Our approach
We build AI that runs inside our customers’ own infrastructure. Their data does not leave the building, so the security of what we ship is part of the product, not an add-on.
Who is accountable
Darío Ávalos, Founder & CEO, is accountable for product and information security at Quantum Howl.
Security contact: security@quantumhowl.com
How we build
- On-premise by design: models, agents and data run on the customer’s infrastructure, with no third-party cloud in the data path.
- Secure development pipeline: secret scanning, static analysis and dependency auditing on every build, plus a software bill of materials (SBOM).
- Isolation by default: automated checks in our build pipeline fail the build if any query escapes its customer scope.
- Remote maintenance only through encrypted tunnels.
- Our AI agents are tested against prompt injection and tool misuse.
- Health software is developed under a lifecycle aligned with IEC 62304 and ISO 14971.
Reporting a vulnerability
If you believe you have found a vulnerability in our website or software, write to security@quantumhowl.com with a description and steps to reproduce. We acknowledge reports within 5 business days and keep you informed until the issue is resolved.
Please do not test systems installed at customer sites, access data that is not yours, or disrupt any service. We will not take legal action against research carried out in good faith within these rules.
