Security

Security by Design

Your data. Protected. Transparent.

We take security seriously. QCypher is built on a foundation of encryption, role-based access control, and continuous monitoring. Here's exactly how we protect your business data — no corporate jargon, just the facts.

Section 01

Data in Transit & At Rest

TLS 1.2+ encryption for all data in transit — website, API, and mobile
AES-256 encryption for data at rest in our Supabase Postgres database
SSL/TLS certificates managed by Let’s Encrypt, with automatic renewal
All customer data encrypted by default — no opt-in required
Section 02

Who Can Access What

Email/password authentication with secure password hashing
Google OAuth available for easier, passwordless login
Multi-factor authentication (MFA) available for admin accounts
Role-based access control — Admin, User, and Read-only tiers
Each customer’s data isolated at the database level via row-level security (RLS)
Super admin access to customer data is exceptional, not routine, and always logged to an audit trail
Section 03

We Watch What Matters

Comprehensive audit logging — every create, update, and delete records who did what, and when
90-day audit trail retention, auto-purged on a schedule after that
Real-time access logging for admin accounts
Cost-conscious, efficient logging — built for a growing business, not enterprise overkill
Super admin actions are logged and visible in each customer’s own audit trail
Logs record actions only — never the content of your customer data
Section 04

When Things Go Wrong

A written incident response plan is in place
Security vulnerabilities can be reported to legal@qcyphertech.com
Customers notified within 24 hours of a confirmed breach, or as required by law
Every incident gets a post-incident review, with lessons learned documented
No data brokers or third parties are given access to customer data
Public disclosure policy: we only publish a public incident report when required by law or explicitly requested by an affected customer — not as a matter of course. Any public report omits customer names and specific technical vulnerabilities.
Section 05

Your Data. Your Control.

You own all of your data — contacts, notes, customer records, everything
Data export available on request, in CSV or JSON
All data removed within 30 days of account closure
Automatic daily backups, managed by Supabase
Backup retention: 7 days minimum, 30 days standard
We never sell or share your customer data with third parties
In compliance terms: we are a "data processor" — you remain the "data controller" of your customer information.
Section 06

Built on Trusted Services

Database: Supabase Postgres, AWS-backed and SOC 2 Type II compliant
Hosting: Vercel — edge functions, DDoS protection, 99.95% uptime SLA
Third-party services: Cal.com for scheduling, Telnyx for SMS/voice, Resend for email
Every third-party service is evaluated for security before we integrate it
No customer data is stored in third-party systems — only operational data like scheduled events or sent emails
Section 07

What’s Coming

SOC 2 Type II audit planned once our customer base reaches 50+
ISO 27001 certification as a long-term goal, 18–24 months out
Automated vulnerability scanning currently in development
Additional API rate limiting and DDoS hardening
A bug bounty program, once scale justifies it
Section 08

Security Documents & Assessments

Security & privacy documentation available on request
Incident response plan available on request
Data Processing Agreement (DPA) available for enterprise customers
SOC 2 report available upon request — currently undergoing preparation
Contact legal@qcyphertech.com for compliance questions.
A Note on Honesty

Transparency Over Perfection

We're a small team, not a 500-person security department — and we'd rather tell you that than pretend otherwise.

What we can tell you is that our architecture is designed for enterprise-grade security from day one: encryption everywhere, strict tenant isolation, and an audit trail for every action that matters.

And when something does go wrong, you get a real incident response process — not just a promise that "we handle everything."

Questions?

We believe in transparency. If you have questions about our security practices, please reach out.

Response time: within 48 business hours

Last updated: August 7, 2026