Security and privacy overview
Two pages, for the person who has to sign off a new supplier. Everything here is stated in more detail on the Trust Centre, in the Data Processing Agreement and in the Records of processing. Last reviewed 13 September 2026.
What InnoQualis is
Section titled “What InnoQualis is”An electronic quality management system (documents, training, deviations, CAPA, audits, change control, complaints, suppliers, equipment) delivered as a subscription, by InnoQualis LTD, a company registered in England and Wales. Your organisation owns its records; we host and process them on your instructions.
Where your data is and who touches it
Section titled “Where your data is and who touches it”- Hosting: OVHcloud, Frankfurt, Germany (EU) — the production platform is moving there now; the provider and region are decided.
- Backups: encrypted before they leave the host; a nightly copy with Hetzner (Germany) and a monthly copy with Backblaze (EU). Two independent providers, so one provider incident cannot take the data and its backups together.
- Email: Microsoft 365, contracted through GoDaddy for the current term. Payments: Stripe — card details never reach us. DNS: Cloudflare (DNS only today). AI features: OpenAI in the United States, under Standard Contractual Clauses, no training on your data, switchable off for your workspace on request.
- Every provider is listed with its agreement on the Trust Centre; you get 15 days’ notice and a right to object before any change.
How it is protected
Section titled “How it is protected”- Access: passwordless sign-in by single-use codes that expire in 15 minutes; four workspace roles; every request scoped to your workspace, enforced at commit time and by tests.
- Records: audit trails are append-only and hash-chained; electronic signatures are never deleted, only superseded with a reason — designed to support 21 CFR Part 11, clause by clause (map on the Trust Centre).
- In transit: TLS 1.2 or higher everywhere, HSTS on.
- At rest: backups, integration tokens and uploaded licensed standards are encrypted. Planned, not yet in place: full-disk encryption of the production host and a managed key service (with the OVHcloud cutover).
- Operations: external uptime monitoring and a public status page (status.innoqualis.com); host intrusion checks every ten minutes; automatic security updates; secrets kept out of source and rotated at defined events; every change reviewed and tested before deployment.
- Vendor access: our staff reach an operator panel that sees counts and user directories, never record content; every operator request is written to the audit log.
What you can expect from us
Section titled “What you can expect from us”| Availability objective | 99.5 % per month (an objective we report against, not a credit-bearing SLA) |
| Recovery | RPO 24 hours, RTO 4 hours (target until the first restore drill is recorded) |
| Breach notice | Without undue delay, no later than 48 hours after we become aware |
| Sub-processor changes | 15 days’ notice, right to object |
| Leaving | 30-day export window, deletion within a further 30 days, written confirmation |
| Audit | By arrangement, once a year, on 30 days’ notice |
What we do not claim
Section titled “What we do not claim”No third-party certification (ISO 27001, SOC 2) is held today; the hosting facility is ISO 27001-certified, InnoQualis is not. No “Part 11 certification” exists for any product; we say designed to support, and your organisation validates its use. No dedicated server per customer — one shared application tier and one shared database with workspace scoping, stated plainly on the Trust Centre. No HIPAA Business Associate Agreement.
Your responsibilities
Section titled “Your responsibilities”What you store and its lawful basis; who you invite and with which role; the security of your own email accounts (sign-in codes arrive by email); your validation decisions and regulatory filings.
Contacts
Section titled “Contacts”dpo@innoqualis.com (data protection) · compliance@innoqualis.com (compliance) · contact@innoqualis.com (everything else, and security reports — see /.well-known/security.txt).