AWS
Backing infrastructure layer (underpins MongoDB Atlas, Resend, several other subprocessors).
QorTrace maps every operational and platform control we run against SOC 2 Type II, ISO/IEC 27001:2022, NIST CSF 2.0, the EU's DORA, and the FFIEC IT-Examination handbook. The numbers below come straight from our internal GRC console — no marketing layer in the middle.
Every percentage on this page is generated from our internal GRC console. We don't "prepare" the numbers for visitors — what you see is what we see.
Every published policy carries an immutable version number. Diff any two versions to see exactly what changed since the last attestation.
Controls are mapped to SOC 2, ISO/IEC 27001:2022, NIST CSF 2.0, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, EU DORA, and FFIEC — the authorities institutional and federal procurement actually ask for.
Auditor-grade evidence (SOC 2 Type II reports, ISO certificates, signed attestations) is available under NDA. Email trust@qortrace.com to request the bundle.
We monitor our own SPF, DKIM, and DMARC daily so any DNS drift is caught within 24 hours. Why this matters →
Two safety nets run every morning: a sweep across every CNAME in our Cloudflare zones (looking for classic subdomain-takeover signatures) and an auto-repair watchdog that re-merges critical DNS records if a third party overwrites them. Findings, if any, are surfaced here within 24 hours. How we do this →
One email per month. Surfaces every drift in our SPF/DKIM/DMARC posture, every subdomain takeover sweep, and every self-healing repair fired in the last 30 days. Nothing else. Built for audit teams that need a paper trail.
Third-party services that process customer data on QorTrace's behalf. We disclose every active relationship below + publish a change-log so your security team can subscribe.
Backing infrastructure layer (underpins MongoDB Atlas, Resend, several other subprocessors).
Claude Sonnet 4.5 LLM inference for Qelli AI chatbot, talk-track generation, and methodology analysis. Customer data NEVER used to train models.
Edge CDN, WAF, DDoS protection, Turnstile bot mitigation, DNS.
Primary database hosting for customer accounts, scans, audits, and engagement data.
Product analytics, funnel attribution, A/B testing.
Transactional email delivery (signups, password resets, audit deliveries, drift alerts).
Error monitoring and stack-trace aggregation.
Payment processing, subscription billing, customer portal.
Each framework's met % is the share of in-scope controls (excluding N/A) marked met by our security team. Controls in the partial state have a remediation owner and a targetSOC 2 follows the AICPA Trust Service Criteria, ISO/IEC 27001 the 2022 Annex A taxonomy, NIST CSF 2.0 the 2024 Cybersecurity Framework (Govern · Identify · Protect · Detect · Respond · Recover), NIST SP 800-53 Rev. 5 the federal control catalog (17 families: AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PS, RA, SA, SC, SI), NIST SP 800-171 Rev. 3 the CUI protection baseline, DORA the EU 2022/2554 chapter structure, and FFIEC the IT-Examination handbook booklets. QorTrace's cryptographic engines themselves align with NIST PQC: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). For a SOC 2 Type II report or a signed compliance receipt, contact trust@qortrace.com.
We use strictly-necessary cookies to run the app. With your consent we also use analytics cookies to understand how QorTrace is used so we can improve it. Cookie Policy · Privacy Policy