Controlled Scope
Every evaluation is bounded by an approved use case, environment, participant list, data classification, and permitted activity.
VEQSA Trust Center
VEQSA's enterprise evaluation approach is designed around controlled scope, minimum necessary data, tenant-aware access, evidence integrity, and deployment options aligned with the partner's approved security boundary.
Specific controls and deployment configurations are established through technical scoping, security review, and the signed Evaluation Partner Agreement.
Security principles
These principles govern each controlled Optimization Intelligence™ evaluation, from initial scope through evidence retention.
Every evaluation is bounded by an approved use case, environment, participant list, data classification, and permitted activity.
Synthetic, masked, reduced-risk, or otherwise minimized data is preferred whenever it can answer the evaluation question.
Portal access, administrative permissions, evaluation activity, and evidence access are governed according to approved roles and organizational boundaries.
Evaluation records, outcomes, replay activity, and approved reports are retained and verified according to the applicable evaluation scope.
Evaluation access does not grant production rights, autonomous operational authority, or an enterprise deployment license.
Controls are applied according to the approved scope of each evaluation rather than asserted as universal guarantees.
Deployment boundaries
A tenant-scoped environment operated within the approved VEQSA service boundary.
A scoped private evaluation option that may allow approved operational data to remain within the partner's cloud boundary, subject to technical feasibility and security review.
A qualified isolated or air-gapped evaluation option where technically supported and expressly defined in the evaluation agreement.
Deployment options are subject to technical feasibility, security review, agreed responsibilities, signed scope, and the applicable Evaluation Partner Agreement. Not every deployment pattern is available for every evaluation.
Data handling
Identify the minimum data required and determine whether regulated or sensitive data is involved.
Document permitted data classes, users, systems, regions, integrations, and handling conditions.
Apply the approved access, storage, transmission, logging, and environment controls.
Retain evaluation data and evidence only according to the agreed purpose and retention period.
Apply the agreed deletion, return, or legally required retention process at evaluation close.
Active credentials, API secrets, private keys, signing material, and protected implementation details are not ordinary evaluation-data fields.
Access and governance
Access is limited to approved enterprise and VEQSA participants.
Permissions are aligned with each participant's evaluation responsibilities.
Approved administrators can review authorized access and evaluation activity.
Changes to data, users, systems, integrations, or scope require documented approval.
Incident and vulnerability handling
VEQSA maintains processes for receiving security reports, investigating suspected incidents, containing identified risks, and coordinating appropriate notifications under the applicable agreement and law.
Response activities and notifications follow the signed agreement; no public service-level or fixed response-time commitment is made on this page.
Security reports
security@veqsa.comVulnerability reports
security@veqsa.comEvaluation escalation
Evaluation-specific escalation contacts and contract-defined notification requirements are established in the signed Evaluation Partner Agreement.
Shared responsibility
Security documentation
Qualified evaluation partners may request appropriate security, privacy, deployment, and data-handling information during the evaluation intake process. Detailed materials are provided according to qualification, confidentiality, relevance, and approved disclosure boundaries.