What your security team needs to review QEval.
Per-capability AI fact sheets, the certifications, and the data-handling answers your security and procurement teams ask for, in one place. No sales call to read them.
The attestations, in one place.
The certifications and controls your security and procurement teams check first. The reports themselves are available under NDA through the attestations portal.
How each part of the platform handles your data.
One fact sheet per scored surface. The handling is the same where it matters; the difference is what each one touches, and when.
The constants.
Four things hold true no matter which part of the platform touches a conversation.
What your security team can request.
The documents a security review actually needs, available under NDA through the attestations portal.
Available under NDA through the attestations portal at trust.etslabs.ai.
Beyond the fact sheets.
Security and Trust
The full data journey: where a conversation goes from ingest to scored evidence.
Read the security modelCompliance and Redaction
Disclosure checks, the redaction pipeline, and audit-ready evidence.
See complianceAttestations portal
SOC 2 and ISO reports and the security questionnaire, available under NDA.
Request accessSecurity and trust, in plain terms.
Where does our conversation data go?
It is ingested into the QEval environment, where personal information is redacted, then scored by QEval's own closed mixture of experts. It does not pass through a general third-party model. The full path is on the Security and Trust page.
Do you use our data to train AI models?
No. Your conversations are not used to train any third-party foundation model, and the scoring models are QEval's own. Personal information is redacted at ingest before any processing.
Which certifications do you hold?
SOC 2 Type II, ISO 27001, ISO 42001 (AI management), PCI DSS Level 1, HIPAA, GDPR, and CCPA, with PII redaction at ingest across the platform.
Can we get your SOC 2 report and security questionnaire?
Yes. The audited reports and the completed security questionnaire are available under NDA through the attestations portal. Your team can request access there or through your pilot contact.
How long do you keep our data?
As long as your policy says, and no longer. Retention is configurable: scored evidence is kept for the audit window you set, then purged on your schedule. The specifics are written into the data processing agreement.
Hand this to your security team.
Start a pilot and we will walk security and procurement through the fact sheets, the attestations, and exactly how your data is handled, before anything is signed.