Security overview
Available overviewQData Projects is an enterprise SaaS offering for security-conscious organizations. Core application controls include RBAC and authentication options. Absolute security guarantees are never made.
A single place for security topics buyers expect. We publish verified overviews and clearly mark drafts. We do not invent certificates, subprocessors or incident procedures we do not operate yet.
QData Projects is an enterprise SaaS offering for security-conscious organizations. Core application controls include RBAC and authentication options. Absolute security guarantees are never made.
The SaaS service runs on infrastructure operated by QData. Server colocation and primary data location are available in Europe and North America — selected at onboarding. A formal infrastructure whitepaper is marked draft until published for the contracted service. We do not offer customer-hosted or on-premises installs.
Supports strong access control and organizational data governance requirements. You can choose Europe or North America for primary data location and colocation. Processing details for the SaaS service are documented in the DPA and customer agreement.
Supports password policy controls, multi-factor authentication (TOTP / WebAuthn where enabled), and enterprise SSO / directory options.
Granular role-based permissions at project level. Membership and role design are part of onboarding.
Encryption in transit via TLS is standard at the edge for the SaaS HTTPS service. Encryption at rest is confirmed per contract — we do not copy third-party cloud claims by default.
Backup routines exist for the operated SaaS environments; retention and restore objectives are confirmed contractually. Public RPO/RTO numbers are not invented here.
DR posture is defined for the SaaS service. Documented DR statements remain draft until approved for the offered service.
Incident response contacts and playbooks will be published when operationalized. Use the security contact channel for urgent reports.
Vulnerability handling follows vendor updates plus our operational patch process for the SaaS platform. Public SLA text remains draft.
Security updates and platform maintenance are included in SaaS operations performed by QData.
Published Privacy Policy for the Website and related communications. Workspace/application data is covered by customer agreements and the DPA. View draft
Published DPA framework for QData Projects SaaS processing operated by QData. Request an executed schedule via the security contact. View draft
Subprocessor lists are published only for services we actually use in the SaaS offering. No placeholder vendors are named as fact.
No ISO/HIPAA/NIS2 certification is claimed for QData Projects on this page. If certifications are obtained, we will list issuer, scope, version and date.
Email security inquiries via the contact form with topic=security. For production emergencies on an operated tenant, use the channel provided in your contract.
Contact us with your framework and SaaS requirements. We answer from verified controls and mark unknowns instead of over-claiming.