Trust Center

Security & Trust Center

A single place for security topics buyers expect. We publish verified overviews and clearly mark drafts. We do not invent certificates, subprocessors or incident procedures we do not operate yet.

Security overview

Available overview

QData Projects is an enterprise SaaS offering for security-conscious organizations. Core application controls include RBAC and authentication options. Absolute security guarantees are never made.

Infrastructure

Draft — not yet published policy

The SaaS service runs on infrastructure operated by QData. Server colocation and primary data location are available in Europe and North America — selected at onboarding. A formal infrastructure whitepaper is marked draft until published for the contracted service. We do not offer customer-hosted or on-premises installs.

Data protection

Available overview

Supports strong access control and organizational data governance requirements. You can choose Europe or North America for primary data location and colocation. Processing details for the SaaS service are documented in the DPA and customer agreement.

Authentication

Available overview

Supports password policy controls, multi-factor authentication (TOTP / WebAuthn where enabled), and enterprise SSO / directory options.

Access control

Available overview

Granular role-based permissions at project level. Membership and role design are part of onboarding.

Encryption

Available overview

Encryption in transit via TLS is standard at the edge for the SaaS HTTPS service. Encryption at rest is confirmed per contract — we do not copy third-party cloud claims by default.

Backup

Draft — not yet published policy

Backup routines exist for the operated SaaS environments; retention and restore objectives are confirmed contractually. Public RPO/RTO numbers are not invented here.

Disaster recovery

Draft — not yet published policy

DR posture is defined for the SaaS service. Documented DR statements remain draft until approved for the offered service.

Incident response

Draft — not yet published policy

Incident response contacts and playbooks will be published when operationalized. Use the security contact channel for urgent reports.

Vulnerability management

Draft — not yet published policy

Vulnerability handling follows vendor updates plus our operational patch process for the SaaS platform. Public SLA text remains draft.

Security updates

Available overview

Security updates and platform maintenance are included in SaaS operations performed by QData.

Privacy

Published

Published Privacy Policy for the Website and related communications. Workspace/application data is covered by customer agreements and the DPA. View draft

DPA

Published

Published DPA framework for QData Projects SaaS processing operated by QData. Request an executed schedule via the security contact. View draft

Subprocessors

Draft — not yet published policy

Subprocessor lists are published only for services we actually use in the SaaS offering. No placeholder vendors are named as fact.

Compliance documentation

Placeholder — no certificate claimed

No ISO/HIPAA/NIS2 certification is claimed for QData Projects on this page. If certifications are obtained, we will list issuer, scope, version and date.

Security contact

Available overview

Email security inquiries via the contact form with topic=security. For production emergencies on an operated tenant, use the channel provided in your contract.

Need a security questionnaire?

Contact us with your framework and SaaS requirements. We answer from verified controls and mark unknowns instead of over-claiming.