Trust Center

Security & Trust Center

Public interface to our Security Assurance program for QData Projects. We publish verified controls, mark items in progress and do not invent certificates, subprocessors or procedures we do not operate.

Service scope

Scope: QData Projects SaaS platform, application, operational processes and infrastructure used to deliver the service.

Product
QData Projects
Deployment
QData-operated SaaS
Customer hosting
Not available
Data residency
EU / North America (customer-selectable)
Infrastructure
Qualified third-party infrastructure (provider not named publicly)
Security responsibility
Shared responsibility model

Current posture

High-level assurance status for QData Projects. Detailed controls and evidence are listed below.

Control areaAssurance status
Application securityOperational
Identity & accessOperational
EncryptionOperational
Data protectionOperational
Infrastructure documentationIn implementation
BackupDocumented
Disaster recoveryIn implementation
Incident responseIn implementation
Vulnerability managementOperational
Privacy / GDPRDocumented

Security at a glance

HostingEU / North America
Data residencyCustomer-selectable
Encryption in transitTLS (HTTPS)
AuthenticationPassword + MFA + WebAuthn / SSO
Access controlRBAC
Tenant isolationImplemented
BackupsOperational (details contractually)
Incident responseOperational contact; public playbook in progress
Security updatesContinuous
Security contactAvailable

Infrastructure & shared responsibility

QData Projects is operated by QData on qualified third-party infrastructure selected and managed under our vendor risk requirements. Physical and data-center controls are provided by infrastructure partners. QData remains responsible for application security, platform configuration, access controls and service-level controls within our scope.

Infrastructure assurance is supported by independent certifications and assessments maintained by applicable infrastructure providers. Provider identity and certification scope are available under NDA for enterprise reviews.

AreaResponsibility
Physical securityInherited / provider
Data-center controlsInherited / provider
Network infrastructureShared
Host infrastructureShared
Application securityQData
Identity & access managementQData
Tenant isolationQData
Data governanceQData
Incident responseShared
BackupShared
Disaster recoveryShared

Data ownership & protection

Who owns the data?
Customer
Where is data stored?
Selected region (Europe or North America)
Who can access it?
Authorized users and controlled QData operators
How is it protected?
Encryption in transit, access controls and contractual safeguards
How long is it retained?
Per contract and applicable policy
What happens after termination?
Defined deletion / export procedure in agreement
Can QData use customer data?
Defined in DPA and customer agreement — not for unrelated purposes

Data residency

Primary data location and colocation are selected at onboarding.

Europe

Primary data location

Available

North America

Primary data location

Available

View data processing details

Security controls

Control-level view for security reviews. Evidence availability is indicated per control.

Identity & access

Authentication

Operational

Password policy controls plus enterprise authentication options for the SaaS workspace.

ISO 27001NIST CSFCIS Controls
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security

Multi-factor authentication

Operational

TOTP and WebAuthn where enabled for workspace accounts.

ISO 27001NIST CSFCIS Controls
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security

SSO / directory

Operational

Enterprise SSO and directory integration options (Enterprise capability).

ISO 27001NIST CSF
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security

RBAC

Operational

Granular role-based permissions at project level.

ISO 27001NIST CSFCIS Controls
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security

Privileged access

Documented

Controlled operator access for SaaS operations; detailed policy available on request.

ISO 27001NIST CSF
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Security

Application security

Secure development

In implementation

Secure SDLC practices for platform changes; formal public policy in progress.

ISO 27001NIST CSF
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Engineering

Dependency management

Operational

Tracking and patching of platform and application dependencies.

NIST CSFCIS Controls
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Engineering

Vulnerability management

Operational

Vendor updates plus operational patch process for the SaaS platform.

ISO 27001NIST CSFCIS Controls
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security

Security testing

In implementation

Security testing program; public summary available on request when published.

ISO 27001NIST CSF
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Security

Patch management

Operational

Security fixes and platform maintenance included in SaaS operations.

ISO 27001CIS Controls
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Operations

Infrastructure

Network security

Documented

Edge TLS and network controls; shared with infrastructure partners.

ISO 27001NIST CSF
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Operations

Host security

Documented

Host-level hardening and maintenance; shared operational model.

ISO 27001CIS Controls
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Operations

Segmentation

Operational

Logical separation between service components and customer environments.

ISO 27001NIST CSF
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Operations

Monitoring

Operational

Security and service health monitoring for operated environments.

NIST CSFCIS Controls
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Operations

Hardening

Documented

Baseline hardening for operated platform components.

CIS ControlsNIST CSF
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Operations

Data security

Encryption

Operational

TLS in transit at the HTTPS edge; encryption at rest confirmed per contract.

ISO 27001NIST CSF
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security

Data isolation

Operational

Tenant and workspace separation within the operated service.

ISO 27001NIST CSF
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security

Backup

Documented

Backup routines for operated environments; RPO/RTO confirmed contractually.

ISO 27001NIST CSF
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Operations

Retention

Documented

Retention aligned with customer agreement and applicable law.

GDPR
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Legal

Secure deletion

Documented

Deletion procedures defined for contract termination scenarios.

GDPRISO 27001
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Operations

Resilience

Backup (resilience)

Documented

Backup capability supporting service recovery objectives.

ISO 27001NIST CSF
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Operations

Disaster recovery

In implementation

DR posture defined; public DR statement in progress.

ISO 27001NIST CSF
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Operations

Business continuity

In implementation

Continuity planning for the SaaS service; detailed BCP on request.

ISO 27001NIST CSF
Evidence: NDA / restrictedLast reviewed: 2026-08-20Owner: Operations

Incident response

In implementation

Incident handling for the operated service; public playbook in progress.

ISO 27001NIST CSF
Evidence: Customer accessLast reviewed: 2026-08-20Owner: Security
Request evidence

Compliance & frameworks

We separate certification, assessment, alignment and regulatory applicability. No certificate is claimed unless formally in scope for QData Projects.

Aligned

ISO/IEC 27001

Planned

Not certified for QData Projects on this page.

Independently assessed

SOC 2 Type II

Planned

Not independently assessed for QData Projects on this page.

Self-assessed

CSA STAR Level 1

Planned

Not self-assessed publicly yet.

Aligned

NIST CSF

Documented

Controls mapped where applicable — not a certification.

Aligned

CIS Controls

Documented

Controls aligned where applicable — not a certification.

Regulatory

GDPR

Documented

Applicable; controls implemented per DPA and agreements.

Regulatory

NIS2

In implementation

Supply-chain relevance assessed; public statement in progress.

Regulatory

CRA

In implementation

Applicability assessed for product context.

Industry & regulatory assurance

Industry-specific assurance topics without claiming certifications we do not hold (for example HIPAA) unless formally in scope.

Healthcare

  • Data protection
  • Access control
  • Auditability
  • Data retention
  • Privacy
  • Security monitoring

Public sector

  • Data residency
  • Access governance
  • Auditability
  • Incident management
  • Supplier security

Research

  • Data ownership
  • Confidentiality
  • Access control
  • Research data protection
  • Collaboration security

IT & technology

  • API security
  • SSO
  • RBAC
  • Auditability
  • Integrations

Evidence library

Documents and artifacts for security reviews. Customer and restricted items require authentication or NDA.

Public

Security overview
Last reviewed: 2026-08-20Operational
View
Privacy Policy
Last reviewed: 2026-07-15Documented
View
DPA framework
Last reviewed: 2026-07-15Documented
View
Security architecture overview
Last reviewed: 2026-08-20In implementation
View
Vulnerability disclosure policy
Last reviewed: 2026-08-24Documented
View
Subprocessor list
Last reviewed: 2026-08-20In implementation
View

Customer access

Security questionnaire (completed on request)
Last reviewed: 2026-08-20Operational
View
CAIQ
Last reviewed: 2026-08-20Planned
View
SIG Lite
Last reviewed: 2026-08-20Planned
View
Penetration test summary
Last reviewed: 2026-08-20Planned
View
BCP / DR summary
Last reviewed: 2026-08-20In implementation
View

NDA / restricted

Security policies (detailed)
Last reviewed: 2026-08-20Restricted
Request
Full penetration test report
Last reviewed: 2026-08-20Restricted
Request
Detailed architecture
Last reviewed: 2026-08-20Restricted
Request

Request security package

Select topics for your security review. We respond from verified controls and mark unknowns instead of over-claiming.

Policy topics

Detailed policy statements. Status reflects assurance level — not marketing availability.

Security overview

Operational

QData Projects is an enterprise SaaS offering for security-conscious organizations. Core application controls include RBAC and authentication options. Absolute security guarantees are never made.

Infrastructure

In implementation

QData Projects is operated by QData on qualified third-party infrastructure under our vendor risk requirements. Europe and North America primary data locations are available at onboarding. A formal infrastructure whitepaper remains in progress. Customer-hosted or on-premises installs are not offered.

Data protection

Operational

Supports strong access control and organizational data governance. Primary data location is selectable: Europe or North America. Processing details are documented in the DPA and customer agreement.

Authentication

Operational

Password policy controls, multi-factor authentication (TOTP / WebAuthn where enabled), and enterprise SSO / directory options.

Access control

Operational

Granular role-based permissions at project level. Membership and role design are part of onboarding.

Encryption

Operational

Encryption in transit via TLS at the HTTPS edge. Encryption at rest is confirmed per contract — we do not copy third-party cloud claims by default.

Backup

Documented

Backup routines exist for operated SaaS environments. Retention and restore objectives are confirmed contractually. Public RPO/RTO numbers are not stated here.

Disaster recovery

In implementation

DR posture is defined for the SaaS service. Documented public DR statements remain in progress.

Incident response

In implementation

Incident response contacts and playbooks will be published when operationalized. Use the security contact channel for urgent reports.

Vulnerability management

Operational

Vendor updates plus operational patch process for the SaaS platform. Public SLA text remains in progress.

Security updates

Operational

Security updates and platform maintenance are included in SaaS operations performed by QData.

Privacy

Documented

Published Privacy Policy for the Website and related communications. Workspace data is covered by customer agreements and the DPA. View document

DPA

Documented

Published DPA framework for QData Projects SaaS processing. Request an executed schedule via the security contact. View document

Subprocessors

In implementation

Lists are published only for services actually used in the SaaS offering. No placeholder vendors are named as fact.

Compliance documentation

Planned

No ISO/HIPAA/NIS2 certification is claimed for QData Projects on this page. Certifications will list issuer, scope, version and date when obtained.

Security contact

Operational

Security inquiries via the contact form with topic=security. For production emergencies on an operated tenant, use the channel in your contract.

Trust Center updates

Changes to public security and assurance content for QData Projects.

Trust Center v2 — posture dashboard, controls, evidence library and shared responsibility model

View

Published DPA framework

View

Published Privacy Policy

View
View all updates

Need a security questionnaire?

Contact us with your framework and SaaS requirements. We answer from verified controls and mark unknowns instead of over-claiming.