Europe
Primary data location
AvailablePublic interface to our Security Assurance program for QData Projects. We publish verified controls, mark items in progress and do not invent certificates, subprocessors or procedures we do not operate.
Scope: QData Projects SaaS platform, application, operational processes and infrastructure used to deliver the service.
High-level assurance status for QData Projects. Detailed controls and evidence are listed below.
| Control area | Assurance status |
|---|---|
| Application security | Operational |
| Identity & access | Operational |
| Encryption | Operational |
| Data protection | Operational |
| Infrastructure documentation | In implementation |
| Backup | Documented |
| Disaster recovery | In implementation |
| Incident response | In implementation |
| Vulnerability management | Operational |
| Privacy / GDPR | Documented |
Primary data location and colocation are selected at onboarding.
Primary data location
AvailablePrimary data location
AvailableControl-level view for security reviews. Evidence availability is indicated per control.
Password policy controls plus enterprise authentication options for the SaaS workspace.
TOTP and WebAuthn where enabled for workspace accounts.
Enterprise SSO and directory integration options (Enterprise capability).
Granular role-based permissions at project level.
Controlled operator access for SaaS operations; detailed policy available on request.
Secure SDLC practices for platform changes; formal public policy in progress.
Tracking and patching of platform and application dependencies.
Vendor updates plus operational patch process for the SaaS platform.
Security testing program; public summary available on request when published.
Security fixes and platform maintenance included in SaaS operations.
Edge TLS and network controls; shared with infrastructure partners.
Host-level hardening and maintenance; shared operational model.
Logical separation between service components and customer environments.
Security and service health monitoring for operated environments.
Baseline hardening for operated platform components.
TLS in transit at the HTTPS edge; encryption at rest confirmed per contract.
Tenant and workspace separation within the operated service.
Backup routines for operated environments; RPO/RTO confirmed contractually.
Retention aligned with customer agreement and applicable law.
Deletion procedures defined for contract termination scenarios.
Backup capability supporting service recovery objectives.
DR posture defined; public DR statement in progress.
Continuity planning for the SaaS service; detailed BCP on request.
Incident handling for the operated service; public playbook in progress.
We separate certification, assessment, alignment and regulatory applicability. No certificate is claimed unless formally in scope for QData Projects.
Not certified for QData Projects on this page.
Not independently assessed for QData Projects on this page.
Not self-assessed publicly yet.
Controls mapped where applicable — not a certification.
Controls aligned where applicable — not a certification.
Applicable; controls implemented per DPA and agreements.
Supply-chain relevance assessed; public statement in progress.
Applicability assessed for product context.
Industry-specific assurance topics without claiming certifications we do not hold (for example HIPAA) unless formally in scope.
Documents and artifacts for security reviews. Customer and restricted items require authentication or NDA.
Select topics for your security review. We respond from verified controls and mark unknowns instead of over-claiming.
Detailed policy statements. Status reflects assurance level — not marketing availability.
QData Projects is an enterprise SaaS offering for security-conscious organizations. Core application controls include RBAC and authentication options. Absolute security guarantees are never made.
QData Projects is operated by QData on qualified third-party infrastructure under our vendor risk requirements. Europe and North America primary data locations are available at onboarding. A formal infrastructure whitepaper remains in progress. Customer-hosted or on-premises installs are not offered.
Supports strong access control and organizational data governance. Primary data location is selectable: Europe or North America. Processing details are documented in the DPA and customer agreement.
Password policy controls, multi-factor authentication (TOTP / WebAuthn where enabled), and enterprise SSO / directory options.
Granular role-based permissions at project level. Membership and role design are part of onboarding.
Encryption in transit via TLS at the HTTPS edge. Encryption at rest is confirmed per contract — we do not copy third-party cloud claims by default.
Backup routines exist for operated SaaS environments. Retention and restore objectives are confirmed contractually. Public RPO/RTO numbers are not stated here.
DR posture is defined for the SaaS service. Documented public DR statements remain in progress.
Incident response contacts and playbooks will be published when operationalized. Use the security contact channel for urgent reports.
Vendor updates plus operational patch process for the SaaS platform. Public SLA text remains in progress.
Security updates and platform maintenance are included in SaaS operations performed by QData.
Published Privacy Policy for the Website and related communications. Workspace data is covered by customer agreements and the DPA. View document
Published DPA framework for QData Projects SaaS processing. Request an executed schedule via the security contact. View document
Lists are published only for services actually used in the SaaS offering. No placeholder vendors are named as fact.
No ISO/HIPAA/NIS2 certification is claimed for QData Projects on this page. Certifications will list issuer, scope, version and date when obtained.
Security inquiries via the contact form with topic=security. For production emergencies on an operated tenant, use the channel in your contract.
Changes to public security and assurance content for QData Projects.
Trust Center v2 — posture dashboard, controls, evidence library and shared responsibility model
ViewPublished DPA framework
ViewPublished Privacy Policy
ViewContact us with your framework and SaaS requirements. We answer from verified controls and mark unknowns instead of over-claiming.