Qualense
PlatformFor ConsultantsPricingROI CalculatorContact

Customer Notices

Qualense Privacy PolicyQualense Terms of ServiceAI Data Handling and Subprocessor DisclosureCUI Handling and Prohibited-Data NoticeSecurity Controls and Data Protection Statement

Sections

Clear notice1. Customer classification responsibility2. Prohibited data3. Permitted onboarding and demo material4. What happens when Qualense detects a concern5. Accidental upload procedure6. No transfer of responsibilityAuthoritative references
gavelQUALENSE LLC · CUSTOMER NOTICE

CUI Handling and Prohibited-Data Notice

Qualense does not currently accept CUI

Clear notice

Qualense is not currently authorized, configured, or offered as a system for storing or processing Controlled Unclassified Information (CUI). Do not upload CUI to Qualense.

Qualense is also not a classified system, a FedRAMP-authorized service, a FIPS-validated cryptographic module, a C3PAO, or a substitute for a customer's approved information system and handling procedures.

1. Customer classification responsibility

The customer—not Qualense—is responsible for determining whether information is CUI or otherwise restricted and for following the governing contract, regulation, agency guidance, security classification guide, CUI Registry category, distribution statement, and organizational policy.

Automated screening looks for known markings and patterns but cannot reliably determine legal status or catch every restricted item. The absence of a warning does not mean content is safe to upload.

Removing, cropping, obscuring, or failing to include a CUI marking does not decontrol the underlying information. Do not re-upload content merely because its marking was removed. Upload is permitted only if an authorized owner has determined and documented that the information is not CUI or has been properly decontrolled or sanitized for use in Qualense.

2. Prohibited data

Unless Qualense gives explicit written authorization in a signed agreement after confirming appropriate technical and contractual safeguards, do not submit:

  • classified information at any level;
  • CUI, covered defense information, controlled technical information, or data subject to DFARS 252.204-7012 handling requirements;
  • export-controlled or sanctions-restricted information, including ITAR-controlled technical data;
  • government, customer, or third-party information that the uploader lacks authority to disclose;
  • passwords, API keys, private keys, tokens, connection strings, recovery codes, or other authentication secrets;
  • payment-card numbers or card-verification data;
  • protected health information, medical records, biometric identifiers, highly sensitive financial data, or government identity numbers;
  • children's personal information;
  • source material subject to legal privilege or special secrecy obligations unless the customer has approved the risk in writing;
  • malware, exploit code intended to cause harm, or files designed to evade security controls; or
  • data whose contract, law, or policy requires a hosting authorization, residency, encryption validation, or security certification Qualense has not documented.

Qualense may identify additional prohibited categories in an Order Form or workspace notice.

3. Permitted onboarding and demo material

Before the customer-data release gates are closed, onboarding and demo uploads must be synthetic. If Qualense later authorizes limited real customer data, it must be non-CUI, lawfully collected, minimized, and approved in the signed Order Form. Native-text files are required under the current service boundary; images and scanned/image-only PDFs are technically blocked and remain unsupported.

4. What happens when Qualense detects a concern

Qualense may stop processing, quarantine or restrict access to a file, notify authorized contacts, preserve limited security evidence, and delete the affected object where supported. Detection does not mean Qualense has classified the information.

Current behavior: images and scanned/image-only PDFs are quarantined and their stored upload is deleted before external OCR or other external AI processing. Substantial native-text PDFs follow the local text path before content screening. This is a fail-safe format gate, not proof that permitted files are free of CUI or secrets; images and scanned/image-only PDFs remain unsupported for customer evidence.

5. Accidental upload procedure

If prohibited data may have been uploaded:

  1. Stop accessing, downloading, sharing, or re-uploading the material.
  2. Preserve the upload time, workspace, engagement, file name, and uploader identity without copying the restricted content into email or a ticket.
  3. Notify deeppractise@gmail.com and the customer's security/contacting officer immediately using an approved channel.
  4. Follow the customer's incident-response, legal, contracting, export-control, and government-reporting procedures. Qualense does not make those reporting decisions for the customer.
  5. Interface deletion of an evidence item removes that evidence object's stored versions and redacts its content-bearing application records, but it does not prove erasure from backups, generated exports, providers, or unrelated records; request a confirmed scope review from Qualense.

Qualense will investigate the storage path, access and audit records, external-provider calls, deletion status, and contractual notification requirements. It will coordinate only with authorized customer contacts and advisers.

6. No transfer of responsibility

Screening, quarantine, warnings, and support do not transfer custody, classification, safeguarding, reporting, or contractual responsibility from the customer. Customer administrators must train users and limit uploads to approved material.

Authoritative references

  • National Archives: Controlled Unclassified Information
  • DFARS 252.204-7012
Qualense wolf markQualense

Evidence organization, human review, assessment support, and working deliverables for NIST SP 800-171 self-assessment workflows.

deeppractise@gmail.com
ProductPlatformPricingROI CalculatorRequest a walkthrough
CompanyFor ConsultantsContact
LegalTerms of ServicePrivacyAI Data HandlingCUI NoticeSecurity

Qualense supports assessment preparation and self-assessment defensibility. It does not issue certifications and is not affiliated with DoD or the Cyber AB.

© 2026 Qualense LLC