Security

When it comes to your security,
we don't blink.

Our products serve regulated industries. Security is not a feature added later. It is the foundation everything is built on.

What every product we ship inherits.

Regardless of which product you use or which industry you operate in, every Quantum Shield deployment shares the same security foundation. This is not configurable. It ships by default.

All products
End-to-end encryption

All data encrypted at rest and in transit. No plaintext storage anywhere in the system, at any layer.

All products
Complete tenant isolation

Each organization's data is separated from every other at the database level. Cross-tenant access is architecturally impossible, not just policy-restricted.

All products
Immutable audit logs

Every action is permanently logged with a server-side timestamp. Records cannot be altered or deleted after the fact — by anyone, including us.

All products
Role-based access control

Every user sees only what their role explicitly permits. Enforced at every layer of the system, not just the interface.

Different products. Different industries.
Different requirements.

Mira and GuardView are deployed in industries with distinct regulatory and operational security needs. Here is how each product addresses them.

Mira operates in healthcare, home care, field services, and private security — industries where location data, shift records, and incident documentation carry legal and compliance weight.

Healthcare and Home Care

Mira's infrastructure is designed to meet HIPAA technical safeguard requirements. Location data, shift records, and care documentation are treated as sensitive health-adjacent information. Data access is logged, isolated, and encrypted at every layer. A Business Associate Agreement is available for applicable healthcare deployments.

Field Services and Logistics

Field deployments use Mira for technician location, job-site check-in, and service records. GPS data access is strictly scoped — workers see their own records, supervisors see their assigned teams, administrators see their organization. Nothing more.

Private Security Operations

Security operations require shift accountability and incident documentation that holds up to scrutiny. Every clock event, location ping, and incident report is server-timestamped and cannot be retroactively altered — providing a chain of accountability built for the industry.

Encryption at restYes
Encryption in transitTLS enforced
HIPAA-ready infrastructureYes
Business Associate AgreementAvailable
Location data sold or sharedNever
Location anti-spoofingYes, multi-signal validation
Audit log retentionPer subscription tier
PlatformsWeb, iOS, Android

GuardView is deployed in corporate campuses, secure facilities, and environments where visitor access control and a verifiable record of entry and exit are operational requirements.

Corporate and Enterprise Facilities

GuardView provides an auditable record of every facility visitor — who requested access, who approved it, when they arrived, and when they left. Each organization's visitor data is completely isolated. No other GuardView client can access your records under any circumstances.

Secure and Sensitive Installations

For facilities with heightened access requirements, GuardView's role architecture separates what employees, guards, and administrators can see and do. Pre-registration workflows ensure visitors are vetted before arrival. Every gate interaction is logged with a tamper-proof timestamp.

Visitor information — names, contact details, visit purpose, and access records — belongs to the facility operator. It is never shared with third parties or used for any purpose outside that organization's operational record. Visitor data is accessible only to authorized administrators within that specific organization.

Encryption at restYes
Encryption in transitTLS enforced
Visitor data sold or sharedNever
Cross-facility data accessImpossible
Tamper-proof visit logsYes
Role-based accessAdmin, Guard, Employee
Installation requiredNone — browser-based
Audit exportCSV, on demand

Found a security issue?

We take every report seriously and respond within 24 hours. Contact us directly if you have identified a potential vulnerability in any Quantum Shield product. We do not take legal action against researchers acting in good faith.

Report a security issue

Send a clear description of the issue, the product affected, and steps to reproduce. We will acknowledge receipt within 24 hours.

Contact security team