Security / Public website

Security

This statement describes how Quantos Systems Private Limited protects information handled through the public Quantos website pages, briefing requests, contact channels, and pre-engagement communications. Security is treated as an architectural property: least-privilege access, controlled data handling, transport protection, and accountable change.

This is a website security statement. It is not a certification, warranty, or service-level commitment, and it does not govern the security of the Quantos platform in a customer deployment that is governed by the applicable Customer Agreement and a controlled security review.

ScopePublic website

Pages, enquiries and pre-engagement communications.

HandlingPurpose-bound

Only the information required for the initiated interaction.

AccessAuthorised personnel

Restricted access, accountable change and controlled delivery.

Deployment evidenceControlled review

Customer architecture and evidence shared under confidentiality.

Security principles

The website is built on the assumption that visitor and enquiry information must remain protected, purpose-bound, and handled only by authorised personnel. Controls are selected to preserve confidentiality, integrity, availability, and accountability.

  • Least privilege by default. Access to website systems and enquiry data is limited to the minimum authority required for an approved function, and elevated access is restricted and accountable.
  • Purpose-bound handling. Information submitted through the website is used only to respond to and administer the interaction you initiated, as set out in the Privacy Policy.
  • Accountable change. Changes to the website and its supporting configuration are made through controlled, reviewable processes.
  • Data minimisation. Public forms request only the information needed for the relevant business conversation.

Protecting website data

Information you submit through the website such as your name, organisation, business contact details, and enquiry content is handled under controlled processes and delivered only to authorised Quantos personnel.

  • Controlled intake. Briefing and contact submissions are routed through approved processing and delivery paths, not exposed to public access.
  • Do not submit sensitive data. Public forms are not an approved channel for confidential enterprise data, production credentials, personal customer records, regulated datasets, classified information, or export-controlled information. Where such information is necessary, an approved secure channel and written terms are established first.
  • Retention. Website enquiry data is retained only as long as reasonably necessary for the stated purpose, security, and legal obligations, as described in the Privacy Policy.

Transport and infrastructure

The website is served over encrypted connections and supported by controls appropriate to a public informational site.

  • Encryption in transit. HTTPS/TLS protects data exchanged between your browser and the website.
  • Access control. Administrative access to the website and its hosting environment is restricted, credential- protected, and limited to authorised personnel.
  • Secrets handling. Credentials, tokens, and environment secrets are kept outside public source and managed through deployment-appropriate controls.
  • Logging and monitoring. Security-relevant events and anomalous conditions are logged and reviewed according to the operating context and available telemetry.

Secure operations

Security is maintained through controlled change, dependency management, vulnerability handling, and operational discipline across the website lifecycle.

  • Controlled change. Changes affecting the live website pass review and authorised deployment.
  • Dependency and vulnerability management. Components and dependencies are monitored and updated, and identified vulnerabilities are assessed and remediated according to severity, exposure, and risk.
  • Cookies and analytics. Optional analytics and measurement technologies operate only in accordance with the cookie controls and choices described in the Privacy Policy.

Responsible disclosure

Security researchers and users should report suspected vulnerabilities in the website privately and responsibly. Do not perform destructive testing, denial-of-service, social engineering, data exfiltration, persistence, or access beyond what is required to demonstrate the issue.

Include
Affected URL or component, reproduction steps, observed behaviour, potential impact, and supporting evidence.
Avoid
Public disclosure before remediation coordination, destructive activity, service disruption, privacy invasion, or accessing unrelated data.
Response
Valid reports are reviewed and acknowledged according to severity, available evidence, and operational context. Remediation timing depends on confirmed risk.

Platform and customer deployments

This page covers the public website only. Security of the Quantos platform in a customer environment including deployment architecture, tenant separation, data isolation, encryption at rest, resilience, incident notification, and shared-responsibility terms is governed by the applicable Customer Agreement and its security, privacy, data-processing, and deployment addenda.

Prospective and active customers may request a controlled security review. Detailed architecture, environment controls, sub-processor information, and available evidence are shared under appropriate confidentiality terms.

Scope and legal notice

This page is a public description of website security practices. It is not a certification, warranty, or service-level commitment, and it does not substitute for a signed agreement.

  • Website scope. This statement covers the public Quantos website and its briefing and contact flows, together with the published Privacy Policy.
  • Platform scope. Platform security commitments apply only to customer environments provisioned under a signed Customer Agreement and applicable addenda.
  • Third parties. Customer-managed systems and third-party services outside the Company’s control are not included unless expressly identified in scope.
  • No absolute guarantee. No website or system can eliminate all security risk. Controls are applied to reduce exposure, detect misuse, preserve evidence, and support recovery.
  • Intellectual property. The Quantos website and system are operated by Quantos Systems Private Limited. The system and related inventions are protected by applicable intellectual-property rights and patent applications.
  • Changes. This statement may be updated to reflect changes in the website, its controls, or applicable legal obligations.

Security contact

For a website security report, a controlled security review, or any question about this statement, contact:

Organisation
Quantos Systems Private Limited
Postal address
2, Mahakaal Ki Baithak, Near Sai Dreams, Amlidih, Raipur, Chhattisgarh 492001, Bharat