PowerQuant

Trust Center

CAIQ-Lite

Cloud Security Alliance CAIQ v4.0 (lite subset, ~50 most-asked questions for mid-market B2B sales). Full CAIQ v4.0 (~270 questions) available on request via security@powerquant.dk.

Last updated 2026-05-05. Reviewer: pending specialiseret IT-/AI-advokatfirma security/compliance counsel.

Application + Interface Security (AIS)

IDQuestionPowerQuant answer
AIS-01Application security policies documented?Yes. SECURITY.md + pre-commit secret-leak prevention.
AIS-02Vulnerability assessments run regularly?Quarterly external code-review. Trivy scans on Docker images.
AIS-03Penetration tests conducted?Annual third-party pen-test scheduled post-Day-180 milestone.

Audit Assurance + Compliance (AAC)

IDQuestionPowerQuant answer
AAC-01SOC 2 Type II?Roadmap Day 545 (post 75K kr/md MRR gate). Currently pre-SOC-2; manual evidence kit.
AAC-02ISO 27001?Not currently certified. Internal controls map to ISO 27002 reference.
AAC-03EU GDPR compliance?Yes. Article 28 DPA available. DPO: dpo@powerquant.dk.
AAC-04EU AI Act compliance?AI provider per Article 4. Article 4 register maintained. Article 50 disclosure on /trust/article-50.
AAC-05NIS2 compliance?Sub-50 FTE / sub-75M kr revenue → not directly classified essential or important entity. Support customers' Article 21(d) supplier-oversight obligations.

Business Continuity + Operational Resilience (BCR)

IDQuestionPowerQuant answer
BCR-01Backup strategy?Hetzner encrypted snapshots, 30-day rolling. Restore-tested quarterly.
BCR-02RPO / RTO?RPO ≤24h. RTO ≤4h tier-1 systems.
BCR-03Disaster recovery plan?Documented internally; sample available NDA-bound.

Change Control + Configuration Management (CCC)

IDQuestionPowerQuant answer
CCC-01Change-management process?All canonical-path changes require Council pre-flight (multi-agent + human sign-off) + signed audit-log entry.
CCC-02Code review before deploy?Yes. Pre-commit hook + Tech Sentinel review.

Data Security + Lifecycle (DSL)

IDQuestionPowerQuant answer
DSL-01Data classification?Customer data classified customer-confidential. Strategic data internal-confidential.
DSL-02Encryption at rest?Hetzner volumes (LUKS). Supabase Postgres native.
DSL-03Encryption in transit?TLS 1.3 enforced. HSTS on powerquant.dk.
DSL-04Key management?Ed25519 signing keys, 0600 perms, rotation-ready.
DSL-05Data retention?Customer evidence-bundles 7 years (audit-trail). Logs 90 days. PII minimised.

Datacenter Security (DCS)

IDQuestionPowerQuant answer
DCS-01Datacenter certifications?Hetzner DE: ISO 27001/27017/27018 + EN 50600. Vercel: SOC 2 Type II + ISO 27001. Supabase: SOC 2 Type II + HIPAA.
DCS-02Physical security?Hetzner: badge + biometric + 24/7 staff. Vercel: AWS-tier physical security.

Encryption + Key Management (EKM)

IDQuestionPowerQuant answer
EKM-01Key rotation?Quarterly review; immediate rotation on suspicion.
EKM-02HSM / KMS?File-system-stored Ed25519 keys, 0600 perms. HSM migration scheduled Day 545+ pre-SOC-2.

Governance + Risk Management (GRM)

IDQuestionPowerQuant answer
GRM-01Risk-assessment process?Quarterly Council pre-flight on roadmap. Annual external code-review.
GRM-02Policies + procedures?Internal canonical repo (read-only for non-founder).
GRM-03Insurance?E&O + cyber insurance scheduled (~90-165K kr/år budget allocated).

Human Resources Security (HRS)

IDQuestionPowerQuant answer
HRS-01Background check?Founder + Technical Officer: Danish CVR-listed; criminal record check on request.
HRS-02Security training?Annual self-administered + IAPP CIPP/E + AIGP credentialing for founder (in progress).
HRS-03Off-boarding?Documented runbook (one founder + one Technical Officer currently).

Identity + Access Management (IAM)

IDQuestionPowerQuant answer
IAM-01MFA enforcement?Yes — GitHub, Stripe, Hetzner, Supabase, Cloudflare all MFA-enforced.
IAM-02RBAC?Founder = root. Technical Officer = read-only canonical + write omega/agents.
IAM-03Access reviews?Quarterly. Documented in audit-log.
IAM-04Privileged access management?sudo NOPASSWD only on dedicated deploy user; bot runs as unprivileged agent.

Infrastructure + Virtualisation Security (IVS)

IDQuestionPowerQuant answer
IVS-01Network segmentation?Hetzner private VLAN between web/db. Cloudflare WAF in front.
IVS-02Hardening?CIS-baseline applied to Hetzner Ubuntu 24.04 LTS. UFW + fail2ban.

Security Incident, Event Forensics (SEF)

IDQuestionPowerQuant answer
SEF-01Incident-response plan?Documented internally. Notification: 24h to customer, 72h GDPR Article 33.
SEF-02Recent incidents?None currently disclosable as of 2026-05-05.

Supply Chain Management (STA)

IDQuestionPowerQuant answer
STA-01Sub-processor list?/trust/sub-processors — 10 entries (Hetzner, Cloudflare, Vercel, Supabase, Anthropic, OpenAI, Cohere, Stripe, Resend, Telegram).
STA-02Sub-processor changes?30-day customer notice + 14-day objection window.

Threat + Vulnerability Management (TVM)

IDQuestionPowerQuant answer
TVM-01CVE monitoring?Daily Trivy scan + npm audit + pip-audit on dependencies.
TVM-02Patch management?Critical CVEs: 24-72h. High: 7 days. Medium: 30 days.

AI-Specific (PowerQuant addendum)

IDQuestionPowerQuant answer
AI-01Models used?Anthropic Claude, Google Gemini, Groq Llama, OpenAI GPT. Heterogeneous failover.
AI-02Training data?We do NOT fine-tune on customer data. Anthropic + OpenAI confirm zero-retention API mode.
AI-03Prompt-injection defence?Anti-fab veto + verbatim-grep + Council 4-method consensus.
AI-04Hallucination defence?Every claim cross-checked against primary EU regulation text. Ed25519 signature on each approval.
AI-05Article 50 disclosure?Yes. /trust/article-50.