1. Overview
At Quallie.Ai Ltd, our commitment to security is foundational to our operations and services. The primary goal of our security policy is to safeguard the confidentiality, integrity, and availability of data. We strive to ensure that authorized users can access necessary information promptly and securely, reinforcing our mission to provide reliable and secure A.I. enabled software solutions.
Understanding the critical importance of security, we place it at the forefront of our priorities. Our approach is proactive and preventative, ensuring that all data handled by Quallie.Ai Ltd remains secure, private, and available as needed by our users. To maintain the highest standards of security, our infrastructure runs exclusively on certified providers, namely Google Cloud and Amazon Web Services. Our AI and transcription services are provided by Google Cloud Vertex AI and by the specialist transcription providers named in our privacy policy, each of which is listed in full there. We adhere to stringent security protocols including:
Data encryption
All data is encrypted both at rest and in transit, using advanced encryption methodologies to protect against unauthorized access and breaches.
Access control
Access to customer data is rigorously controlled. Employees at Quallie.Ai Ltd are permitted to access customer data strictly with customer permission ensuring a transparent and consensual data management process.
Data replication
We employ strategies for data replication to ensure data availability and integrity. This approach ensures uninterrupted access to data, even in the event of hardware failures or other disruptions. Our database is backed up automatically every day, with 14 daily backups retained and point-in-time recovery available to any moment in the last 7 days. Backups are stored across multiple regions within the EU, and uploaded and generated media is held in versioned storage so that earlier versions of a file can be recovered.
Ethical data use
Quallie.Ai Ltd does not use customer data to train artificial intelligence models or for any other purposes not previously agreed with the client, upholding our commitment to data privacy and ethical use. Our incident response plan ensures that in case of security breaches or data loss, all relevant parties are notified, and access to data is restored swiftly and effectively.
2. Data encryption
At Quallie.Ai Ltd, ensuring the security of data, whether at rest or in transit, is paramount. We employ robust encryption methodologies to protect your information from unauthorized access and breaches.
Data at rest
To safeguard data stored on our systems, we utilize industry-standard encryption methods, namely AES-256 encryption, one of the most secure encryption standards available today. This ensures that your data remains protected against external threats and vulnerabilities.
Data in transit
We are committed to protecting data as it moves between our servers and users' browsers. All data in transit is securely encrypted using HTTPS, incorporating TLS (Transport Layer Security) protocols. This not only secures data as it travels across the internet but also helps in maintaining the privacy and integrity of the information being transmitted.
Data encryption key management
Our encryption keys are managed using security practices provided by our cloud service providers (i.e. Google Cloud and Amazon Web Services), using their platform-managed key services. This approach ensures that key management is both secure and compliant with the latest industry standards, without requiring us to directly handle or maintain the encryption keys. Regular updates and rotations of encryption keys are conducted by our providers, aligning with best practices for security and data protection.
3. Access control
Quallie.Ai Ltd implements stringent access control measures to ensure that data access is secure, appropriate, and compliant with our privacy standards.
User authentication
We employ two-step authentication to verify the identities of users accessing our internal systems. This enhanced security measure requires not only a password but also a second factor, significantly reducing the risk of unauthorized access.
Authorization and data access
Access to customer data within Quallie.Ai Ltd is tightly controlled and managed at the highest level. The Chief Technology Officer (CTO) directly oversees the access permissions, granting access to employees only when strictly necessary and approved by the customer. This ensures that access is always justified, documented, and aligned with customer expectations and legal requirements.
Role-based access control (RBAC)
Our platform utilizes role-based access control (RBAC) to manage permissions efficiently. This framework allows different levels of access depending on the user's role within the organization, ensuring that individuals can only access information essential to their job functions.
Review and revocation of access
Permissions are granted on a case-by-case basis and are promptly revoked when no longer necessary. This process is crucial to maintaining the security and integrity of customer data.
4. Network security
At Quallie.Ai Ltd, we prioritize the security of our network infrastructure as a critical aspect of our overall security strategy. We implement robust measures to protect against unauthorized access and cyber threats, ensuring a secure environment for our users and their data.
Encryption and traffic management
All network traffic to and from Quallie.Ai Ltd is encrypted using HTTPS, ensuring that data transmitted over the internet is secure and protected from interception. This is a fundamental security measure that helps safeguard user data integrity and confidentiality.
Edge protection and DDoS mitigation
All traffic reaches Quallie.Ai through a Google Cloud global HTTPS load balancer protected by Google Cloud Armor, our web application firewall. Cloud Armor applies OWASP core rule set protections and rate limiting at the edge, and Google's global network absorbs volumetric distributed denial-of-service attacks before they reach our services. Our application services accept no traffic except through that load balancer, enforced both by network ingress restrictions and by a signed header that the load balancer injects and our services verify.
Server security
Our servers are rigorously maintained with the latest security patches and updates. This proactive approach ensures that vulnerabilities are addressed promptly, minimizing the risk of malicious attacks, and securing our infrastructure.
Monitoring and response
Our infrastructure is monitored continuously through Google Cloud Logging and Cloud Monitoring. Load balancer and web application firewall requests are logged, and alerting policies notify our engineers of error conditions and anomalous traffic so that they can be investigated and responded to. Our application logs are structured and deliberately exclude interview transcripts, AI output, credentials and user email addresses, so that operational monitoring never exposes research content.
5. Application security
Quallie.Ai Ltd is committed to maintaining the highest level of application security by implementing stringent coding practices and security measures throughout our development and operational processes.
Strong password policies
We enforce strong password requirements to enhance user account security. This includes the use of complex passwords that must meet specific criteria to prevent easy guessing or brute-force attacks.
Data segregation
Data is segregated by workspace, customer and project. Every read and write is authorised on the server in the context of the specific project it targets, against explicit grants: belonging to a workspace does not by itself grant access to the research held inside it, and access to one project does not extend to another. This not only enhances security but also ensures compliance with data protection regulations.
Code standards
Credentials and secrets are held in Google Secret Manager and injected at deploy time. They are never committed to source control and never exposed to the browser. By keeping sensitive data out of client-facing layers, we minimise the risk of accidental exposure or security breaches. Authorisation is always enforced on the server rather than in the client, so that actions can only be performed by authorised users, and our deployment pipeline blocks any release whose container images carry unreviewed high or critical severity vulnerabilities.
6. Incident response plan
Quallie.Ai Ltd has a robust incident response plan in place to address security breaches swiftly and effectively. Our approach ensures that we can manage incidents with the utmost seriousness and minimal impact to our customers.
Initial response and notification
Upon detection of a security breach, our immediate priority is to assess the scope and impact of the incident. We take decisive actions to contain the breach and prevent further unauthorized access. Affected customers are notified as soon as the breach is confirmed and we have a clear understanding of the impact. Communication is transparent, providing details on the nature of the breach, the data involved, and the steps being taken to address the issue.
Responsibility and oversight
The Chief Technology Officer (CTO) is directly responsible for managing the incident response.
Notification to regulatory authorities
In compliance with data protection regulations and industry standards, we notify relevant regulatory authorities within the timelines mandated by law. This ensures that all legal and ethical obligations are met in the handling of the incident.
Remediation and review
Following immediate remediation actions, a thorough investigation is conducted to identify the root cause of the breach. This involves a comprehensive review of our security policies and practices to prevent similar incidents in the future. Enhancements to security measures are implemented based on the findings, and all changes are documented and communicated to relevant stakeholders.
7. Contact us
We continuously evaluate and update our security practices in response to evolving threats and technological advancements. Our commitment to security is integral to our mission, and we remain dedicated to providing a safe and secure service for all our users.
For any further information on specific queries, please contact our security team at security@quallie.ai