Everything digital leaves a trace. We collect the traces, put them on one timeline, compare them against what is happening in the world, and from that tell you two different things: something is wrong right now, or here is your proof that it is not.
01
Collection
Your systems already write down what they do: who signed in and from where, which file was opened, what the firewall let through, what changed on a server. Those records are called logs. We collect the logs — the traces of the activity — and connect to the systems read-only. A credential returned with write permission is rejected at connection time rather than retained.
02
Correlation
One record on its own means very little. The same account signing in from two countries twenty minutes apart means a great deal. Records from every source go onto a single timeline, so what they mean together becomes visible — which no single system can see, because each one only holds its own half of the story.
03
Enrichment
What is happening in your environment is then compared against what is known to be happening everywhere else: addresses being used in attacks this week, domains registered days ago, file signatures from live campaigns. That comparison is called threat intelligence. A language model reads the result and explains it in words your people can act on — running as a public service, or entirely inside your own network if you would rather nothing left it at all.
04
Triage
Not everything unusual is wrong. A backup job reads thousands of files at night; an administrator signs in from a hotel abroad. Every signal is weighed for what it would actually cost you, the ones with an ordinary explanation are set aside, and what remains reaches a person in the order it deserves. A language model assists with that ranking, so your people spend the day on the few things that matter.
05
Detection
A break-in already under way, an account taken over, malicious software running, data leaving where it should not. You are told immediately and not in tomorrow's report, because Article 23 counts from the moment you become aware and gives you twenty-four hours.
06
Measurement
The same material, read a second way. Every signal is attached to a numbered control of CIR (EU) 2024/2690 and becomes evidence: what you can prove, what you cannot, what was found and whether it was fixed. One report every morning, and a record that does not depend on anyone remembering to write it.
The whole loop, end to end.
Where the evidence comes from, what happens to it, and who acts on it. The boundary on the right is the product definition: we measure, your people change things.
Your organisation
Office 365
Google Workspace
Azure
AWS
ERP systems
On-premises network
Firewalls
Routers
Servers
Storage
Quanovio
Threat intelligence feedsOSINT databases
01
Collection
Logs only
No file contents
Read-only access
02
Correlation
One timeline
Across every source
Patterns over time
03
Enrichment
Threat intelligence
OSINT sources
AI-assisted, public or on-premises
04
Triage
Severity assigned
False positives dropped
AI-assisted ranking by impact
05
Case decision
Incident or finding
Mapped to a control
Article 23 clock starts
06
Alerting and reporting
Immediate alert
Daily compliance record
Evidence pack
Enrichment and triage are AI-assisted. The model runs either as a public service or entirely inside your own network, which needs a GPU in your environment; where we supply that capacity it is charged separately.
Your administrators
Remediation
Carried out by your own administrators
Quanovio has no write access
You decide what changes
Or handed to TEAM-Z, VDR Tech’s managed service
The next collection verifies it
We collect the traces, never the content.
This is the distinction the whole product rests on. A log records that a document was opened, by whom, from where and when. It does not contain the document. We do not read your email, open your files, or copy your customer records — and we could not produce them if asked, because we never held them. What we hold is a record of activity, which is also the only thing an assessor ever asks to see.
What Quanovio does not do.
It does not remediate, and could not. No connector holds write access, so no configuration is changed, no account is disabled and no file is moved. The changes are made by your own administrators, and Quanovio measures the result at the next collection. If you would rather not make them yourself, TEAM-Z makes them under a separate contract — never this product.
The same house · a separate serviceVDR Tech · TEAM-Z
If you would rather it were done for you.
Quanovio tells you what is wrong and proves it was fixed. Someone still has to do the fixing. Quanovio is a VDR Tech product, and TEAM-Z is another one: an AI operations team that runs IT and security work end to end, live in three countries today. Same company, different service, bought under its own contract.
01
What it takes on
Whole operations rather than isolated tasks: tickets, incidents and change on the IT side, triage and escalation on the security side. A finding Quanovio raises becomes a case with an owner, a plan and a closure date — and the next collection is what says whether it held.
02
Who signs
Nothing with consequence runs unsigned. Anything that touches a real system escalates to a person on your side, with the whole file behind it, and no credential is changed at all without your explicit authorisation. Every decision lands in a log that can be reconstructed minute by minute for an auditor.
03
Where it runs
Single tenant, no exceptions. On VDR Tech infrastructure, in your own cloud, or on your own hardware with no internet at all. Where the work runs and where the model runs are decided separately, and both are decided by you.
This changes nothing about Quanovio. The connectors stay read-only whichever you buy, the two hold separate credentials under separate contracts, and the evidence is still what the next collection observes — not a report written about its author’s own work, which is why a fix that did not hold shows up either way. TEAM-Z is scoped and priced on its own, by outcome rather than by hour.