Security overview
Last updated 27 September 2026
QSyn is designed to run where your data already lives, so sensitive data never has to leave your perimeter to be used.
Deployment
- On-premises, in your private cloud (AWS, GCP or Azure), or hybrid.
- Kubernetes-native; GPU optional for synthetic data, recommended for risk workloads.
- Pilots run in a sandbox inside your environment, not on QSyn infrastructure.
Controls built into the platform
| Area | How QSyn handles it |
|---|---|
| Encryption | TLS 1.3 for data in transit; encryption at rest for stored datasets and models. |
| Access | Role-based access control and single sign-on (SSO). |
| Privacy | Differential privacy with per-dataset (ε, δ) budgets, membership- and attribute-inference tests and re-identification scoring. Synthetic datasets rated HIGH risk are blocked from export automatically. |
| Audit | Every job logs its scenario, dataset lineage and model configuration to an immutable store; stored files are hashed. |
| Reproducibility | Deterministic seeds: the same inputs produce the same results, which supports model validation. |
Compliance status
| Framework | Status |
|---|---|
| SOC 2 | In progress Readiness program underway. We don't claim a SOC 2 report yet and will publish the date when one is issued. |
| Model risk (SR 11-7) | Roadmap Model documentation, backtesting and benchmark comparison to support your validation team. |
| GDPR / DORA | The platform is designed so personal data stays in your environment; synthetic outputs carry privacy evidence for your DPO. |
Reporting a vulnerability
Email founders@qsyn.finance with the subject “Security report”. We'll acknowledge within two business days and keep you updated until it's resolved. Please give us reasonable time to fix an issue before disclosing it.