Trust Center
Security & compliance at Qontiv
Qontiv is built for manufacturers in regulated industries. One page for procurement, legal, and security teams.
Questions or vendor security questionnaires:security@qontiv.com
Certifications
- SOC 2 Type IIOn roadmap
- ISO/IEC 27001:2022On roadmap
- ISO/IEC 42001:2023 (AI)On roadmap
Qontiv does not currently hold these certifications. Our compliance program — policies, Statement of Applicability drafts, and evidence collection — is in active development. We can walk procurement and security teams through the current state under NDA:security@qontiv.com.
Designed for compatibility with
- IATF 16949Designed for
- AS9100 Rev DDesigned for
- ISO 13485 / FDA QMSRDesigned for
- 21 CFR Part 11Designed for
- EU GMP Annex 11Designed for
- EU AI Act (Reg. 2024/1689)Designed for
- EU Cyber Resilience ActDesigned for
Sub-processors
12 sub-processors disclosed — 7 processing data today and 5 disclosed ahead of enablement. 30 days' advance notice of any addition or material change.
View full list →Data Processing Agreement
Standard DPA covering GDPR Article 28, NIS2 Article 23 breach-notification SLAs, and EU AI Act Article 26 deployer/provider obligations.
Uptime & status
Current service status, historical uptime, and incident reports. Each component names the exact hostname it checks. Note before you click: those checks currently observe our non-production tier, and the page says so — production availability is not reported there yet.
status.qontiv.com →Vulnerability disclosure
Responsible disclosure policy per EU CRA Article 13 §5. Critical vulnerabilities acknowledged within 48 hours, patched within 7 days. PGP key available on request.
security@qontiv.com →Compliance framework coverage
Qontiv is designed for compatibility with the frameworks below — Qontiv does not hold these certifications on your behalf. Your organization retains its own certification obligations.
125 controls mapped across 10 frameworks. Every count and label in the table below is generated from that catalog at build time, so this page cannot drift from it. Full catalog with per-control evidence and ownership boundaries available under NDA —request the full control catalog →
| Framework | Controls mapped | Our coverage | You operate | Applies to |
|---|---|---|---|---|
| ISO/IEC 27001:2022 Annex A | 21 | Full mapping | — | All customers |
| SOC 2 (CC series) | 21 | Full mapping | 2 of 21 | All customers |
| 21 CFR Part 11 | 14 | Full mapping | 2 of 14 | FDA-regulated manufacturers |
| EU GMP Annex 11 | 13 | Full mapping | 3 of 13 | EU pharmaceutical manufacturers |
| ISO/IEC 42001:2023 Annex B | 13 | Full mapping | — | Customers using AI Copilot |
| ISO 13485:2016 | 12 | 1 of 12 partial | 10 of 12 | Medical device manufacturers |
| EU AI Act (Reg. 2024/1689) | 10 | 8 of 10 partial | — | EU customers using AI features |
| EU Cyber Resilience Act | 8 | 2 of 8 partial | — | EU market placement |
| IATF 16949 | 8 | Full mapping | 6 of 8 | Automotive manufacturers |
| AS9100 Rev D | 5 | Full mapping | 3 of 5 | Aerospace manufacturers |
These are two independent measures, which is why they are separate columns — a single compatible-or-not badge could not carry both, and the earlier version of this table got them confused.
Our coverage is what Qontiv asserts about its own mapping: "Full mapping" means we have mapped a Qontiv control to every catalog requirement for that framework. It says nothing about how well you are doing, and nothing about certification.You operate counts the mapped controls whose operation is yours or shared rather than ours — training your people, running your management review, deciding your retention periods. A high number there is normal and expected; it is the honest shape of a shared-responsibility model, not a gap in the product.
Neither column asserts that Qontiv holds certification under any framework. Your organization holds its own certification; we are built to be compatible with it. Mapping coverage is also a separate thing from our purchasable compliance packages — two of those four are built today and two are scoped on request. Seepricing for which is which, because a "Full mapping" row here does not mean a packaged module ships.
Evidence, not attestation
A mapped control is a claim until something checks it. Three of the things on this page are checked by machinery rather than by us remembering to, which is the part we would want to see if we were the ones reviewing a vendor.
Controls computed from your own data
Six of the mapped controls are not attestations. Qontiv evaluates them directly against the production records in your tenant — whether every gauge was calibrated on schedule, whether an uncertified operator ran a step that required certification, whether an approved revision was promoted without a signed change order, and three more — then drills through to the rows behind the answer.
Six is six, and we will not call it coverage; the remaining controls are mapped and evidenced but not computed. Results are per-tenant and visible in-product only, so no figure from them appears on this page. A control can also returnnot measured — no rows to evaluate, or too little history for a defensible answer — which is deliberately not presented as a failure, because it is not one.
What each one checks →A lint that blocks our own merges
Every pull request against this website runs a compliance-language deny-list over both the source content and the rendered pages. The rules fail the build on any sentence asserting that Qontiv itself is certified or conformant, on pairing a standard's name with a claim of readiness for it, on asserting that our e-signature binding was validated by us rather than by the customer, and on a set of competitor and pricing claims we decided not to make.
It has documented escape hatches — an allowlist for internal governance files, which have to name a forbidden phrase in order to forbid it, a negation rule, and a per-line exemption comment — and we would rather disclose those than let the control sound stronger than it is.
Evidence references that must resolve
Each control in the catalog carries evidence references. Documentation and architecture-test references are CI-verified to resolve, and architecture-test references are additionally checked to contain a live test rather than a file that used to have one.
References naming a GraphQL query are additionally checked against the committed schema. What is not checked is the remainder — references pointing out to in-app routes and API paths — so this is not a claim that every link in the catalog is verified.
The reasoning behind all of this — and why a quality system that does not run production cannot answer these questions at all — is onwhy Qontiv.
Security practices
Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Row-level security enforced at the PostgreSQL layer — no shared row access between tenants.
Access control
Role-based access with 12 predefined roles covering ISA-95 operations pillars. MFA enforced for all privileged accounts. OAuth2/OIDC — no shared credentials.
Immutable audit trail
All regulated records are append-only at the database level. Electronic signatures immutably bound to record, user identity, timestamp, and declared meaning per 21 CFR Part 11 §11.50.
Vulnerability management
Dependabot, CodeQL, and Trivy scan every PR and nightly. Patch SLAs: Critical ≤7 days, High ≤30 days, Medium ≤90 days. SBOM published per release per EU CRA Article 13.
Incident response
NIS2-aligned IRP with Article 23 cadence: 24-hour early warning, 72-hour notification, 1-month final report for affected EU customers.
AI governance
Every AI interaction producing a regulated record is logged immutably (prompt, model ID, template version, response, user). Human-override actions logged per EU AI Act Article 14.
Ready to see Qontiv in your environment?
A 30-minute walkthrough with your equipment and your data.