Operator access

Enter the evidence workspace.

The public product site and the security console have separate trust boundaries. A protected synthetic-only engineering PoC is available now. Access is restricted to explicitly approved Google accounts.

Authentication happens only on the separate console origin.

Protected workflow

A separate operator door. No public-site credential handling.

The access surface is deliberately small: Google proves the account identity, and Q² Assure independently checks the exact test-user allowlist.

  1. 01

    Authenticate

    Continue to Google, select an approved account, and return to a protected Assure session.

  2. 02

    Authorize source

    Register only approved repositories and preserve an immutable snapshot before analysis begins.

  3. 03

    Review evidence

    Track scan coverage, replay citations, inspect validation lineage, and record human decisions.

Current boundary

The demonstration is public. The workspace is not.

No scanner API, source snapshot, findings database, session key, Google client secret, or operator credential is deployed with this public site. Those components run on a separate Google-restricted engineering host and remain isolated from the marketing origin.

Access boundary reviewed 13 August 2026