πŸ›‘οΈ Data Security & Privacy

We treat security as a core feature, not an afterthought. Our infrastructure, processes, and culture are built to protect your data with the highest industry standards.

πŸ“„ Last updated: October 24, 2025

🧠 Security by Design

At That Is A Q, security is embedded into every layer of our development lifecycle. We don't bolt security on at the end; we architect it from the start. This means rigorous code reviews, automated vulnerability scanning, and continuous threat modeling.

Our team undergoes regular security training, and we follow the principle of least privilege across all internal and client-facing systems.

πŸ”„ DevSecOps

Security checks integrated into every CI/CD pipeline, ensuring vulnerabilities are caught before deployment.

πŸ” Continuous Audits

Regular penetration testing and dependency audits to identify and patch weaknesses proactively.

πŸ“š Secure Coding

Adherence to OWASP Top 10 best practices and secure development frameworks for all custom software.

πŸ§ͺ Threat Modeling

Proactive analysis of potential threats during the design phase to mitigate risks before code is written.

πŸ” Encryption & Data Protection

We employ military-grade encryption standards to protect data at rest and in transit. Your sensitive information is never stored in plain text.

  • βœ“ AES-256 encryption for all data at rest.
  • βœ“ TLS 1.3 encryption for all data in transit.
  • βœ“ Key Rotation policies enforced automatically.
  • βœ“ Tokenization for sensitive PII where applicable.

πŸ”‘ Access Control & Identity

Access to client data and infrastructure is strictly controlled and monitored.

Multi-Factor Authentication

MFA is mandatory for all employee accounts, vendor access, and administrative panels.

Role-Based Access Control

Employees only access the data necessary for their role. No broad, unnecessary permissions.

Session Management

Strict timeout policies and secure session handling to prevent unauthorized access.

Audit Logs

Immutable logs track who accessed what and when, ensuring full accountability.

☁️ Infrastructure Security

We host solutions on enterprise-grade cloud providers with built-in redundancy and DDoS protection.

Our infrastructure is hardened following CIS benchmarks, with automated patching and real-time monitoring for anomalies. We utilize Web Application Firewalls (WAF) and rate limiting to protect against common attacks.

βœ… Compliance & Certifications

We adhere to global standards to ensure your data is handled responsibly across jurisdictions.

πŸ‡ͺπŸ‡Ί

GDPR

Full compliance with EU General Data Protection Regulation.

πŸ‡ΊπŸ‡Έ

CCPA

Adherence to California Consumer Privacy Act requirements.

πŸ”’

SOC 2 Type II

Currently undergoing audit. Report available for enterprise clients.

πŸ›‘οΈ

ISO 27001

Information Security Management System aligned with ISO standards.

πŸ₯

HIPAA Ready

Capabilities to support healthcare data requirements upon request.

🌍

Data Residency

Flexible region selection to keep data within specific borders.

🀝 Client Data & Ownership

Your data belongs to you, not us. We act as a processor, not a controller.

We sign strict Non-Disclosure Agreements (NDAs) and Data Processing Agreements (DPAs) with every client. Upon project completion or contract termination, we securely wipe all client data from our systems according to NIST 800-88 guidelines, unless otherwise retained for legal purposes.

🚨 Incident Response

Despite our best efforts, incidents can happen. We have a robust response plan in place.

  • Detection: 24/7 monitoring and automated alerts.
  • Response: Dedicated incident response team activated within 30 minutes.
  • Communication: Transparent communication to affected stakeholders within defined SLAs.
  • Recovery: Rapid restoration from immutable backups.
  • Post-Mortem: Root cause analysis and process improvement documentation.

❓ Frequently Asked Questions

Data is stored in secure, redundant cloud regions (AWS, Azure, or GCP) configured to your requirements. We support data residency options to ensure data stays within specific geographic boundaries if needed.
No. We do not sell, rent, or share your data with third parties for advertising or analytics. We only engage vetted sub-processors with strict contractual obligations, and we maintain a full list of sub-processors for transparency.
In the unlikely event of a breach, we follow our Incident Response Plan. We will notify affected clients within 72 hours (or as required by law/regional agreements) and provide full transparency regarding the scope and remediation steps.
Absolutely. You have the right to access, port, or delete your data at any time. You can submit a request via our security portal or by emailing security@thatisaq.com.

Have Security Questions?

Our security team is available to discuss specific requirements, provide a Security Whitepaper, or review your specific concerns.

Contact Security Team
πŸ“§ security@thatisaq.com