VEQSA Trust Center

Security and control for enterprise evaluation

VEQSA's enterprise evaluation approach is designed around controlled scope, minimum necessary data, tenant-aware access, evidence integrity, and deployment options aligned with the partner's approved security boundary.

Specific controls and deployment configurations are established through technical scoping, security review, and the signed Evaluation Partner Agreement.

Security principles

Principles that bound every evaluation

These principles govern each controlled Optimization Intelligence™ evaluation, from initial scope through evidence retention.

Controlled Scope

Every evaluation is bounded by an approved use case, environment, participant list, data classification, and permitted activity.

Minimum Necessary Data

Synthetic, masked, reduced-risk, or otherwise minimized data is preferred whenever it can answer the evaluation question.

Tenant-Aware Access

Portal access, administrative permissions, evaluation activity, and evidence access are governed according to approved roles and organizational boundaries.

Evidence Integrity

Evaluation records, outcomes, replay activity, and approved reports are retained and verified according to the applicable evaluation scope.

No Uncontrolled Production Reliance

Evaluation access does not grant production rights, autonomous operational authority, or an enterprise deployment license.

Controls are applied according to the approved scope of each evaluation rather than asserted as universal guarantees.

Deployment boundaries

Deployment aligned with enterprise requirements

Subject to Technical Scoping

VEQSA-Controlled Evaluation

A tenant-scoped environment operated within the approved VEQSA service boundary.

Subject to Technical Scoping

Private Cloud or VPC

A scoped private evaluation option that may allow approved operational data to remain within the partner's cloud boundary, subject to technical feasibility and security review.

Subject to Technical Scoping

Isolated Test Bench

A qualified isolated or air-gapped evaluation option where technically supported and expressly defined in the evaluation agreement.

Deployment options are subject to technical feasibility, security review, agreed responsibilities, signed scope, and the applicable Evaluation Partner Agreement. Not every deployment pattern is available for every evaluation.

Data handling

Data boundaries are defined before access begins

  1. 01

    Classify

    Identify the minimum data required and determine whether regulated or sensitive data is involved.

  2. 02

    Approve

    Document permitted data classes, users, systems, regions, integrations, and handling conditions.

  3. 03

    Protect

    Apply the approved access, storage, transmission, logging, and environment controls.

  4. 04

    Retain

    Retain evaluation data and evidence only according to the agreed purpose and retention period.

  5. 05

    Delete or Return

    Apply the agreed deletion, return, or legally required retention process at evaluation close.

Active credentials, API secrets, private keys, signing material, and protected implementation details are not ordinary evaluation-data fields.

Access and governance

Access follows approved roles and authority

Authorized Users

Access is limited to approved enterprise and VEQSA participants.

Role-Based Permissions

Permissions are aligned with each participant's evaluation responsibilities.

Administrative Review

Approved administrators can review authorized access and evaluation activity.

Change Control

Changes to data, users, systems, integrations, or scope require documented approval.

Incident and vulnerability handling

Disciplined response within the applicable agreement

VEQSA maintains processes for receiving security reports, investigating suspected incidents, containing identified risks, and coordinating appropriate notifications under the applicable agreement and law.

Response activities and notifications follow the signed agreement; no public service-level or fixed response-time commitment is made on this page.

Security reports

security@veqsa.com

Vulnerability reports

security@veqsa.com

Evaluation escalation

Evaluation-specific escalation contacts and contract-defined notification requirements are established in the signed Evaluation Partner Agreement.

Shared responsibility

A clear division of evaluation responsibilities

VEQSA responsibilities

  • Operate the approved VEQSA evaluation boundary
  • Enforce approved service-side access controls
  • Protect VEQSA technology and retained evaluation materials
  • Support evidence and verification capabilities within scope
  • Coordinate evaluation security issues

Partner responsibilities

  • Provide authorized and lawfully obtained data
  • Protect partner-controlled identities, devices, and credentials
  • Define permitted users and business authority
  • Maintain partner-side cloud, endpoint, and network controls
  • Prevent evaluation outputs from being used outside the signed scope

Security documentation

Security review through controlled disclosure

Qualified evaluation partners may request appropriate security, privacy, deployment, and data-handling information during the evaluation intake process. Detailed materials are provided according to qualification, confidentiality, relevance, and approved disclosure boundaries.