Trust
Security
Our own posture, stated plainly. For how we secure the systems we build, see the platform security model.
| Area | Practice |
|---|---|
| Client data | Default position is that it never leaves your systems. We work inside your environment on your equipment or on managed devices under your acceptable-use policy. Where a copy is unavoidable, it is agreed in writing, minimised, time-boxed and destroyed on a stated date. |
| Access | Least privilege, individually named accounts, no shared credentials, and access removed at the end of an engagement rather than at the end of a support period. We do not retain client credentials, keys or repository access after handover. |
| Devices | Full-disk encryption, enforced updates, screen lock, endpoint protection, and no client data on personal equipment. Where a client requires their own managed device, we use it. |
| Development | Work happens in your repositories under your review process, so your standard applies rather than ours. On our own systems: pinned dependencies, secret scanning, and secrets held in an encrypted store rather than in configuration. Findings are triaged rather than accumulated. |
| Sub-processors | Kept deliberately short, named in the engagement contract, and available in full on request. We do not add a sub-processor to a client engagement without agreement. |
| Incident response | A documented plan with defined roles and notification timelines. Clients are told about anything touching their data before it is convenient for us. |
Responsible disclosure
If you believe you have found a vulnerability in this website or in software we publish, we want to hear from you and we will not take legal action against good-faith research conducted under this policy.
How to report
Email security@qailabs.io with enough detail to reproduce the issue. We acknowledge within two working days and give a first assessment within ten.
In scope
- · This website and its subdomains.
- · Any open-source software we release, if and when we release any.
Out of scope
- · Client systems. If you have found something in a system we built for a client, please tell us and we will route it, do not test it.
- · Denial-of-service testing, social engineering, and physical access attempts.
- · Reports generated solely by automated scanners with no demonstrated impact.
Safe harbour
Research conducted in good faith under this policy, without accessing data belonging to others, without degrading service, and with disclosure to us before anyone else, will not be treated as a hostile act. Give us a reasonable period to fix an issue before publishing.
Due diligence questions?
Procurement and security teams can request our full documentation set. We would rather answer a questionnaire early than at contract stage.