Trust Centre
How TrustQuant itself is secured
You are asked to trust us with read access to your infrastructure, so you deserve the same evidence-first answers we produce about everyone else. This page is our own security posture, stated plainly — including what we cannot yet prove.
TrustQuant uses read-only cloud permissions and security metadata to assess control posture. It does not read customer content, write to infrastructure, or modify configurations.
No agents
Nothing is installed on your hosts. Collection is out-of-band, via provider APIs.
No write access
Every permission we request is read-only. We could not change your environment if we tried.
No content access
We read configuration and security metadata — never files, records, messages or code.
Security architecture
The platform is agentless by design. Your cloud providers already expose read-only APIs for exactly this purpose — we connect to those, collect security metadata, and run every model on our own infrastructure. Analysis is out-of-band: nothing executes inside your environment, and there is no inbound path from us into your network.
Architecture statements describe the platform as built for the Q3 2026 pilot cohort.
Data path · read-only · outbound-only from your account
Your cloud accounts
AWS, Azure, GCP and Microsoft 365. You grant scoped read-only roles from your own console — and can revoke them there at any time.
Metadata collection
Scheduled, read-only API calls retrieve configuration states, control settings and security log metadata. Nothing runs on your hosts.
Out-of-band analysis
Rating models execute entirely on TrustQuant infrastructure. Your rating, factor scores and evidence trail are produced there.
Data handling
What we collect — and what we never touch
The clearest way to earn trust with data is to need less of it. TrustQuant is built around security metadata: enough to score your controls, nothing that exposes your business content.
We collect
- Configuration states — encryption settings, security-group rules, exposure of ports and endpoints
- Control settings — MFA status, access-policy definitions, credential-rotation metadata
- Patch and version metadata for operating systems and services
- Backup job status and restore-test recency
- Security log events and audit metadata
- Resource inventory and cost metadata (the FinOps signals that fund remediation)
We never collect
- File or object contents — documents, images, backups themselves
- Database rows, records or query results
- Personal data held inside your systems about your customers or staff
- Emails, chat messages or their contents
- Source code or intellectual property
- Secrets, keys or password values
- UK GDPR posture
- Processing is designed around the UK GDPR and the Data Protection Act 2018. Collection is privacy-by-design: security metadata rather than personal data wherever possible, with a data-processing agreement available to pilot participants.
- Data residency
- Assessment evidence is held in UK cloud regions. If that ever changes, this page will say so before it does — residency is a commitment, not a footnote.
- Retention
- We keep evidence snapshots only as long as they power your rating history. When your subscription ends, assessment data is scheduled for deletion rather than archived indefinitely.
- Deletion on request
- You can request full deletion of your assessment data at any time; verified requests are completed within 30 days. Revoking our read-only role in your own console cuts off collection immediately — you never have to ask us first.
Access & encryption
Least privilege runs in both directions: the narrowest possible scopes into your environment, and tightly restricted access to your evidence inside ours.
All connections — API collection and the platform itself — are encrypted with TLS 1.2 or higher. There are no unencrypted paths.
Assessment evidence is encrypted at rest with AES-256, with keys managed through our cloud provider's key-management service.
Where the provider supports it we hold no long-lived secrets at all — AWS access uses short-lived role assumption with an external ID. Where tokens are required, they are stored encrypted and scoped read-only.
Connectors request the minimum read-only permission set per provider (detailed in the checklist below) — never broad or administrative access.
Access to customer evidence inside TrustQuant is restricted to named engineers, protected by MFA, and logged. We hold ourselves to the same access-control factor we score you on.
Setup checklist
Exactly what you grant, per provider
For the technical buyer: the read-only roles and scopes a TrustQuant connection uses, following each provider's published patterns. Grant them from your own console in under 10 minutes — and revoke them the same way.
The final connector scope list is confirmed and documented during pilot onboarding. It will never include write, create or delete permissions.
Amazon Web Services
A cross-account IAM role assumed with an external ID — no IAM user, no access keys to share.
SecurityAuditViewOnlyAccessAWS-managed job-function policies: list, describe and get configuration metadata only.
Cannot create, modify or delete any resource; cannot read S3 object contents or database rows.
Microsoft Azure
A Microsoft Entra app registration assigned built-in roles at subscription scope.
ReaderSecurity ReaderAzure built-in roles: view resources, configurations and security findings — nothing else.
Cannot write to any resource, change role assignments, or access data-plane content such as blob contents.
Google Cloud
A dedicated service account granted read-only IAM roles at project or organisation level.
roles/viewerroles/iam.securityReviewerPredefined GCP roles: view resource configuration and IAM policy metadata.
Cannot edit resources or IAM policy, and holds no permissions on stored object contents.
Microsoft 365
A Microsoft Entra app with admin-consented, read-only Microsoft Graph application permissions.
SecurityEvents.Read.AllPolicy.Read.AllReports.Read.AllAuditLog.Read.AllRead-only Graph scopes for security events, policy state, usage reports and audit logs.
Cannot read mailboxes, files or Teams messages; cannot change any tenant setting.
Procurement fast-track
We are pre-launch, and we will not decorate this page with certification badges we do not hold. Here is what your security and procurement team can get from us today, and what is honestly still on the roadmap.
Available today
Published rating methodology
Every factor, weighting and score band is public — no NDA required. Read the methodology
This security architecture overview
The agentless, read-only model documented on this page, kept current as the platform evolves.
Public pricing
Full plan pricing from £50/month, on the website, with no gated quote process. See pricing
Sample assessment report
An illustrative end-to-end report so your team can evaluate the output before connecting anything. View the sample report
Security questionnaire responses
We complete your standard security questionnaire, answered directly by the founding team.
Architecture review call
Direct access to our technical co-founder to walk your security reviewers through the design.
On the roadmap
Independent penetration test
RoadmapThird-party testing of the platform with a shareable attestation letter, planned alongside the pilot.
Cyber Essentials certification
RoadmapThe NCSC baseline we help customers evidence — applied to TrustQuant itself.
SOC 2 programme
RoadmapType I followed by Type II as the platform moves from pilot to general availability.
ISO/IEC 27001
RoadmapA certified ISMS is the longer-term goal once the audit programme above is established.
When any of these is achieved it moves to the left-hand column with the evidence attached. Until then, claiming it would be exactly the self-attestation theatre this company exists to replace.
Security questions from a review or due-diligence process: security@trustquant.co.uk. Everything else: hello@trustquant.co.uk.
Found a vulnerability?
We welcome good-faith security research into our own systems. Report privately, give us reasonable time to fix, and our published safe-harbour commitment applies — we will not pursue legal action over good-faith research conducted under the policy. We aim to acknowledge every report within three UK working days.
/.well-known/security.txt · RFC 9116
Contact: mailto:security@trustquant.co.uk Expires: 2027-07-01T00:00:00.000Z Policy: https://trustquant.co.uk/trust/disclosure Canonical: https://trustquant.co.uk/.well-known/security.txt Preferred-Languages: en
Machine-readable security contact, published at /.well-known/security.txt so researchers and scanners find the right inbox first time.
Diligence done? See the platform next
The same transparency applies to the rating itself — methodology, weightings and a full sample report are all public.