← Back to website
TRUST CENTRE

Security and AI governance

Last updated 9 August 2026

QAI Transformation is designed as an intelligence layer—not a replacement for your controlled quality system or professional judgement.

Human control

AI may draft, retrieve, classify and recommend. Named people retain approval, disposition, release, root-cause and CAPA-closure decisions.

Least privilege

Implementations start with the minimum necessary access, normally read-only exports or connections. Roles, environments and customer data are separated according to the agreed architecture.

Traceability

Material outputs are designed to retain source references, workflow status and review history so users can reconstruct how an output was produced and approved.

Data protection

Production designs use encryption in transit and at rest, access control, managed secrets and appropriate retention. Customer data is not reused across customers. Exact hosting, subprocessors and residency are documented during assessment and contracting.

Controlled change

Models, prompts, integrations and evaluation criteria are versioned according to the risk of the intended use. Higher-risk or regulated deployments receive expanded validation and change-control support.

Responsible disclosure

Report a suspected vulnerability privately to security@qaitransformation.com. Please include enough detail to reproduce the issue and avoid accessing data that is not yours.