Trust Center

Trust Center

Qlogue is designed for environments where evidence, security and accountability matter. This Trust Center provides information on our security, privacy, AI governance and operational controls.

Some assurance documentation is publicly available. Sensitive security and due-diligence material may be provided to clients and prospective clients following an access request.

Assurance status

The following indicators reflect the current state of Qlogue's control environment. Controls evolve as our products and operating environment develop.

✓Implemented◐In progress○Planned⊘Certificate icon shown only for independently certified controls

Information Security Management

In progress

Qlogue maintains a documented information-security framework covering access control, information handling, secure development, incident management, supplier risk and business continuity.

ISO/IEC 27001:2022

In progress

Qlogue is developing its information-security management framework with reference to ISO/IEC 27001:2022. Certification has not yet been awarded.

SOC 2

Planned

SOC 2 assurance is being evaluated. No SOC 2 report currently exists.

UK Data Protection

Implemented

Qlogue operates a documented privacy and data-handling framework designed around applicable UK data-protection requirements.

AI Governance

Implemented

Qlogue maintains governance controls for the use, development, evaluation and change management of AI-enabled systems.

Secure Development

Implemented

Product development follows controlled source-code, access, testing, dependency and change-management practices.

Security controls

The following categories summarise Qlogue's operational security controls. Detailed policy documentation is available to clients and prospective clients on request.

Synthetic-first development

Client / Production Environment

↓ controlled access

Qlogue Approved Production Environment

Separate from

Product Development Environment

Synthetic data

Anonymised data

Benchmark datasets

Non-client development material

Qlogue follows a synthetic-first development model. Product development and testing performed within the product development environment are designed to use synthetic, anonymised or otherwise approved non-client datasets.

Client production information is not routinely made available to the product development environment.

Any exception requires formal approval, an identified business purpose, appropriate security controls and applicable legal and data-transfer safeguards.

AI System Governance

Qlogue treats AI assurance as a system-level control problem rather than considering only the underlying model. Governance controls apply across each layer of an AI-enabled system.

System layers

Model

Model and provider approval; model-version change controls

Service

API changes; service-level monitoring and escalation

Harness

Prompt and instruction management; RAG and evidence-source changes

Use Case

Human oversight; evaluation; dependency changes

Dependency

Dependency changes; third-party risk; change management

Governance controls

Model and provider approval
Model-version change controls
Prompt and instruction management
RAG and evidence-source changes
API change controls
Dependency change management
Human oversight requirements
Evaluation and testing
Monitoring and alerting
Escalation procedures

How we evaluate AI-enabled systems

Qlogue uses multiple evaluation mechanisms depending on the risk and use case. Evaluation design is selected according to risk and use case rather than relying solely on model-vs-model evaluation or outcome accuracy.

Deterministic controls

  • Schema validation
  • Citation verification
  • Required-field checks
  • Reconciliation
  • Threshold tests
  • Rule-based control checks
  • Provenance integrity checks

Model-based evaluation

  • Independent challenge
  • Contradiction detection
  • Omission identification
  • Evidence-grounding assessment
  • Reasoning consistency
  • Adversarial review

Human evaluation

  • Subject-matter review
  • Professional judgement
  • Severity assessment
  • False-positive assessment
  • Escalation decisions
  • Final acceptance

Reasoning provenance

Qlogue products are designed around reconstructability. Where appropriate, conclusions should remain connected to the evidence, rules, assumptions, challenges and human decisions that produced them.

Ground
Analyse
Challenge
Verify
Visible judgement
Claim-to-source traceability
Citation checking
Evidence boundaries
Assumptions
Challenge records
Human interventions
Overrides
Decision records
Version history

Data we process

The following summarises the categories of personal and operational information Qlogue may process.

Website and business contacts

  • Names
  • Business email addresses
  • Organisation
  • Job title
  • Correspondence
  • Newsletter and community preferences

adubio users

Where applicable

  • Account information
  • Authentication information
  • Usage information
  • Workspace metadata

Client information

Processing depends on the relevant engagement, contractual arrangement and deployment architecture.

Client-data requirements are assessed engagement by engagement. Qlogue seeks to minimise the personal and confidential information required for product testing and assurance activities.

For full details, see our Privacy Notice.

Service providers & subprocessors

Qlogue maintains a register of technology and processing providers. Further information can be provided as part of client due diligence.

Policy library

The following documents are publicly available. Detailed internal procedures are available to clients and prospective clients on request.

Privacy NoticeView
Cookie NoticeView
Terms of UseView
Information Security OverviewAvailable on request
AI Governance OverviewAvailable on request
Responsible AI PrinciplesAvailable on request
Data Handling OverviewAvailable on request
Vulnerability Disclosure PolicyAvailable on request

Assurance resources

Qlogue maintains a library of assurance documentation. Public documents are available below. Sensitive material is provided following a reviewed access request.

Public

Privacy NoticeView
Security OverviewAvailable on request
AI Governance OverviewAvailable on request
Data Processing OverviewAvailable on request
Subprocessor ListAvailable on request
Vulnerability Disclosure PolicyAvailable on request

Available on request

Information Security Policy
Access Control Policy
Secure Development Policy
Incident Response Policy
Business Continuity Plan summary
Data Classification Policy
Third-Party Risk Policy
AI System Governance Policy
AI Evaluation & Assurance Policy
Architecture and security overview
Completed security questionnaires

Future independent assurance

ISO/IEC 27001 certificateNot yet available — certification in progress
Penetration-test executive summaryNot yet available
SOC 2 reportNot yet available

Request assurance documents

Complete the form below to request access to Qlogue's assurance documentation. Requests are reviewed by Qlogue before any material is shared. Sensitive documents are not distributed automatically.

By submitting this form, you acknowledge our Privacy Notice. Your details will be used to process and respond to your request.

Report a security issue

We welcome responsible reports of potential security vulnerabilities affecting Qlogue services.

Security contact

[email protected]

Responsible disclosure

  • Provide sufficient detail to allow us to reproduce and assess the issue.
  • Do not access, modify or delete data beyond what is necessary to demonstrate the vulnerability.
  • Do not disclose the issue publicly before we have had a reasonable opportunity to assess and address it.
  • We will acknowledge receipt of your report and keep you informed of progress where appropriate.
  • Qlogue does not currently operate a formal bug-bounty programme.

Trust & security updates

Material trust and security updates, including new certifications, significant control improvements and relevant service incidents, will be published here.

No material trust or security updates have been published.

Service status

Formal public service-status reporting will be introduced as adubio moves into production enterprise deployment.

Security & due diligence

If you are conducting supplier due diligence on Qlogue or adubio, submit your security questionnaire or information request through the Trust Center.

Trust Center owner

Qlogue

Last reviewed

September 2026

Version

1.0

Security and privacy controls evolve as Qlogue's products and operating environment develop. Information published here reflects the current control environment and is reviewed periodically.

Qlogue

Reasoning provenance infrastructure for regulated institutions.

Qlogue, in your inbox

Research, fieldnotes and practitioner explainers, periodically.

By subscribing you consent to receive the Qlogue newsletter by email. You can unsubscribe at any time. Privacy notice.

© 2026 Alogue Advisory Ltd. All rights reserved.

Qlogue is a trading name of Alogue Advisory Ltd. Registered in England and Wales. Company No. 17388755.