Connect

SECURITY & DATA HANDLING

First check whether it can run on your internal network and where your data resides.

How hyperQ products are installed differs from product to product. Scribe is an on-premises deployment installed on internal and institutional networks, while AX ONE, Entitle, VAI Ops, and OnDesk run on their own service domains. This site itself has no database and forwards inquiries to the responsible mailbox.

Deployment

The deployment model differs by product.

They are split into on-premises builds, service-based products, and package builds. Start by checking which product runs on which network.

On-premises build

Scribe — Installed on internal and institutional networks

Operates document AI as an on-premises deployment inside air-gapped and institutional networks, turning in-house data into documents, reports, and official letters.

Service-based

Entitle — entitle.hyperq.run

Handles product license issuance and renewal, and controls user and organization permissions. Offline activation is provided for air-gapped networks.

Service-based

OnDesk — ondesk.hyperq.run

It runs remote support for on-site and customer PCs and maintenance for installed products, with permission and session control linked to Entitle.

Service-based

AX ONE · VAI Ops — Their own service domains

AX ONE runs on axone.run and VAI Ops on vaiops.hyperq.run. The deployment checklist covers the operations data sources to connect and the site environment where the models will be deployed.

Package build

Robision · PCB Inspector · AI Safety

These are implemented on site as AI Vision Factory, PCB Quality Pack, and Safety Compliance Pack configurations, respectively.

Packages

On-Prem AI Office

A package defined for public sector, finance, and internal-network organizations where security policy makes public AI services hard to use. Scribe, Entitle, and OnDesk make up the document AI and the permissions and support structure, and the free document tool Worx is in preparation for release.

Technical details of product-side security specifications (encryption methods, audit log retention periods, SSO·RBAC standards, and the like) are not covered on this page.

This Site

This site has no database.

The following applies only to the hyperq.run website and is separate from product security specifications. Entries from inquiry and application forms pass through the intake function (Cloudflare Pages Functions) and are delivered to the team inbox via the company mail account (Microsoft 365).

No storage

Email delivery only, no server storage

The intake function only sends the email and stores nothing, and the site has no database. As a rule, received emails are kept in the team inbox for the period necessary to fulfill the purpose and then destroyed.

Delivery path

office@ → [email protected]

Mail is sent using Microsoft 365 Graph app-only authentication, and no user password is involved. Sent messages are not kept in the Sent Items folder.

If delivery fails

Mail composer opens if the intake function is unavailable

If the server returns an error, a mail compose window opens on the visitor's device, and the inquiry is submitted only when the visitor sends it themselves. Unsent content does not accumulate on the server.

Controls

Intake-stage validation and delivery configuration are set in code and deployment settings.

These are the items checked when a form is submitted, and the security headers applied to every path.

Required consent

Consent to personal data collection is a required field

All five forms use a required consent checkbox with a link to the privacy notice, and if the consent value is missing, the intake function rejects the request.

Input validation

Only permitted form types and valid email formats are accepted

The intake function checks the form type and the email format. Input values are truncated to 4000 characters per field, and HTML special characters are escaped before they go into the message body.

Transport security

Security headers on every route

The headers below are applied to every path.

  • X-Content-Type-Options: nosniff
  • Referrer-Policy: strict-origin-when-cross-origin
  • Permissions-Policy: camera=(), microphone=(), geolocation=()
  • X-Frame-Options: SAMEORIGIN
Deployment

Static deployment · No servers of our own

The site runs as a static deployment on Cloudflare Pages, with domain connection and SSL handled by Cloudflare DNS.

Customer Confidentiality

Customer information never goes into public materials.

How we handle public cases and performance figures is codified as a rule and checked by e2e tests.

Case disclosure

Inspection screens blurred · Customer undisclosed

Inspection screens in public cases are blurred to protect customer confidentiality and show only the detection results. Customer information is not disclosed.

Automatic blocking

Leak checks on public build output

If a customer name, internal financials, or actual unit prices end up in a public build output (HTML) or a content data file, the test fails. Once a check is added, it is not removed.

Stating figures

Sources and conditions stated together

Public performance figures are published with their source (company performance records, 2026) and a caption stating the conditions. Customer names and prices are not included.

Before You Deploy

If you have these items ready before the consultation, the review moves faster.

These questions are drawn from the deployment checklists for each product and package. Even if you have no fixed answer, simply telling us the current state is enough.

Network environment

Which must it run on: an internal network, an air-gapped network, or a network-separated environment?

If your network is air-gapped, we also check whether offline activation is needed. This is a Scribe·Entitle deployment checklist item.

Document assets

Which document type is most common - HWPX, DOCX, or PDF?

Please tell us your main document forms and where the data resides. We also check whether document permissions, audit logs, and remote support are needed.

Operational data

Which operational data sources (MES, ERP, etc.) will be connected?

We also confirm the scope of sites and systems you want to connect. This is an AX ONE deployment checklist item.

Training data

What data do you hold, and what is its labeling status?

We also check the site environment where the model will be deployed. This is a VAI Ops deployment checklist item.

External access

How much external access does your network policy allow?

We also check the number of PCs and devices to be supported. This is an OnDesk deployment checklist item.

Site data

Where is CCTV, wearable, and sensor data stored?

We also check whether you need per-site permission and evidence-retention policies. This is a Safety Compliance Pack consultation question.

Public sector and government deployments are often reviewed jointly by IT, document and records, and security managers. Our consultation page also asks about deployment constraints such as internal networks, on-premises installation, and access permissions early on.

Terms & Contact

The governing law is that of the Republic of Korea, and there is a single point of contact.

The governing law and authoritative language of the Terms of Use, the usage restrictions, and where to send access, correction, and deletion requests.

Governing law

Laws of the Republic of Korea · Korean version authoritative

The Terms of Use are interpreted in accordance with the laws of the Republic of Korea, and disputes are subject to the courts having jurisdiction under applicable laws. The Korean version of the Terms of Use is the authoritative version; the English and Chinese translations are for reference only.

Export controls

Compliance with export control laws

The license prohibits the export or transfer of the software in violation of applicable export control laws, including those of the Republic of Korea and the United States.

Usage restrictions

No crawling · copying · reverse engineering

Automated crawling and bulk collection, content reproduction and republication, reverse engineering, and attempts to circumvent security are prohibited.

Contact

[email protected]

Send access, correction, and deletion requests to this address and we will process them. The privacy notice was last updated on 2026-07-23.

Security requirements not covered on this page can be confirmed directly in a consultation.

Next Step

Network conditions and data handling standards are confirmed in the consultation.