
Quality and security
How we look after the quality of our work and the information entrusted to us.
Quality and Information Security Policy
At CUANTICO, we are committed to accelerating digital transformation, driving the adoption of emerging technologies and innovation models that modernize the management of organizations.
Our quality management is based on excellence and on the trust of our stakeholders, ensuring that every solution we develop is secure, scalable, and sustainable, with a global impact.
Our information security management aims to protect information assets and preserve their confidentiality, integrity, and availability. To do so, we manage information security risks, strengthen cybersecurity, and safeguard personal information, contributing to business continuity in the face of adverse events and incidents.
We rely on competent personnel, trusted contractors and providers, and a permanent support structure that guarantees customer satisfaction, compliance with their requirements, and adherence to applicable legal regulations.
Scope of our management systems
At CUANTICO we work under a management approach focused on quality, continuous improvement, and the protection of information, backed by international standards.
Our management systems:
- ISO 9001:2015 – Quality Management: the Quality Management System of CUANTICO CORPORATION S.A.S. aims to ensure the quality and continuous improvement of our development, support, and operation services for digital platforms, as well as our consulting and virtual training activities.
- ISO/IEC 27001:2022 – Information Security: Our Information Security Management System establishes a framework to manage information-related risks and strengthen its confidentiality, integrity, and availability in the services and processes within its scope.
Integrated Management System objectives
Customer Satisfaction
Meet our customers' expectations by measuring and analyzing their needs.
Continuous Improvement
Continuously improve the organization's processes and results through good quality practices, in order to optimize resources and improve productivity through process standardization.
Financial Sustainability
Ensure the organization's solvency and profitability to meet its financial obligations and shareholders' expectations.
Regulatory Compliance
Ensure compliance with the legal and regulatory requirements applicable to the organization by strengthening and applying the Integrated Management System.
Human Talent Development
Develop and train our team to have competent personnel, fostering a participatory work environment focused on quality, information security, cybersecurity, and personal data protection.
Risk Management
Foster a risk management culture and model, implementing proactive controls that mitigate the impact of adverse scenarios.
Certifications
The quality management system of CUANTICO CORPORATION S.A.S., at its Bogotá site, is certified to ISO 9001:2015 by ICONTEC for: Development, support and operation services for digital platforms: Record traceability; digital procedures; data observatory and artificial intelligence models. Consulting in: Public ICT management; digital innovation practices and E-government. Implementation and operation of Learning Management Systems (LMS). The certification does not cover CUANTICO AI LLC (Florida).
ISO/IEC 27001 certification and SOC 2 Type I audit: in progress.
Certificate details:
- Holder: CUANTICO CORPORATION S.A.S.
- Certified site: Calle 93A No. 13-24, piso 5, Bogotá D.C., Colombia
- Certification body: ICONTEC (IQNet member, accredited by ONAC and IAF)
- Certificate number: SC-2002300
- Date of grant: June 18, 2025
- Current cycle: June 18, 2025 to June 17, 2028
- Latest certificate revision: July 11, 2025
Security of our platforms
MinTrace, CUANTICO's mineral traceability platform, is a good example of how we protect the information entrusted to us.
In MinTrace:
- The platform runs on Amazon Web Services and each organization’s data is isolated.
- Information is encrypted in transit (TLS 1.2 or higher) and at rest.
- Access uses two-factor authentication and single sign-on with OAuth 2.0, with roles and segregation of duties.
- The audit log is write-only: not even administrators can alter it.
- Vulnerability management is aligned with ISO/IEC 27001:2022.
Guardian watches our own infrastructure
Guardian, our AI agent-based security operations center, is a research initiative that protects MinTrace’s infrastructure 24/7 today.
Personal data
We process personal data under our personal data processing policy (POL-LCO-01, version 3 of August 31, 2026).
To access, update, correct or delete your data, or to submit a request or a complaint, write to our Personal Data Protection Officer at info@cuantico.com.
Laws that govern personal data processing in our markets:
- Colombia: Law 1581 of 2012
- Brazil: General Data Protection Law (LGPD), Law 13,709 of 2018
