to data handling and incident response.

As a quantum computing platform that processes proprietary circuits, molecular structures, and machine learning models, we employ industry-standard controls to protect your data at every stage of processing.

This page provides an overview of our security practices. It is provided for informational purposes only and does not form part of any contract or agreement. For contractual terms governing data processing, please refer to our Data Processing Addendum.

Security by Design

Security is considered at every stage of the platform development lifecycle. New features and infrastructure changes are assessed for security impact before deployment. Controls are implemented by default rather than added as an afterthought, ensuring that data protection is built into the platform architecture from the ground up.

Data Classification

Data submitted to the Qubitry platform is classified and handled according to its type:

  • Compute Data: quantum circuits, molecular structures, machine learning models, and job configurations submitted for processing. Subject to strict ephemeral processing controls as described below.
  • Account Information: personal information collected during registration. Handled in accordance with our Privacy Policy.
  • Metadata: anonymised and aggregated operational data used for platform improvement. Does not include compute data content.

Controls are applied proportionally to the classification level, with Compute Data receiving the highest level of protection.

Encryption

ScopeStandard
Data in transitTLS 1.3
Data at restAES-256
Data in memory during computationProcess-level isolation with dedicated memory allocation

All communication between your applications and the Qubitry platform is encrypted using TLS 1.3. Any temporary storage required during job execution uses AES-256 encryption. Compute data in memory is isolated at the process level and automatically released upon job completion.

Compute Data Protection

Qubitry processes compute data solely for the purpose of executing the computation you request. We implement strict controls to ensure your data is protected:

  • Compute data is not used for model training or platform improvement
  • Compute data is not analysed or mined beyond what is necessary to execute your job
  • Compute data is deleted automatically upon job completion
  • No human access to compute data occurs during or after processing
  • Metadata (job runtimes, resource utilisation) is retained in anonymised and aggregated form only

Infrastructure Security

The Qubitry platform runs on infrastructure provided by leading cloud GPU providers. Each provider is evaluated for security posture and bound by contractual safeguards consistent with our Data Processing Addendum.

  • Multi-tenant isolation through process-level separation
  • Network security controls including firewalls and intrusion detection
  • Regular security assessments of our infrastructure and dependencies
  • Automated monitoring and alerting for anomalous activity

Access Control

Access to the Qubitry platform and underlying systems is governed by role-based access controls:

  • Authentication via strong password policies
  • Session management with automatic timeout
  • Principle of least privilege applied to all internal access
  • Audit logging of all administrative access
  • Regular access reviews

Personnel Security

All Qubitry personnel with access to production systems undergo background checks and receive annual security awareness training. Access to sensitive systems is granted on a need-to-know basis and is reviewed periodically. Personnel are required to follow documented security policies and are subject to confidentiality obligations.

Compliance

Qubitry is designed to support compliance with the following frameworks:

  • UK GDPR and Data Protection Act 2018: data processing limited to documented instructions, data portability, right to deletion
  • EU GDPR: Standard Contractual Clauses for international transfers
  • CCPA: no sale of personal information, transparency in data practices
  • SOC 2: security, availability, and confidentiality controls (certification in progress)

Vulnerability Management

We maintain an ongoing vulnerability management programme that includes:

  • Regular automated vulnerability scanning of our infrastructure
  • Periodic penetration testing by independent third parties
  • Dependency monitoring and prompt patching
  • Secure development practices throughout our software development lifecycle

Incident Response

In the event of a security incident affecting compute data or personal information, we follow a documented incident response plan:

  1. Detection: automated monitoring and alerting systems
  2. Containment: immediate isolation of affected systems
  3. Investigation: root cause analysis by our security team
  4. Notification: affected parties notified without undue delay
  5. Remediation: corrective measures implemented to prevent recurrence

Responsible Disclosure

If you believe you have discovered a security vulnerability in the Qubitry platform, we encourage you to report it to us responsibly.

Please email security@qubitry.ai with a description of the vulnerability. We will:

  • Acknowledge receipt within 24 hours
  • Investigate and validate the report
  • Work to resolve the issue promptly
  • Keep you informed of progress

We ask that you refrain from publicly disclosing any vulnerability until we have had a reasonable opportunity to address it.

Contact

For security-related inquiries: security@qubitry.ai