QReportly

QReportly

Sign in

For DPO / IT reviewers

Enterprise security evaluation pack

A single checklist of controls we actually publish. Use it in vendor questionnaires. We do not attach certificates we do not hold.

Qreportly LLC · 30 N Gould St Ste R, Sheridan, WY 82801, USA

Share this URL with your DPO, IT security, or procurement reviewer. Each item links to the source page. Negative answers (no ISO 27001, no SOC 2, no published pentest) are listed on purpose.

  1. 1.

    Legal identity of the provider

    Documented

    Qreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA — Wyoming LLC. No EU VAT / CUI is published because none is registered. Terms state governing law with a GDPR / Member State carve-out for channel data.

    Legal identity of the provider
  2. 2.

    Data Processing Agreement (Art. 28)

    Documented

    Public DPA for Channel Data. The customer is controller for whistleblowing content; QReportly is processor under documented instructions — not Art. 6(1)(b) for whistleblowers or persons mentioned.

    Data Processing Agreement (Art. 28)
  3. 3.

    Subprocessor list

    Documented

    Public list: Supabase (EU Frankfurt), Vercel, Stripe (US / SCCs), Brevo (EU), optional Google OAuth (US). Marketing pixels, if any, are for the marketing site only — not the reporting channel.

    Subprocessor list
  4. 4.

    Hosting and transfers

    Documented

    Report content and primary production are hosted in the EU. Stripe and Google OAuth may process limited account data outside the EEA under GDPR transfer safeguards. We do not claim EU-only for every ancillary provider.

    Hosting and transfers
  5. 5.

    Technical and organisational measures

    Documented

    TLS in transit, organisation-scoped access, bcrypt password hashes, encrypted TOTP secrets, backup posture as operated by the EU hosting stack. No client-side E2EE of report bodies.

    Technical and organisational measures
  6. 6.

    Retention defaults

    Documented

    Attachments: 180 days after case close. Register: 5 years default, 3 years when the workspace is configured for Germany. The customer as controller may set retention within applicable law.

    Retention defaults
  7. 7.

    Administrator MFA

    Product control

    Authenticator-app TOTP with hashed recovery codes. Required for organisation owner, admin and designated officer. Optional for other members. Enforcement is on the server. Google sign-in does not skip that requirement.

    Administrator MFA
  8. 8.

    ISO 27001, SOC 2, pentest

    Not claimed

    No published ISO 27001, SOC 2, or third-party pentest report. When an independent assessment exists, it will be listed on the Trust Center rather than implied here.

    ISO 27001, SOC 2, pentest
  9. 9.

    Responsible disclosure

    Documented

    Public policy and contact@qreportly.com. Not a paid bug bounty. Do not send exploit PoCs to this pack; follow the disclosure page.

    Responsible disclosure
  10. 10.

    Cookies

    Documented

    Cookie policy for the marketing site and necessary session cookies for the authenticated product. The public reporting channel is designed not to persist reporter IP or fingerprinting data.

    Cookies
  11. 11.

    Availability check

    Product control

    A public reachability probe on this site. Not a historical SLA status.qreportly.com.

    Availability check
  12. 12.

    Breach notification

    Documented

    Personal-data incidents affecting Channel Data are notified to the customer without undue delay, as described in the DPA.

    Breach notification

Related

Trust CenterApplication status