Quanovio

PlatformFive stages

How Quanovio turns activity into evidence.

Everything digital leaves a trace. We collect the traces, put them on one timeline, compare them against what is happening in the world, and from that tell you two different things: something is wrong right now, or here is your proof that it is not.

01

Collection

Your systems already write down what they do: who signed in and from where, which file was opened, what the firewall let through, what changed on a server. Those records are called logs. We collect the logs — the traces of the activity — and connect to the systems read-only. A credential returned with write permission is rejected at connection time rather than retained.

02

Correlation

One record on its own means very little. The same account signing in from two countries twenty minutes apart means a great deal. Records from every source go onto a single timeline, so what they mean together becomes visible — which no single system can see, because each one only holds its own half of the story.

03

Enrichment

What is happening in your environment is then compared against what is known to be happening everywhere else: addresses being used in attacks this week, domains registered days ago, file signatures from live campaigns. That comparison is called threat intelligence. A language model reads the result and explains it in words your people can act on — running as a public service, or entirely inside your own network if you would rather nothing left it at all.

04

Triage

Not everything unusual is wrong. A backup job reads thousands of files at night; an administrator signs in from a hotel abroad. Every signal is weighed for what it would actually cost you, the ones with an ordinary explanation are set aside, and what remains reaches a person in the order it deserves. A language model assists with that ranking, so your people spend the day on the few things that matter.

05

Detection

A break-in already under way, an account taken over, malicious software running, data leaving where it should not. You are told immediately and not in tomorrow's report, because Article 23 counts from the moment you become aware and gives you twenty-four hours.

06

Measurement

The same material, read a second way. Every signal is attached to a numbered control of CIR (EU) 2024/2690 and becomes evidence: what you can prove, what you cannot, what was found and whether it was fixed. One report every morning, and a record that does not depend on anyone remembering to write it.

The whole loop, end to end.

Where the evidence comes from, what happens to it, and who acts on it. The boundary on the right is the product definition: we measure, your people change things.

Your organisation
Office 365
Google Workspace
Azure
AWS
ERP systems
On-premises network
Firewalls
Routers
Servers
Storage
Quanovio
Threat intelligence feeds OSINT databases
01

Collection

  • Logs only
  • No file contents
  • Read-only access
02

Correlation

  • One timeline
  • Across every source
  • Patterns over time
03

Enrichment

  • Threat intelligence
  • OSINT sources
  • AI-assisted, public or on-premises
04

Triage

  • Severity assigned
  • False positives dropped
  • AI-assisted ranking by impact
05

Case decision

  • Incident or finding
  • Mapped to a control
  • Article 23 clock starts
06

Alerting and reporting

  • Immediate alert
  • Daily compliance record
  • Evidence pack

Enrichment and triage are AI-assisted. The model runs either as a public service or entirely inside your own network, which needs a GPU in your environment; where we supply that capacity it is charged separately.

Your administrators

Remediation

  • Carried out by your own administrators
  • Quanovio has no write access
  • You decide what changes
  • Or handed to TEAM-Z, VDR Tech’s managed service

The next collection verifies it

We collect the traces, never the content.

This is the distinction the whole product rests on. A log records that a document was opened, by whom, from where and when. It does not contain the document. We do not read your email, open your files, or copy your customer records — and we could not produce them if asked, because we never held them. What we hold is a record of activity, which is also the only thing an assessor ever asks to see.

What Quanovio does not do.

It does not remediate, and could not. No connector holds write access, so no configuration is changed, no account is disabled and no file is moved. The changes are made by your own administrators, and Quanovio measures the result at the next collection. If you would rather not make them yourself, TEAM-Z makes them under a separate contract — never this product.

The same house · a separate serviceVDR Tech · TEAM-Z

If you would rather it were done for you.

Quanovio tells you what is wrong and proves it was fixed. Someone still has to do the fixing. Quanovio is a VDR Tech product, and TEAM-Z is another one: an AI operations team that runs IT and security work end to end, live in three countries today. Same company, different service, bought under its own contract.

01

What it takes on

Whole operations rather than isolated tasks: tickets, incidents and change on the IT side, triage and escalation on the security side. A finding Quanovio raises becomes a case with an owner, a plan and a closure date — and the next collection is what says whether it held.

02

Who signs

Nothing with consequence runs unsigned. Anything that touches a real system escalates to a person on your side, with the whole file behind it, and no credential is changed at all without your explicit authorisation. Every decision lands in a log that can be reconstructed minute by minute for an auditor.

03

Where it runs

Single tenant, no exceptions. On VDR Tech infrastructure, in your own cloud, or on your own hardware with no internet at all. Where the work runs and where the model runs are decided separately, and both are decided by you.

This changes nothing about Quanovio. The connectors stay read-only whichever you buy, the two hold separate credentials under separate contracts, and the evidence is still what the next collection observes — not a report written about its author’s own work, which is why a fix that did not hold shows up either way. TEAM-Z is scoped and priced on its own, by outcome rather than by hour.

Ask about remediation

What it reads

Sources are added one at a time, and each one states which numbered controls it advances. A source that advances none is not offered.

SourceStatus
Microsoft 365 and Entra ID — sign-ins, authentication methods, accounts and external sharingAvailable
Google Workspace — sign-ins, account activity and file sharingAvailable
Windows, Linux and macOS servers — file integrity, configuration, inventory and vulnerabilitiesAvailable
Workstations and laptops — the same checks, on the machines people actually useAvailable
Firewalls and network equipment — Fortinet, Palo Alto, Cisco, Sophos, SonicWall, pfSense, MikroTikAvailable
Cloud platforms — Amazon Web Services, Microsoft Azure and Google CloudAvailable
Identity providers — Okta, Entra ID and other single sign-on servicesAvailable
Endpoint protection — Microsoft Defender, CrowdStrike, SentinelOneAvailable
Virtualisation and backup — VMware, Hyper-V and VeeamAvailable
Container platforms — Kubernetes and DockerAvailable
Code and change history — GitHub and GitLabAvailable
Anything that already sends logs — Splunk, Elastic, Graylog, or plain syslogAvailable

Which of these you actually need depends on what you run.

Describe your environment and you will receive a written statement of the controls it would evidence, and the ones it would not.

See your coverage