Security & Trust

Enterprise isolation, by design

Every Qualimetry Enterprise customer runs in their own isolated cloud environment with dedicated infrastructure and data, role-based access control and a fully managed operating model.

Isolation

Your own environment, not a shared tenant

Qualimetry Enterprise is deployed per customer. Your infrastructure and your data stand alone, so nothing about your estate is co-located with another organisation.

Dedicated cloud

Your deployment runs in its own cloud subscription, resource group and virtual network, provisioned for your organisation alone.

Dedicated data

Your data lives in a database dedicated to your organisation. It is never pooled into a shared multi-tenant store.

Managed for you

Qualimetry provisions, operates and maintains the environment as a managed service, so your teams keep their focus on their code.

Access control

Control who can see and change what

Access is governed by role-based access control, administration and security roles and single sign-on, so the right people have the right access and nobody has more than they need.

  • Role-based access control that scopes what each person can see and do.
  • Administration and security roles so sensitive actions sit with named owners.
  • Single sign-on so access follows your existing identity provider.
Accountable by default

Security decisions are recorded, scoped and reviewed

A vulnerability suppression moves through an approval workflow that records who asked, who decided, on what evidence, over what scope and until when. No risk is accepted silently.

  • Approval workflow so a suppression is a decision, not a quiet edit.
  • An AI assessment recorded against the decision, so the reviewer had an argued position rather than a bare severity.
  • The next compliant upgrade checked first, so acceptance is a last resort rather than a first one.
  • Scope and expiry so accepted risk is bounded and revisited rather than forgotten.
  • The requester is told, by email, on approval or rejection.
Agent access

Coding agents get read access, and nothing more

Connecting an agent to Qualimetry is one of the questions a security team will ask about first. Every one of the eighteen MCP tools is read-only, so an agent can ask what your standards are and what findings are open, and that is the entire surface.

  • No write path exists from an agent into your standards, findings or configuration.
  • Tokens are scoped to your organisation and issued through the Compliance Center.
  • Authoring stays with people you authorise, in the Standards Center.
We hold ourselves to it

The platform meets the standards it enforces

Qualimetry applies its own governance, review and analysis to itself, so the platform is held to the same quality and security bar it sets for your teams.

Per-customer
isolation
Dedicated
data
Role-based
access
Fully
managed
Questions

Security and trust, answered

Is our data isolated from other customers?
Yes. Qualimetry Enterprise is deployed per customer, with a dedicated environment and a database dedicated to your organisation. Your data is never pooled into a shared multi-tenant store.
Who can access our environment?
Access is controlled by role-based access control and single sign-on. Administration and security roles scope what each person can see and do, so people only get the access their role needs.
How are security decisions governed?
Vulnerability suppressions move through an approval workflow. Each one carries a required note, a defined scope and an expiry, so accepted risk is recorded, reviewable and time-bound rather than silent.
Who operates the environment?
Qualimetry runs it as a managed service. We provision, operate and maintain the deployment for your organisation, so your teams keep their focus on their code.

Talk to us about your requirements

Book a demo to walk through the deployment model and access controls for your organisation.

Book a Demo