Trust Center
QueryTek Review™ provides this page for procurement and security reviewers. It summarizes what we can substantiate today and what is still in progress. The full customer security packet is available on request through your account team.
Security posture we can discuss today
- Pull requests run static analysis and dependency scanning (SAST/SCA) per our CI security contract.
- The repository is scanned for high-confidence secret patterns on every change.
- Open-source license compliance is checked for runtime dependencies with a maintained third-party notices file.
- First-party application and script sources are scanned for copyleft license headers before release.
- Dynamic analysis runs on a scheduled staging baseline over Review-owned registration and payment surfaces (not on every pull request).
- Review is human-scored language quality assurance (LQA); quality outcomes reflect human reviewer judgment, not a standalone AI scoring product.
Not yet available
| Topic | Status |
|---|---|
| SOC 2 Type II report | Not yet issued. The customer security packet describes current controls and planned assurance. |
| Contracted penetration test executive summary | Not yet delivered. A third-party penetration test is scheduled; we do not claim completion. |
| Public CSA STAR listing | Not published. Any future STAR listing requires Legal approval and a separate program decision. |
Request materials
We share the current customer security packet and related diligence materials under our existing distribution process. This is not a self-serve download of a SOC report or penetration test.