Operator access
Enter the evidence workspace.
The public product site and the security console have separate trust boundaries. A protected synthetic-only engineering PoC is available now. Access is restricted to explicitly approved Google accounts.
Authentication happens only on the separate console origin.Protected workflow
A separate operator door. No public-site credential handling.
The access surface is deliberately small: Google proves the account identity, and Q² Assure independently checks the exact test-user allowlist.
-
01
Authenticate
Continue to Google, select an approved account, and return to a protected Assure session.
-
02
Authorize source
Register only approved repositories and preserve an immutable snapshot before analysis begins.
-
03
Review evidence
Track scan coverage, replay citations, inspect validation lineage, and record human decisions.
Current boundary
The demonstration is public. The workspace is not.
No scanner API, source snapshot, findings database, session key, Google client secret, or operator credential is deployed with this public site. Those components run on a separate Google-restricted engineering host and remain isolated from the marketing origin.
Access boundary reviewed 13 August 2026