Security & trust

Put the boundary in view. Ask the right questions.

A regulated buyer should not have to infer a security posture from adjectives. This page separates what you can inspect on the public surface, how governed Autopilot is intended to operate, and what must be confirmed for your deployment.

This is a current public posture, not a certification statement. Confirm deployment-specific details before sharing regulated or confidential data.

The short version

The public site is clear about its limits.

The marketing site is static, the contact flow sends submitted fields through a QTXpert endpoint and routes them through SendGrid to info@qtxpert.com, and the product workspace starts at authenticated sign-in. Workspace controls, data handling, and assurance evidence belong in the evaluation conversation.

Inspect now

Product captures, documentation, privacy notice, and authenticated workspace entry.

Confirm with us

Residency, retention, role matrix, subprocessors, incident response, and certifications.

Current public posture

Specific enough to evaluate. Honest enough to verify.

These statements describe the public surface as it exists today. “Confirm” is deliberate: it marks information that should come from the QTXpert team or your deployment agreement, not from marketing copy.

AccessVerified entry path

Authenticated workspace sign-in

The live QTXpert workspace starts at a sign-in page. The public CTA does not imply anonymous product use or a free trial.

Open workspace sign-in
Public websiteEndpoint + no CRM

No website-side contact database

The marketing site does not use a third-party form collector or CRM. Submitted fields pass through the QTXpert contact endpoint to SendGrid for delivery to info@qtxpert.com, with a mail-client fallback if automated delivery is unavailable.

Read the privacy boundary
Roles and approvalsConfirm

Ask for the current role matrix

Scoped access and human approvals are part of the product control model. Confirm the actual roles, permissions, approval steps, and audit behavior for your organization.

Data residencyNot published

Confirm storage and processing regions

The public site does not specify workspace data residency. Ask where inputs, generated artifacts, logs, and evidence are processed and stored.

RetentionNot published

Confirm retention and deletion defaults

The public site does not state workspace retention periods. Confirm defaults, deletion workflows, backups, and evidence lifecycle before an evaluation.

CertificationsNo public claim

Do not infer SOC 2 or ISO status

This site does not publish a SOC 2, ISO 27001, HIPAA, or similar certification claim. Ask for the current assurance pack and scope directly.

DeploymentDiscuss

Managed, private, or hybrid patterns

The platform story includes deployment flexibility. Confirm which model, network boundary, operational responsibility, and support path are available for your use case.

AI traceabilityDesign principle

Keep context and review visible

QTXpert is positioned around source context, generated artifacts, human review, and evidence. Confirm model providers, logging, export, and data-use details for your deployment.

Autopilot controlsDesigned

Autonomous execution stays bounded

Autopilot should run only within an explicit scope, approved environments, role-aware permissions, retry and failure rules, and a reviewable evidence trail. Confirm the exact controls for your deployment.

Evidence you can inspect

Start with the surfaces that are real today.

A useful evaluation starts from something tangible and then moves into the controls that matter for your context.

Product captures

Review context intake, coverage choices, and generated test suites with sample data.

Open demo

Task-first docs

See how the workflow is explained and where configuration changes the answer.

Read the docs

Direct questions

Ask for the current control, commercial, or deployment detail instead of inferring it.

Contact the team
Questions for an evaluation

Bring these questions to the conversation.

Which regions process and store our data?
What are the retention and deletion defaults?
Which roles, approvals, and audit events are available?
Which model providers and subprocessors are in scope?
How are prompts, artifacts, logs, and evidence used?
What assurance documents and incident processes can be shared?
Make trust concrete

A better question is worth asking.

Share your deployment context and the control details your team needs before it can evaluate the workflow.

Ask about security & governance