Art. 50(2) marking deadline: 2 Dec 2026 · 57 days

Security

Security and data residency

The infrastructure facts your security team will ask for, in one place: region, inference, retention and the controls around them.

Security & Compliance

EU-first. Sovereign by design.

Customer data is stored and processed in AWS Frankfurt (eu-central-1). Inference runs in the EU. No customer data is transferred to US regions. Built by a European company for European institutions.

Full security documentation: tracegov.ai/security

0Customer data transfers to US regions
TLS 1.3Enforced for data in transit
7 yrAudit Trail Retention
6Frameworks assessed, our own assessment

Data Residency

AWS Frankfurt (eu-central-1)

Customer data is stored and processed in Frankfurt. Inference runs in the EU. No customer data is transferred to US regions.

Encryption at Rest

AES-256 via AWS KMS

Databases, knowledge graph and document store, all encrypted.

Encryption in Transit

TLS 1.3 enforced

All data in motion protected with latest transport layer security.

Merkle-Chain Audit Trail

SHA-256 hash-verified records

Cryptographic linking between records. 7 years retention.

Regulatory Compliance

Six frameworks. Statuses are our own assessment, not certifications.

  • GDPRAligned

    Articles 5, 25, 28, 32, 35, 44-49

    Data protection by design. Consent-gated analytics. No cross-border transfer outside EU.

  • EU AI ActAligned

    Articles 9, 12, 13, 14, 26

    Risk management, record-keeping, transparency, human oversight, and deployer obligations.

  • SOC 2 Type IIIn Progress

    Security, availability, and confidentiality controls under independent audit.

  • ISO 27001Aligned

    Information security management system aligned with international standards.

  • NIS2 DirectiveAligned

    Network and information security measures for essential and important entities.

  • DORAAligned

    Digital operational resilience for financial sector ICT risk management.

Access Control

  • Role-Based Access Control

    Granular permissions per workspace, per user, per action.

  • Multi-Factor Authentication

    MFA enforced for all accounts. No exceptions.

  • Least-Privilege IAM

    Every function, service and role carries minimum permissions only.

Transparency & AI Ethics

  • No Foundation Model Training

    Your prompts and responses are never used to train foundation models. Your regulatory data stays yours.

  • Honest Benchmarks

    We publish our real TRACE scores -- 60-67%, not >90%. Regulatory AI is hard. We measure honestly and improve transparently.

  • EU-First

    Quantamix Solutions is an EU-based company building sovereign AI infrastructure. Data residency, compliance and transparency are not features. They are foundations.

AWS stack, data flow, incident-response SLA and secure-development practicesShow details

Enterprise-Grade AWS Infrastructure

Full stack deployed in AWS Frankfurt (eu-central-1)

Compute & Delivery

  • AWS Lambda: serverless, auto-scaling
  • AWS Amplify: frontend and CI/CD
  • CloudFront CDN: TLS 1.3 enforced
  • Route 53: DNS with DNSSEC
  • WAF: DDoS protection, rate limiting

AI & Data

  • AWS Bedrock: EU inference profiles only
  • DynamoDB: 14 tables, AES-256 encrypted
  • Neo4j: knowledge graph, encrypted
  • S3: document storage, encrypted
  • TRACE and CERI engines: custom AI scoring

Identity & Monitoring

  • AWS Cognito: MFA, JWT, token rotation
  • IAM: least-privilege, role-based
  • CloudWatch: real-time monitoring
  • Automated anomaly alerting
  • Stripe: PCI DSS Level 1, EU processing

Data flow: everything stays in Frankfurt

Client Browser→ TLS 1.3 →→CloudFront CDN→Amplify + Lambda→Bedrock AI→DynamoDB + Neo4j

All services configured to eu-central-1 via IAM policies, VPC config, and service endpoints.

Incident Response SLA

MinutesDetection (automated)
<1 hourAcknowledgment
<4 hoursContainment
<24 hoursCustomer notification

Secure Development Practices

  • Infrastructure as Code (AWS CDK/CloudFormation)
  • Automated dependency vulnerability scanning
  • Code review required for all production changes
  • Separate staging and production environments
  • Zero third-party data sharing

Responsible Disclosure

Security researchers can report vulnerabilities via security@tracegov.ai.

24h

Acknowledgment

72h

First update on resolution

Full security documentation and Data Processing Agreements available for enterprise customers upon request.