No AI credentials in a run
Test runs hold no AI credentials, so a model call cannot happen inside a run, even by mistake.
The Qventis Engine compiles tests once and runs them with zero AI tokens, so no model is in the loop at run time. Around it, your security team sets where AI may help authors, which model and region it uses, and who approves.
| Scope | AI policy | Model and zone |
|---|---|---|
| Retail | Generate with approval | Azure OpenAI, EU data zone |
| Claims | Suggest only | Amazon Bedrock, US region |
| Payments | Off | None, no model call possible |
| Reporting | Suggest only | Local model |
Test runs hold no AI credentials, so a model call cannot happen inside a run, even by mistake.
The author of a test, heal or AI draft is never its sole approver. That holds for people and agents alike.
AI permissions grow only on evidence and drop back automatically when a rule is breached.
Each scope gets one setting, so a regulated line of business and an internal tool follow different rules on one platform.
Administrators decide how far AI may go in each scope. Approving a heal always stays with a person.
Access works the way your identity team already runs it, and is denied by default.
Data is encrypted in transit with TLS and at rest. Prompts and outputs stay in the residency zone you pin each scope to.
Every action is recorded with who, what, when and why, and exports to your SIEM.
Use the security contact form and choose "Report a vulnerability". We acknowledge your report, keep you updated and ask for reasonable time to fix before disclosure.
Yes. Ask during your evaluation and we walk your security team through it.
We walk your team through AI policy, approvals and audit on your own scenarios.