Security
Last updated: 19 June 2026. We believe in being straight about what's in place today versus what's on the roadmap — so this page distinguishes the two clearly.
What this covers
Qualitronyx is in active development. Today, qualitronyx.com is a marketing website with sign-up and free-template forms. It does not yet store your plant's audit records or CAPA data — that's the product we're building. This page describes how we secure the site and the limited data we collect now, plus the controls we're building for the platform.
Data we collect today
- Only what you submit through our forms — typically your name, work email, company and the audit standard you select.
- Standard server logs (e.g. IP address, request data) kept for security and reliability.
- Analytics data only with your consent (see our Privacy Policy). We use Google Consent Mode v2 — nothing analytics- or advertising-related loads until you accept.
We do not sell your personal data.
How it's protected
- Encryption in transit. The entire site is served over HTTPS (TLS) with automatically renewed certificates. Plain HTTP is redirected to HTTPS.
- Hardened hosting. Hosted on a reputable cloud provider behind a firewall that exposes only the ports we need (HTTPS and administrative SSH), with automated intrusion prevention.
- Least-privilege access. Form submissions are stored in an access-restricted location on the server; administrative access is limited and key-based.
- Minimal data. We collect only what we need to respond to you and provide what you requested.
On our roadmap (with the platform)
As Qualitronyx grows from a marketing site into a product that stores your audit data, we are building toward:
- Role-based access control and a complete, tamper-evident audit trail.
- Encryption at rest and automated, tested backups with defined recovery objectives.
- Self-service data export and deletion.
- An electronic-signature path aligned with 21 CFR Part 11 expectations.
- Documented sub-processors and data-residency options.
These are commitments we're working toward, not certifications we hold today. We will not claim a compliance certification (such as SOC 2 or ISO 27001) unless and until we have actually achieved it.
Responsible disclosure
If you believe you've found a security vulnerability, please email us at [security@qualitronyx.com] with the details. We'll acknowledge your report, investigate promptly, and we won't pursue action against good-faith research that respects user privacy and avoids service disruption.
Contact
For privacy questions and your data rights, see our Privacy Policy. For anything else, email [security@qualitronyx.com].