I’m evaluating for a team
Team evaluation starts with boundaries: where quality workflows run, who can access their evidence, and which controls your organization must validate. QualityMax documents hosted, on-premises, and fully isolated deployment options in its product map.
Evaluate Sovereign in context
Section titled “Evaluate Sovereign in context”Sovereign is the QualityMax option for teams that need an in-network deployment model. It is presented as a private-preview design-partner program, so treat architecture and availability as an evaluation conversation rather than a completed public deployment recipe. The product map is the public orientation point for deployment options.
For a useful review, name the applications that must remain private, the teams that operate them, and the evidence that needs to be retained. That makes it possible to compare a hosted workflow with a Sovereign or other isolated deployment without assuming every control is identical.
Review the security model
Section titled “Review the security model”The relevant security model is operational as well as technical: identify the users, repositories, test targets, execution environment, and evidence viewers in scope. The core concepts explain where tests can run and how execution artifacts become evidence. Use those boundaries to ask who operates each component and what reviewers need to see.
The public security overview is currently only an outline, so this guide does not claim a certification, control set, or implementation detail that has not been documented publicly.
Map compliance and on-premises requirements
Section titled “Map compliance and on-premises requirements”Write down your compliance requirements before comparing deployment options: data residency, identity, auditability, retention, and network boundaries are common review inputs. An on-premises or fully isolated option may change how your team operates execution and evidence; it does not by itself prove compliance with a particular standard.
Use the product map for deployment orientation and the core concepts for test-execution and evidence questions. Validate the final architecture and controls against your organization’s requirements.
Suggested evaluation agenda
Section titled “Suggested evaluation agenda”- Map the team’s required security model and evidence viewers.
- Compare hosted, on-premises, and isolated boundaries using the product map.
- Confirm compliance requirements and deployment controls with the responsible stakeholders.