Data Collection Practices

What telemetry the platforms collect, and what they deliberately do not.

Last updated September 1, 2026

Visibility platforms are defined as much by what they exclude as by what they observe. This page describes the categories of data QAISG platforms process and the boundaries we design around.

QWatch

QWatch processes metadata about AI activity from telemetry sources the customer connects, such as identity providers, endpoint agents, browsers, enterprise AI platforms, and network or gateway logs. Typical fields include:

  • the AI tool, service, or endpoint involved,
  • the identity, device, and organizational unit associated with the activity,
  • timestamps, frequency, and category of use,
  • policy state (for example sanctioned, under review, exception) and control outcomes.

Not collected by default: the content of prompts or responses, file contents, or keystrokes. Customers who require content-level inspection for a specific control operate that through their own data protection tooling; QWatch records the outcome, not the content.

QComp

QComp processes the governance records customers create and upload: control definitions, framework mappings, evidence documents, assessment results, and workflow history. Evidence documents may contain whatever the customer chooses to attach; we recommend minimizing personal data in evidence.

Website

This website collects the information you provide through inquiry forms and standard server logs required to operate the service.

Boundaries

We do not use customer platform data to train models. We do not sell customer data. Access by QAISG staff is limited to support and operations purposes and is logged.

Back to Trust Center