For DPO / IT reviewers
Enterprise security evaluation pack
A single checklist of controls we actually publish. Use it in vendor questionnaires. We do not attach certificates we do not hold.
Qreportly LLC · 30 N Gould St Ste R, Sheridan, WY 82801, USA
Share this URL with your DPO, IT security, or procurement reviewer. Each item links to the source page. Negative answers (no ISO 27001, no SOC 2, no published pentest) are listed on purpose.
- 1.
Legal identity of the provider
DocumentedQreportly LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA — Wyoming LLC. No EU VAT / CUI is published because none is registered. Terms state governing law with a GDPR / Member State carve-out for channel data.
Legal identity of the provider → - 2.
Data Processing Agreement (Art. 28)
DocumentedPublic DPA for Channel Data. The customer is controller for whistleblowing content; QReportly is processor under documented instructions — not Art. 6(1)(b) for whistleblowers or persons mentioned.
Data Processing Agreement (Art. 28) → - 3.
Subprocessor list
DocumentedPublic list: Supabase (EU Frankfurt), Vercel, Stripe (US / SCCs), Brevo (EU), optional Google OAuth (US). Marketing pixels, if any, are for the marketing site only — not the reporting channel.
Subprocessor list → - 4.
Hosting and transfers
DocumentedReport content and primary production are hosted in the EU. Stripe and Google OAuth may process limited account data outside the EEA under GDPR transfer safeguards. We do not claim EU-only for every ancillary provider.
Hosting and transfers → - 5.
Technical and organisational measures
DocumentedTLS in transit, organisation-scoped access, bcrypt password hashes, encrypted TOTP secrets, backup posture as operated by the EU hosting stack. No client-side E2EE of report bodies.
Technical and organisational measures → - 6.
Retention defaults
DocumentedAttachments: 180 days after case close. Register: 5 years default, 3 years when the workspace is configured for Germany. The customer as controller may set retention within applicable law.
Retention defaults → - 7.
Administrator MFA
Product controlAuthenticator-app TOTP with hashed recovery codes. Required for organisation owner, admin and designated officer. Optional for other members. Enforcement is on the server. Google sign-in does not skip that requirement.
Administrator MFA → - 8.
ISO 27001, SOC 2, pentest
Not claimedNo published ISO 27001, SOC 2, or third-party pentest report. When an independent assessment exists, it will be listed on the Trust Center rather than implied here.
ISO 27001, SOC 2, pentest → - 9.
Responsible disclosure
DocumentedPublic policy and contact@qreportly.com. Not a paid bug bounty. Do not send exploit PoCs to this pack; follow the disclosure page.
Responsible disclosure → - 10.
Cookies
DocumentedCookie policy for the marketing site and necessary session cookies for the authenticated product. The public reporting channel is designed not to persist reporter IP or fingerprinting data.
Cookies → - 11.
Availability check
Product controlA public reachability probe on this site. Not a historical SLA status.qreportly.com.
Availability check → - 12.
Breach notification
DocumentedPersonal-data incidents affecting Channel Data are notified to the customer without undue delay, as described in the DPA.
Breach notification →