Trust

Security practices

This page is maintained by HCQS FZE LLC to answer common security questions about the HCQS platform. It describes controls we operate today — it is not a certification or an independent audit.

Authentication

Accounts sign in with email or a supported identity provider. Sessions are token-based and expire; passwords are never stored in plain text.

Data access

Business data is isolated per account with row-level access rules enforced in the database, so one workspace cannot read another's records.

Infrastructure

The platform runs on managed cloud infrastructure with encrypted connections (HTTPS/TLS), managed backups and least-privilege service credentials.

Monitoring

Application and database activity is logged, and automated scanning runs against the codebase and dependencies as part of our release process.

Shared responsibility

HCQS secures the platform, its infrastructure and the isolation between accounts. As the business owner, you are responsible for who you invite into your workspace, the strength of your credentials, and the lawfulness of the data you collect from your own customers.

Data location and retention

Business data is stored with managed cloud providers and retained while your account is active. Deletion requests are handled as described in our privacy policy.

Reporting a vulnerability

Report suspected vulnerabilities to security@hcqs.ai. Include reproduction steps and the affected URL. We acknowledge reports within two business days and ask that you avoid accessing other customers' data while testing.

Contact

Security and compliance questionnaires: HCQS FZE LLC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates.