🔒 Security Policy & Transparency

Security by Design,
Transparency by Default

At That Is A Q, protecting client data and system integrity isn't an afterthought—it's the foundation of every architecture we design and every product we ship.

How We Approach Security
Our security posture is built on industry best practices, continuous improvement, and a zero-trust mindset.
🛡️

Zero Trust Architecture

We assume breach. Every request is authenticated, authorized, and encrypted. Least-privilege access is enforced across all environments and team members.

🔐

Encryption Everywhere

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Customer secrets, keys, and credentials are never stored in plain text or exposed in logs.

👁️

Continuous Monitoring

Real-time threat detection, automated vulnerability scanning, and 24/7 infrastructure monitoring ensure issues are identified and mitigated before impact.

🔄

Secure SDLC

Security is integrated into every phase: threat modeling, code reviews, automated testing, penetration testing, and post-deployment validation.

Infrastructure & Practices
The technical controls and workflows that keep your data secure.

Access Control

Role-based access (RBAC) with MFA enforced. Short-lived tokens via JWT and OAuth 2.0. Session rotation after privilege changes.

Key Management

Keys are rotated automatically and stored in HSM or cloud KMS. No hardcoded secrets in repositories or configuration files.

Vulnerability Scanning

Automated SAST/DAST pipelines, dependency auditing, and weekly third-party penetration tests on production environments.

Data Isolation

Tenant-level data separation using schema or database isolation. Strict network segmentation and private subnets for sensitive workloads.

Audit Logging

Immutable, tamper-evident logs for all administrative actions, data access, and configuration changes. Retained for 7+ years.

Incident Response

Documented playbooks, dedicated security team, and automated alerting. SLA-driven containment and post-incident reviews.

Certifications & Frameworks
We align with globally recognized security and privacy standards.
SOC2
SOC 2 Type IIAnnually audited. Covers security, availability, and confidentiality.
GDPR
GDPR CompliantData processing agreements, DPO available, right to erasure supported.
ISO
ISO 27001 (Auditing)Implementing ISMS controls. Target certification: Q3 2025.
CCPA
CCPA / CPRA ReadyOpt-out controls, data mapping, and consumer request workflows.

That Is A Q undergoes regular third-party audits and maintains a public status page for infrastructure transparency. Clients can request our latest compliance reports under NDA.

Our data processing terms and security addendums are provided during onboarding for all enterprise engagements.

Found a Vulnerability?

We appreciate security researchers who help us keep our systems safe. Please report issues responsibly and we will acknowledge your contribution.

01
Report
Email details to our security team
02
Acknowledge
Response within 24 hours
03
Resolve
Fix & notify when patched