Move cursor | Click to ripple
Trust Center

What your security team needs to review QEval.

Per-capability AI fact sheets, the certifications, and the data-handling answers your security and procurement teams ask for, in one place. No sales call to read them.

Certifications

The attestations, in one place.

The certifications and controls your security and procurement teams check first. The reports themselves are available under NDA through the attestations portal.

SOC 2 Type II
Audited security controls
ISO 27001
Information security management
ISO 42001
AI management system
PCI DSS Level 1
Cardholder data handling
HIPAA
Protected health information
GDPR
EU data protection
CCPA
California privacy
PII redaction
Removed at ingest
AI fact sheets

How each part of the platform handles your data.

One fact sheet per scored surface. The handling is the same where it matters; the difference is what each one touches, and when.

Auto QA
Scores completed conversations against your scorecard.
What it processes
Completed conversations: recordings, transcripts, and metadata from your CCaaS or storage.
When it runs
After the conversation, in batch or near real time.
Model
QEval proprietary closed mixture of experts. No general third-party model sits in the scoring path.
PII handling
Personal information is detected and redacted at ingest, before any model processes the conversation.
Third-party training
Never. Your data is not used to train any third-party foundation model.
Encryption
Encrypted in transit and at rest.
Retention
Configurable to your policy. Evidence is kept for audit, then purged on your schedule.
Certifications
SOC 2 Type II, ISO 27001, ISO 42001, PCI DSS Level 1, HIPAA, GDPR, CCPA.
AI Agent QA
Scores conversations handled by your AI agents, on the same scorecard as your people.
What it processes
Conversations handled by your AI agents (Sierra, Decagon, Agentforce, in-house GenAI, and others), by transcript or log.
When it runs
After the conversation, on the same scorecard used for human agents.
Model
QEval proprietary closed mixture of experts. Scoring an AI vendor output does not route your data into that vendor model.
PII handling
Personal information is detected and redacted at ingest, before any model processes the conversation.
Third-party training
Never. Your data is not used to train any third-party foundation model.
Encryption
Encrypted in transit and at rest.
Retention
Configurable to your policy. Evidence is kept for audit, then purged on your schedule.
Certifications
SOC 2 Type II, ISO 27001, ISO 42001, PCI DSS Level 1, HIPAA, GDPR, CCPA.
Real-Time Agent Assist
Guides the agent live, during the conversation.
What it processes
The live conversation stream while the call is in progress.
When it runs
In real time, as the agent is on the call.
Model
QEval proprietary closed mixture of experts. Guidance is generated in the QEval environment, not handed to a third-party model.
PII handling
Personal information is redacted at ingest before processing; guidance shown to the agent carries no stored raw PII.
Third-party training
Never. Your data is not used to train any third-party foundation model.
Encryption
Encrypted in transit and at rest.
Retention
Configurable to your policy.
Certifications
SOC 2 Type II, ISO 27001, ISO 42001, PCI DSS Level 1, HIPAA, GDPR, CCPA.
Coaching
Turns scores and outcomes into coaching, with no new conversation capture.
What it processes
Scores, evidence, and outcome signals already produced by scoring. No new conversation capture.
When it runs
After scoring, as coaching and performance workflows.
Model
QEval proprietary closed mixture of experts.
PII handling
Operates on already-redacted, scored data. No raw PII is reintroduced.
Third-party training
Never. Your data is not used to train any third-party foundation model.
Encryption
Encrypted in transit and at rest.
Retention
Configurable to your policy.
Certifications
SOC 2 Type II, ISO 27001, ISO 42001, PCI DSS Level 1, HIPAA, GDPR, CCPA.
On every fact sheet

The constants.

Four things hold true no matter which part of the platform touches a conversation.

Redaction at ingest
Personal information is removed before any model sees the conversation.
A closed model
Scoring runs on QEval's own mixture of experts. Your data never trains a third-party model.
Encrypted throughout
In transit and at rest, with access controls and audit logging.
You set retention
Evidence is kept for audit, then purged on the schedule your policy requires.
For procurement

What your security team can request.

The documents a security review actually needs, available under NDA through the attestations portal.

SOC 2 Type II report
The full audited report, not just the badge.
ISO 27001 and 42001 certificates
Current certificates with scope and dates.
Penetration test summary
The most recent third-party test results.
Security questionnaire
A pre-filled CAIQ-style questionnaire to speed your review.
Data processing agreement
The DPA and the current subprocessor list.
Architecture and data-flow notes
How a conversation moves from ingest to scored evidence.

Available under NDA through the attestations portal at trust.etslabs.ai.

Questions

Security and trust, in plain terms.

Where does our conversation data go?

It is ingested into the QEval environment, where personal information is redacted, then scored by QEval's own closed mixture of experts. It does not pass through a general third-party model. The full path is on the Security and Trust page.

Do you use our data to train AI models?

No. Your conversations are not used to train any third-party foundation model, and the scoring models are QEval's own. Personal information is redacted at ingest before any processing.

Which certifications do you hold?

SOC 2 Type II, ISO 27001, ISO 42001 (AI management), PCI DSS Level 1, HIPAA, GDPR, and CCPA, with PII redaction at ingest across the platform.

Can we get your SOC 2 report and security questionnaire?

Yes. The audited reports and the completed security questionnaire are available under NDA through the attestations portal. Your team can request access there or through your pilot contact.

How long do you keep our data?

As long as your policy says, and no longer. Retention is configurable: scored evidence is kept for the audit window you set, then purged on your schedule. The specifics are written into the data processing agreement.

Bring procurement

Hand this to your security team.

Start a pilot and we will walk security and procurement through the fact sheets, the attestations, and exactly how your data is handled, before anything is signed.

Contractual commitments

Four numbers no peer publishes.

94%+
Accuracy SLA
Written into the master agreement
30 days
Deployment
Money-back guarantee
60 days
Exit clause
Cancel with notice, no penalty
120 days
ROI
Documented customer-average outcome