
SandboxAQ typical implementation process:
Initial assessment and requirements gathering: SandboxAQ experts consult with the enterprise team to understand scientific, technical, and security objectives, determine data sources, and design a scalable architecture to meet project needs.
Cloud environment setup: SandboxAQ software is deployed on a secure cloud, typically leveraging Google Cloud infrastructure, with self-service virtual machines preconfigured for scientific computing and AI workflows.
Data integration and security configuration: Data is ingested, permissions and access management (IAM) are established, and sensitive data sources are securely unified for ease of management and compliance.
Tool deployment and workflow customization: Models, simulation engines, and AI/ML pipelines are provisioned according to requirements—options include ready-to-run containers, cloud-native batch scheduling, and custom plugin integrations.
Development and test cycles: Teams develop, test, and validate workloads using standardized environments and tools like JupyterLab, GitHub, and internal batch or containerized services, iterating until optimal configurations are reached.
Production scale-up: Finalized workflows are launched at full scale, frequently running massive parallelized jobs across distributed global resources with monitoring and logging tools for transparency.
SandboxAQ can be highly customized to fit specific business needs across various industries, offering configurable modules, scalable infrastructure, and integration capabilities tailored for enterprise environments. The platform’s Large Quantitative Models (LQMs) are engineered to be domain-specific, supporting custom solutions in finance, life sciences, cybersecurity, industrial optimization, and more.
Configurable Modules: SandboxAQ offers dedicated modules (e.g., AQtive Guard) for inventory discovery, automated remediation, and compliance management, all of which can be adapted to meet enterprise security policies and regulatory requirements.
Integration and API Support: The platform supports deployment within existing IT ecosystems via enterprise APIs, compatible with major cloud providers like AWS and Google Cloud, allowing seamless integration with current business operations and data workflows.
Scalable Computing: Workflows and model training can be scaled on demand, which lets organizations tailor computational resources to their unique requirements, whether running millions of molecular simulations or optimizing industrial supply chains.
Industry-Specific Solutions: LQMs are built for real-world use cases with flexibility in scientific domains (physics, chemistry, biology, economics), ensuring that organizations can customize models and data pipelines for their particular challenges—such as drug discovery, financial risk modeling, or navigation in GPS-denied environments.
Compliance Customization: Systems can be configured to meet stringent industry compliance mandates, including NIST and OMB standards, with policy management tailored for each customer’s regulatory environment.
Data Security Granularity: User roles, permissions, and access protocols are customizable via IAM controls, supporting granular security practices for sensitive or regulated data.
Continuous Learning and Updates: SandboxAQ’s models and modules support continuous learning, allowing enterprises to incorporate new data, update algorithms, and tweak outputs to stay aligned with emerging business goals.
Pharmaceutical companies can collaborate with SandboxAQ to customize drug discovery engines, parameterizing molecular simulations to their proprietary targets, with secure, cloud-based data management.
Financial firms utilize custom LQMs for specific risk analysis applications, integrating with their internal infrastructure for real-time modeling and optimization.
SandboxAQ offers a range of training and support resources for new users, focusing on onboarding, technical assistance, and ongoing education to ensure effective adoption and use across enterprise environments.
Onboarding Assistance: New users receive support during the onboarding process, including provisioning equipment, creating user accounts, and guiding setup for both hardware and software environments.
Technical Engagement: Technical Engagement Managers and delivery leaders oversee client onboarding, helping organizations integrate SandboxAQ’s solutions into their workflows.
SandboxAQ Academy: The company supports educational initiatives through SandboxAQ Academy, which provides resources, seminars, hands-on training, and workshops in AI and quantum technologies for corporate teams and academic partners.
Industry Collaborations: SandboxAQ collaborates with universities, global system integrators (such as EY and Deloitte), and industry partners to deliver custom upskilling programs, seminars, and residency programs, extending practical experience to business and technical users.
Webcasts and Publications: Regular online seminars, webcasts, and a publications library are available to help teams stay updated on platform advancements and best practices.
Dedicated Enterprise Support: The platform offers comprehensive customer service channels, including technical support, compliance guidance, and generative AI assistants to resolve issues, ensure successful deployments, and answer ongoing technical or regulatory questions.
Resource Access: Users have access to knowledge bases, IT support contacts (including email and phone), and direct communication channels for both troubleshooting and continuous improvement.
SandboxAQ implements a suite of advanced security measures to protect user and organizational data, reflecting both current and future cybersecurity threats—including those posed by quantum computing, AI-driven attacks, and the proliferation of machine identities.
Post-Quantum Cryptography: SandboxAQ has developed and contributed to NIST-approved post-quantum encryption algorithms such as HQC (Hamming Quasi-Cyclic) and SPHINCS+, which are specifically engineered to resist decryption attempts from quantum computers.
AQtive Guard Platform: This is a unified, enterprise-ready cryptography management solution that covers:
Continuous inventory and monitoring of cryptographic assets and non-human identities (NHIs), such as API keys and machine credentials.
Automated detection and remediation of cryptographic vulnerabilities, such as weak/expiring certificates or outdated algorithms.
Governance workflows for credential management, ensuring consistent policy enforcement (e.g., certificate rotation and renewal).
Zero Trust Architecture: SandboxAQ’s solutions enforce Zero Trust parameters—including continuous monitoring, strict policy compliance, robust encryption throughout the data lifecycle, and granular user/device trust management.
AI-Driven Threat Detection: The platform uses AI-powered risk analysis to continuously detect, prioritize, and mitigate vulnerabilities in real time, providing visibility and automated protection across cloud and hybrid environments.
Integration with Enterprise Security Tools: SandboxAQ integrates with security leaders such as CrowdStrike, Palo Alto Networks, and ServiceNow, allowing organizations to leverage external threat intelligence, event monitoring, and best-practice compliance automation.
NIST and OMB Alignment: All cryptographic processes are designed to comply with leading standards, including NIST’s post-quantum cryptography mandates and the U.S. government’s OMB, NSM-10, and Quantum Computing Cybersecurity Preparedness Act requirements.
Sector-Specific Protections: SandboxAQ’s solutions are actively used by high-security sectors (U.S. Department of Defense, Department of Health & Human Services, Aramco, Vodafone) and are designed to satisfy stringent compliance mandates in financial services, health care, and critical infrastructure.
Automated Remediation: Real-time orchestration of remedial actions (such as instant credential replacement) to prevent service downtime and data breach risks.
Credential and Key Lifecycle Management: End-to-end management for digital certificates, cryptographic keys, and secrets, reducing manual overhead and limiting credential-based attack surfaces.
Robust Audit and Observability: Deep observability and reporting enable compliance tracking, forensics, and last-mile protection for both human and machine identities.
SandboxAQ releases updates frequently, typically aligning new features, datasets, and platform capabilities with both customer needs and emerging technological advancements. Updates may include new AI datasets, cryptographic protocols, platform modules, and vulnerability fixes, with recent releases publicized in press rooms and technical blogs.
Updates and major product or dataset launches occur multiple times each quarter, evidenced by press announcements and scientific collaborations (e.g., the SAIR dataset in June 2025, AQCat25 dataset in September 2025, and new AQtive Guard security modules at major industry events).
Platform enhancements (software, documentation, cloud services, and security modules) are rolled out on an agile schedule, often concurrent with scientific or security breakthroughs, industry requirements, or compliance mandates.
Cloud-Native Deployment: All SandboxAQ software and code updates are managed through its centralized, cloud-based infrastructure (primarily Google Cloud), where code and data reside in version-controlled repositories.
Automated DevOps Pipeline: Once code is reviewed and merged into the company’s main repository, updates become immediately available for batch execution—ensuring that enhancements, bug fixes, and security patches are distributed throughout the platform ecosystem without delay.
Self-Service Development: SandboxAQ provides standardized, centrally maintained environments for scientists and developers, allowing them to access new versions instantly using tools like SSH, browser-based VNC, or JupyterLab.
Package and Dependency Management: Updates to models, tools, and dependencies are streamlined using a globally resolved transitive dependency tree, allowing seamless integration and quick deployment of new features across heterogeneous resources.
SandboxAQ recognizes user and organizational rights regarding data ownership and provides mechanisms for data portability and control, aligning with modern enterprise SaaS practices and global privacy regulations.
User/Enterprise Data Control: Enterprises remain owners of their proprietary and sensitive data. SandboxAQ acts as a data controller only in contexts that require operational processing (such as user accounts, usage analytics, and SaaS feature management), but does not claim ownership over customer intellectual property or scientific results generated on the platform.
Data Usage: Data provided to SandboxAQ—whether for platform usage, scientific modeling, or integrations—is only processed for the purposes defined in contractual agreements and privacy policies. There is no indication that SandboxAQ sells or inappropriately reuses customer data.
Transparency and Consent: Customers are informed of their rights regarding the sharing, processing, and use of their data. Explicit user consent is required for data that may be used outside the core service offering, and organizations can contact SandboxAQ to limit sharing or request removal of personal information.
Export and Portability Rights: Organizations typically retain full control over their cryptographic, operational, and scientific datasets within SandboxAQ’s platform. Solutions acquired by SandboxAQ, such as Cryptosense, maintain "clear policies to ensure that organizations retain control over their cryptographic data and have the flexibility to move it if needed".
API/Data Export: SandboxAQ platforms are designed with integration and interoperability in mind, enabling data exports via secure API endpoints and facilitating migration or transfer of data for business continuity, audit, or compliance needs.
SandboxAQ offers flexible, cloud-native scalability for organizations, allowing customers to scale resources up or down to meet changing scientific, business, or operational needs—often without infrastructure limits or friction.
Rapid Resource Expansion: Organizations can quickly increase computational throughput, launching jobs on tens of thousands of cloud-based virtual machines in parallel for intensive projects such as drug discovery, financial modeling, or cybersecurity analysis.
Self-Service Provisioning: Users and teams have access to self-service VMs with alternate configurations (CPU, GPU, memory), enabling low-friction testing, development, and large-scale deployment. There is no need for manual quota increase requests—resources are provided on demand.
Integration with Existing Investments: SandboxAQ supports managed services for long-term projects, leveraging customer cloud investments (Google Cloud, AWS, etc.) to ensure smooth scaling within preferred or multi-cloud environments.
Flexible Licensing/Contracting: Modular solutions (like AQtive Guard, LQMs) are designed for flexible use, adjusted to the size and scope of customer teams and workloads.
On-Demand Reduction: Organizations can reduce their utilization at any time, scaling down the number or type of resources, or archiving datasets or jobs as needed.
No Major Infrastructure Commitment: Since development, batch computation, and production are cloud-native and provided as SaaS, customers are not tied to fixed infrastructure investments or long-term hardware contracts.
Integrated Cost Management: Because pricing adapts to actual resource usage (on-demand, spot VMs, data volumes), organizations manage costs dynamically by reducing operational scale when projects finish or business needs change.
Agile Workflows: Teams can move rapidly from experimentation to production and back, launching jobs of varied size at will.
SandboxAQ's terms and conditions include several key points on contract renewal and cancellation, but do not provide a standardized, explicit renewal/cancellation section typical of SaaS products. Below are the most relevant data points and contractual patterns found in their published terms.
Right to Modify Terms: SandboxAQ may update or change the terms and conditions at any time, with the user's continued access or use constituting consent to the modified terms. Customers are responsible for reviewing the terms regularly for updates.
Termination of Access: SandboxAQ may terminate or suspend access to services in accordance with these terms, particularly if there is a breach or violation of usage policies, intellectual property restrictions, or applicable laws.
No Obligated Renewal: Continued access and use are subject to compliance; there is no indication of automatic renewal—renewal may depend on new agreements or the updated terms at the time of renewal.
Cancellation by User: If the user does not agree to the new or existing terms at any point, the terms explicitly state that use must cease immediately, effectively serving as the customer's right to cancel.
Liability and Indemnity: Customers are responsible for any claims and must indemnify SandboxAQ for breaches or misuse. Use of the service is at the sole risk of the user.
Service Licensing: Access is provided under limited, revocable, and non-exclusive license conditions. There are no guarantees of ongoing availability or perpetual renewal rights.
No explicit details on notice periods or refund/cancellation fees are stated in public terms.
SandboxAQ software meets a broad array of high-level compliance standards centered on cryptography, information security, and regulatory requirements for enterprises, the public sector, and healthcare organizations.
NIST Post-Quantum Cryptography (PQC): SandboxAQ is a direct contributor to NIST’s PQC process, with its own HQC and SPHINCS+ algorithms standardized for quantum-resistant security. The platform is aligned with NIST FIPS publications, ensuring that cryptographic infrastructure satisfies rigorous government and civilian protection mandates.
OMB and NSM-10: Compliance includes mandates from the US Office of Management and Budget (OMB) and National Security Memorandum 10, which require federal agencies and contractors to inventory, migrate, and implement quantum-resistant encryption in preparation for quantum computing risks.
Quantum Computing Cybersecurity Preparedness Act: The software is compliant with recent regulations that ensure organizations adopt quantum-safe cryptography and document migration plans for critical infrastructure.
Healthcare Data Protection: SandboxAQ can be deployed in environments subject to healthcare regulations for cryptographic enforcement and data privacy, assisting organizations with compliance for patient data integrity and confidentiality.
Automated Remediation & Policy Management: The platform supports automated enforcement of credential rotation, certificate renewal, and cryptographic lifecycle management policies to maintain compliance—especially with evolving standards and regulatory upgrades.
RNP 2 and Navigation Standards: In certain geospatial and navigation deployments, SandboxAQ achieves compliance with RNP 2 navigation standards for critical systems operating in GNSS-deprived environments.