Skip to content

Security and privacy overview

Two pages, for the person who has to sign off a new supplier. Everything here is stated in more detail on the Trust Centre, in the Data Processing Agreement and in the Records of processing. Last reviewed 13 September 2026.

An electronic quality management system (documents, training, deviations, CAPA, audits, change control, complaints, suppliers, equipment) delivered as a subscription, by InnoQualis LTD, a company registered in England and Wales. Your organisation owns its records; we host and process them on your instructions.

  • Hosting: OVHcloud, Frankfurt, Germany (EU) — the production platform is moving there now; the provider and region are decided.
  • Backups: encrypted before they leave the host; a nightly copy with Hetzner (Germany) and a monthly copy with Backblaze (EU). Two independent providers, so one provider incident cannot take the data and its backups together.
  • Email: Microsoft 365, contracted through GoDaddy for the current term. Payments: Stripe — card details never reach us. DNS: Cloudflare (DNS only today). AI features: OpenAI in the United States, under Standard Contractual Clauses, no training on your data, switchable off for your workspace on request.
  • Every provider is listed with its agreement on the Trust Centre; you get 15 days’ notice and a right to object before any change.
  • Access: passwordless sign-in by single-use codes that expire in 15 minutes; four workspace roles; every request scoped to your workspace, enforced at commit time and by tests.
  • Records: audit trails are append-only and hash-chained; electronic signatures are never deleted, only superseded with a reason — designed to support 21 CFR Part 11, clause by clause (map on the Trust Centre).
  • In transit: TLS 1.2 or higher everywhere, HSTS on.
  • At rest: backups, integration tokens and uploaded licensed standards are encrypted. Planned, not yet in place: full-disk encryption of the production host and a managed key service (with the OVHcloud cutover).
  • Operations: external uptime monitoring and a public status page (status.innoqualis.com); host intrusion checks every ten minutes; automatic security updates; secrets kept out of source and rotated at defined events; every change reviewed and tested before deployment.
  • Vendor access: our staff reach an operator panel that sees counts and user directories, never record content; every operator request is written to the audit log.
Availability objective99.5 % per month (an objective we report against, not a credit-bearing SLA)
RecoveryRPO 24 hours, RTO 4 hours (target until the first restore drill is recorded)
Breach noticeWithout undue delay, no later than 48 hours after we become aware
Sub-processor changes15 days’ notice, right to object
Leaving30-day export window, deletion within a further 30 days, written confirmation
AuditBy arrangement, once a year, on 30 days’ notice

No third-party certification (ISO 27001, SOC 2) is held today; the hosting facility is ISO 27001-certified, InnoQualis is not. No “Part 11 certification” exists for any product; we say designed to support, and your organisation validates its use. No dedicated server per customer — one shared application tier and one shared database with workspace scoping, stated plainly on the Trust Centre. No HIPAA Business Associate Agreement.

What you store and its lawful basis; who you invite and with which role; the security of your own email accounts (sign-in codes arrive by email); your validation decisions and regulatory filings.

dpo@innoqualis.com (data protection) · compliance@innoqualis.com (compliance) · contact@innoqualis.com (everything else, and security reports — see /.well-known/security.txt).