Security and AI governance
Last updated 9 August 2026
QAI Transformation is designed as an intelligence layer—not a replacement for your controlled quality system or professional judgement.
Human control
AI may draft, retrieve, classify and recommend. Named people retain approval, disposition, release, root-cause and CAPA-closure decisions.
Least privilege
Implementations start with the minimum necessary access, normally read-only exports or connections. Roles, environments and customer data are separated according to the agreed architecture.
Traceability
Material outputs are designed to retain source references, workflow status and review history so users can reconstruct how an output was produced and approved.
Data protection
Production designs use encryption in transit and at rest, access control, managed secrets and appropriate retention. Customer data is not reused across customers. Exact hosting, subprocessors and residency are documented during assessment and contracting.
Controlled change
Models, prompts, integrations and evaluation criteria are versioned according to the risk of the intended use. Higher-risk or regulated deployments receive expanded validation and change-control support.
Responsible disclosure
Report a suspected vulnerability privately to security@qaitransformation.com. Please include enough detail to reproduce the issue and avoid accessing data that is not yours.