Trust · Compliance · Architecture

The QorBOM security & trust posture.

A single page your procurement team can cite. Every claim below is verifiable today — through the standards we natively emit, the regulations we map to, the public methodology log, and the architecture commitments documented in our partner agreement.

Service status
Operational
Methodology version
qortrace-cbom-method-v0.1
BOM specs supported
CycloneDX 1.6 · SPDX 3.0.1
API uptime target
99.5% (commitment)
Compliance overview

Standards alignment at a glance.

The visual summary — hover for a quick summary, click for full evidence. The detailed citation matrix is below.

Architecture commitments

Four guarantees, written into every partner agreement.

These are not aspirations — they are how the platform works at the code level today. Procurement teams can verify each one by inspection.

Source code is never retained

Repository tarballs are fetched into memory, scanned, and discarded. Only the resulting BOM persists. No client source code lives on QorTrace infrastructure beyond the scan window (~30 seconds typical).

Tenant isolation enforced at every query

Every API call carries a tenant_id+tenant_kind tuple. No cross-tenant read path exists. API keys are stored as SHA-256 hashes — the plaintext bytes leave our infrastructure exactly once, at issuance.

Reproducible by methodology pin

Every BOM carries an immutable qortrace-cbom-method-v* version and a SHA-256 over the canonical-sorted output. Two scans of the same repo at the same methodology version produce byte-identical BOMs.

Data residency: documented, region-pinnable

Production data lives in a single documented region by default. Enterprise tier supports region pinning to EU-only or US-only infrastructure for clients with sovereignty requirements.

Standards · Regulations · Bodies

Full alignment matrix.

Procurement teams: this is the table to copy into your vendor assessment. Every row is auditable against the cited specification.

Framework / specVersionStatusScope
CycloneDX1.6ImplementedNative output · cryptographic-asset components
SPDX3.0.1ImplementedNative output · security_CryptographicAsset elements
Package URL (purl) specstableImplementedUniversal component identification
OpenAPI3.1ImplementedPartner API contract
NIST FIPS 203 (ML-KEM)Final · 2024ImplementedDetected & graded as quantum-safe
NIST FIPS 204 (ML-DSA)Final · 2024ImplementedDetected & graded as quantum-safe
NIST FIPS 205 (SLH-DSA)Final · 2024ImplementedDetected & graded as quantum-safe
NIST SP 800-218AInitial Public DraftAlignedPQC profile of SSDF
NSA CNSA 2.0v1.0 · 2022Aligned2030/2035 deadline tracking in output
EU Cyber Resilience ActArticle 13 · 2027AlignedCBOM mandate compliance path
EU DORAArticle 24 · TLPTAlignedCryptographic mapping evidence
EU NIS2Directive 2022/2555AlignedRisk-management documentation
EO 14028 (Improving Cybersec)Federal · 2021AlignedCrypto inventory narrative for SSPs
EO 14306Federal · 2024AlignedCrypto agility assessment input
FedRAMPrev 5AlignedCryptographic inventory section evidence
CMMC 2.0L2 / L3AlignedSC.L2-3.13.11 evidence input
ENISA PQC migration guidanceJune 2024AlignedCycloneDX-native output matches ENISA toolkit
OWASP CycloneDX projectContributorOutput format used by spec maintainers
SOC 2 Type Iin progressIn progressAudit window opens Q3 2026
ISO 27001plannedPlannedTargeted post-Series-A
Platform architecture

Six layers. Each one verifiable.

  1. 01
    API edge

    Cloudflare-fronted HTTPS · TLS 1.3 · HSTS preload · WAF rules · Bearer token auth · per-tenant rate limits

  2. 02
    Application

    FastAPI on Python 3.11 · stateless workers · tenant_id+tenant_kind on every request · structured access logs

  3. 03
    Scan engine

    In-memory tarball scan · 25 MB / 1k file caps · 25s wall-clock budget · no source-code persistence

  4. 04
    Storage

    MongoDB with TLS · field-level encryption for BOM payloads · TTL indexes for ephemeral cache · daily snapshots

  5. 05
    Secrets

    API keys: SHA-256 hashed at rest · plaintext shown ONCE · revocation propagates within seconds · per-key call telemetry

  6. 06
    Observability

    Per-request trace IDs · 30-day log retention · automated alerts on auth-anomaly patterns · public status page (in build)

QorTrace methodology

Versioned. Pinned to every output. Public.

The same methodology that powers QorTrace's enterprise audit engagements — used today by treasuries, custodians, and exchanges for their post-quantum readiness reviews — is the foundation for every QorBOM scan.

Current version
qortrace-cbom-method-v0.1
Active since
2026-02-17
Change-control policy
Public versioned log · all changes carry a date stamp + rationale · prior versions remain queryable for historical scan reproducibility
Reproducibility guarantee
Same repo + same methodology version → byte-identical BOM SHA-256
Peer review
External quantum-cryptography advisory reviewers vetting methodology changes before promotion
Founding partner cohort

25 firms. By application only.

QorBOM is launching with a deliberately small founding cohort of audit firms, MSSPs, and consultancies. The cohort closes before Q3 2026 general availability. Members get sandbox access during the methodology lock-down period, direct input on the platform roadmap, and preferential white-label pricing held for the life of their first three-year term.

We deliberately seat the cohort small — methodology integrity at this stage matters more than logo count. The same discipline that gets a methodology cited in regulatory workpapers gets it wrong in the first six months of unchecked growth.

Apply to the founding cohort
Cohort terms
  • Sandbox API key issued within 2 business days of approval
  • Founder-direct technical onboarding call (30 min)
  • White-label pricing locked for first three-year term
  • Direct input on methodology v0.2 → v1.0 roadmap
  • Right of first refusal on the Q3 2026 GA Series-A round
  • No platform fee until first 10 successful client scans
Vendor onboarding kit

Need the formal compliance pack?

We ship a vendor-assessment kit to procurement teams reviewingQorBOM for inclusion in their tooling pipeline. Includes the full architecture diagram, methodology change-log, incident-response policy, data-residency commitments, and an SOC 2 Type I bridge letter (where applicable).

Email partners@qortrace.com

Pack delivered within 1 business day for active partner applicants.