Security Built for Manufacturing
Enterprise-grade protection for your most sensitive quality data
Your PPAP submissions, engineering drawings, and process data represent critical intellectual property. QualityEngineer.ai is architected from the ground up to protect it with the controls OEMs, primes, and Tier 1 suppliers demand across automotive, aerospace, and regulated industries.
TISAX Compliance Readiness
TISAX (Trusted Information Security Assessment Exchange) is the automotive industry's standard for information security. Managed by the ENX Association and based on the VDA Information Security Assessment (ISA) catalog, TISAX is required by major OEMs including Volkswagen Group, BMW, Daimler, and their supply chains. Our platform architecture is designed to align with TISAX requirements so that your quality data is handled with the level of protection your customers expect.
- Information Security Management aligned with the VDA ISA catalog requirements for handling confidential quality and engineering data
- Prototype and confidential data protection controls aligned with TISAX Assessment Levels 2 and 3
- Third-party data processing controls with clear data handling boundaries and processing agreements
- Access control policies enforced at the application layer with organization-scoped data isolation
- Incident response and change management processes aligned with VDA ISA control objectives
- Regular internal assessments against TISAX control objectives to maintain compliance readiness
Note: "TISAX-ready" indicates our architecture and controls are aligned with TISAX requirements. TISAX assessment labels are issued by accredited audit providers through the ENX Association.
Data Protection and Encryption
Encryption at Rest
Customer data is encrypted at rest. Our production database runs on encrypted block storage with full-volume AES-256 encryption, and uploaded files and documents are stored in object storage encrypted at rest with AES-256. Encryption keys are managed by our infrastructure provider.
Encryption in Transit
Every connection to QualityEngineer.ai is secured with TLS 1.2 or higher. All API calls, file uploads, and browser sessions are encrypted end-to-end between your device and our infrastructure.
Organization-Scoped Isolation
Multi-tenant architecture enforces strict organization-level data isolation. Every database query is scoped by organization ID, preventing any possibility of cross-tenant data access.
Authentication and Access Control
JWT-based authentication with short-lived tokens (30-minute expiry). Role-based access control ensures users only access data within their organization and permission level.
Secure File Storage
Uploaded documents and drawings are stored in access-controlled file storage, separate from application data. Files are only accessible through authenticated API endpoints with proper authorization checks.
No Cross-Tenant Data Leakage
Strict query-level enforcement prevents data from one organization from ever appearing in another organization's context. Every API endpoint validates organization membership before returning results.
AI Data Handling
We understand that sending quality documents to an AI system raises legitimate concerns. Here is exactly how your data is handled during AI-powered evaluation and document generation.
- AI processing is powered by Anthropic's Claude API, which does not use customer data for model training. Your documents are never used to improve or fine-tune AI models.
- Documents sent to the AI for evaluation or generation are processed in real time and are not stored by the AI provider after the response is returned.
- AI context is strictly scoped to your organization. Documents from one organization are never included in prompts or context for another.
- No customer data - including uploaded documents, evaluation results, or generated content - is used to improve AI models or shared with third parties.
- Source document content stays within your organization's boundary. AI-generated outputs are stored in your organization's workspace and subject to the same access controls as any other document.
How AI processing works
AI Transparency and the EU AI Act (Article 50)
Our classification. QualityEngineer.ai is a limited-risk AI system under the EU AI Act. Our obligations are the transparency duties of Article 50: we tell you when you are interacting with AI, and we identify AI-generated content. QualityEngineer.ai is not a high-risk system under Annex III. It is decision-support software with a human accountable for every output, it does not control machinery or act as a safety component, and it does not make employment, credit, or essential-service decisions about people.
What our AI does. Depending on the feature you are using, our AI can read engineering drawings and documents and extract characteristics, dimensions, and requirements for your review; draft and help structure quality work such as PPAP and PSW packages, CAPA and root-cause analysis, APQP planning, supplier reviews, and inspection and study summaries; coach you through a method such as a root-cause investigation by asking questions and checking your work against the standard; answer questions about using QualityEngineer.ai; and check a package for completeness so you can fix gaps before you submit.
A human is accountable for every output. Our AI drafts, analyzes, checks, and suggests. It does not approve, sign, or submit anything on your behalf, and it does not create a final record without your review. Every AI output is presented to you as a draft or suggestion, and you accept it, edit it, or reject it. A qualified person on your team remains accountable for what enters your quality records and what you submit to your customers. Qualification and training decisions in the product are made by your organization's people, not by the AI.
How we identify AI content. When you use an AI feature, the interface tells you so. AI-generated outputs are stored with provenance metadata recording that they were AI generated and which model produced them, and we are extending visible AI-assisted, human-reviewed markings across generated documents.
Data handling. AI processing is powered by Anthropic's Claude API, which does not use customer data for model training. Documents sent for evaluation or generation are processed in real time and are not stored by the AI provider after the response is returned. AI context is strictly scoped to your organization; content from one organization is never included in prompts or context for another. Full detail is in the AI Data Handling section on this page.
A control for data-sensitive work. For customers who need certainty that specific content never reaches a model, we are adding a per-organization control to turn off AI features and run the product on its manual paths.
Questions. Questions about our AI transparency posture or the EU AI Act can be sent to dan@qualityengineer.ai.
Infrastructure Security
Isolated Hosting
Application infrastructure runs on dedicated, isolated cloud resources. No shared hosting or multi-tenant infrastructure at the server level.
Container Isolation
Services run in isolated Docker containers with strict resource boundaries and network policies. Each service operates independently with minimal attack surface.
Automated Backups
Database backups run on automated daily schedules with off-site retention, and backup files are encrypted at rest with AES-256. Backups can be restored if data recovery is needed.
Security Updates
Operating systems, runtime environments, and dependencies are patched on a recurring cycle, with automated weekly dependency update checks. Infrastructure health monitoring runs daily.
DDoS Protection
Network-level DDoS mitigation protects against volumetric attacks. Application-layer rate limiting prevents abuse and ensures service availability for legitimate users.
Monitoring and Alerting
Continuous monitoring of application health, performance metrics, and security events. Automated alerting escalates anomalies for rapid incident response.
Privacy and Compliance
GDPR Readiness
- Data minimization - we collect only what is necessary for the service
- Right to deletion - request complete removal of your data at any time
- Data portability - export your data in standard formats
- Privacy by design - data protection built into every feature from day one
- Transparent data processing with clear documentation of how data is used
Industry Standards Alignment
- Controls designed against the SOC 2 Trust Services Criteria for security, availability, and confidentiality
- ISO 27001 aligned information security management framework
- Data processing agreements available for enterprise customers
- Internal application and infrastructure penetration testing, most recently June 2026, and recurring code-level scanning for committed secrets
- Documented security policies and procedures available upon request
We do not hold a SOC 2 report and are not pursuing SOC 2 attestation at this time. Our security assessments are performed internally; we have not engaged a third-party assessor.
Industry-Specific Security
We built QualityEngineer.ai for manufacturing industries with strict data security requirements. That means we understand the unique needs that come with handling engineering drawings, PPAP submissions, process data, and supplier communications across automotive, aerospace, medical device, and general manufacturing.
Engineering Drawing Protection
Uploaded drawings are access-controlled per organization, stored on encrypted-at-rest storage, and processed in memory for AI evaluation. Access logs track every document view and download.
PPAP Document Confidentiality
PPAP submissions contain proprietary process parameters, capability data, and supplier information. All PPAP data is encrypted at rest, scoped to the owning organization, and only accessible by authorized team members.
Supplier Portal Security
The supplier portal uses secure, time-limited access tokens for document uploads. Suppliers do not need to create accounts or share credentials. Each portal link is scoped to a specific PPAP request with controlled access.
Audit Trail for Compliance
Full audit trail records who accessed what data and when. Document changes, evaluation results, and status updates are all logged with timestamps and user attribution for IATF 16949 and VDA 6.3 audit readiness.
Questions About Security?
We welcome security reviews and are happy to provide additional documentation, data processing agreements, or arrange a call to discuss your organization's specific requirements.
Request a security whitepaper, data processing agreement, or schedule a security review by emailing security@qualityengineer.ai