Trust Center
Trust Center
Qlogue is designed for environments where evidence, security and accountability matter. This Trust Center provides information on our security, privacy, AI governance and operational controls.
Some assurance documentation is publicly available. Sensitive security and due-diligence material may be provided to clients and prospective clients following an access request.
Assurance status
The following indicators reflect the current state of Qlogue's control environment. Controls evolve as our products and operating environment develop.
Information Security Management
In progressQlogue maintains a documented information-security framework covering access control, information handling, secure development, incident management, supplier risk and business continuity.
ISO/IEC 27001:2022
In progressQlogue is developing its information-security management framework with reference to ISO/IEC 27001:2022. Certification has not yet been awarded.
SOC 2
PlannedSOC 2 assurance is being evaluated. No SOC 2 report currently exists.
UK Data Protection
ImplementedQlogue operates a documented privacy and data-handling framework designed around applicable UK data-protection requirements.
AI Governance
ImplementedQlogue maintains governance controls for the use, development, evaluation and change management of AI-enabled systems.
Secure Development
ImplementedProduct development follows controlled source-code, access, testing, dependency and change-management practices.
Security controls
The following categories summarise Qlogue's operational security controls. Detailed policy documentation is available to clients and prospective clients on request.
Synthetic-first development
Client / Production Environment
Qlogue Approved Production Environment
Separate from
Product Development Environment
Synthetic data
Anonymised data
Benchmark datasets
Non-client development material
Qlogue follows a synthetic-first development model. Product development and testing performed within the product development environment are designed to use synthetic, anonymised or otherwise approved non-client datasets.
Client production information is not routinely made available to the product development environment.
Any exception requires formal approval, an identified business purpose, appropriate security controls and applicable legal and data-transfer safeguards.
AI System Governance
Qlogue treats AI assurance as a system-level control problem rather than considering only the underlying model. Governance controls apply across each layer of an AI-enabled system.
System layers
Model and provider approval; model-version change controls
API changes; service-level monitoring and escalation
Prompt and instruction management; RAG and evidence-source changes
Human oversight; evaluation; dependency changes
Dependency changes; third-party risk; change management
Governance controls
How we evaluate AI-enabled systems
Qlogue uses multiple evaluation mechanisms depending on the risk and use case. Evaluation design is selected according to risk and use case rather than relying solely on model-vs-model evaluation or outcome accuracy.
Deterministic controls
- Schema validation
- Citation verification
- Required-field checks
- Reconciliation
- Threshold tests
- Rule-based control checks
- Provenance integrity checks
Model-based evaluation
- Independent challenge
- Contradiction detection
- Omission identification
- Evidence-grounding assessment
- Reasoning consistency
- Adversarial review
Human evaluation
- Subject-matter review
- Professional judgement
- Severity assessment
- False-positive assessment
- Escalation decisions
- Final acceptance
Reasoning provenance
Qlogue products are designed around reconstructability. Where appropriate, conclusions should remain connected to the evidence, rules, assumptions, challenges and human decisions that produced them.
Data we process
The following summarises the categories of personal and operational information Qlogue may process.
Website and business contacts
- Names
- Business email addresses
- Organisation
- Job title
- Correspondence
- Newsletter and community preferences
adubio users
Where applicable
- Account information
- Authentication information
- Usage information
- Workspace metadata
Client information
Processing depends on the relevant engagement, contractual arrangement and deployment architecture.
Client-data requirements are assessed engagement by engagement. Qlogue seeks to minimise the personal and confidential information required for product testing and assurance activities.
For full details, see our Privacy Notice.
Service providers & subprocessors
Qlogue maintains a register of technology and processing providers. Further information can be provided as part of client due diligence.
Policy library
The following documents are publicly available. Detailed internal procedures are available to clients and prospective clients on request.
Assurance resources
Qlogue maintains a library of assurance documentation. Public documents are available below. Sensitive material is provided following a reviewed access request.
Public
Available on request
Future independent assurance
Request assurance documents
Complete the form below to request access to Qlogue's assurance documentation. Requests are reviewed by Qlogue before any material is shared. Sensitive documents are not distributed automatically.
Report a security issue
We welcome responsible reports of potential security vulnerabilities affecting Qlogue services.
Security contact
[email protected]Responsible disclosure
- Provide sufficient detail to allow us to reproduce and assess the issue.
- Do not access, modify or delete data beyond what is necessary to demonstrate the vulnerability.
- Do not disclose the issue publicly before we have had a reasonable opportunity to assess and address it.
- We will acknowledge receipt of your report and keep you informed of progress where appropriate.
- Qlogue does not currently operate a formal bug-bounty programme.
Trust & security updates
Material trust and security updates, including new certifications, significant control improvements and relevant service incidents, will be published here.
No material trust or security updates have been published.
Service status
Formal public service-status reporting will be introduced as adubio moves into production enterprise deployment.
Security & due diligence
If you are conducting supplier due diligence on Qlogue or adubio, submit your security questionnaire or information request through the Trust Center.
Trust Center owner
Qlogue
Last reviewed
September 2026
Version
1.0
Security and privacy controls evolve as Qlogue's products and operating environment develop. Information published here reflects the current control environment and is reviewed periodically.