New: AI Compliance Intelligence — automate gap analysis across 30+ standards. Read the announcement
Security & Trust

Security is not a feature. It’s the foundation.

Independently audited, continuously monitored, and built on zero-trust principles. Your data is protected by the same controls you’re using Quays to enforce.

Certifications & attestations

SOC 2 Type II

Annual third-party audit covering security, availability, confidentiality, and processing integrity.

ISO 27001

Information Security Management System certified by an accredited body. Annual surveillance audits.

GDPR

Full compliance with EU General Data Protection Regulation. EU data residency available.

HIPAA

Business Associate Agreements available for covered entities. Aligned with HITECH security rule.

CCPA

California Consumer Privacy Act compliant. Full data subject rights honored.

21 CFR Part 11

Validated environments for life sciences customers. Compliant e-signatures and audit trails.

Defense in depth

Compliance vulnerability scanning

AI-powered analysis continuously scans your QMS for missing controls, outdated SOPs, untrained personnel, and overdue reviews — the equivalent of CVE scanning, but for compliance gaps.

  • ISO 9001 / 13485 / 27001 frameworks
  • 21 CFR Part 11 controls
  • GxP requirements
  • GDPR data handling

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit. Customer-managed encryption keys (BYOK) available on Enterprise. Field-level encryption for PII and PHI.

  • AES-256 at rest
  • TLS 1.3 in transit
  • BYOK / customer-managed keys
  • Field-level PII encryption

Infrastructure security

Multi-region active-active deployment on AWS. Hardened images. Continuous vulnerability scanning. Quarterly third-party penetration testing.

  • Multi-region AWS
  • CIS-hardened images
  • Continuous vuln scanning
  • Quarterly pen tests

Identity & access

SAML 2.0 SSO with any IdP. SCIM 2.0 auto-provisioning. Granular RBAC down to the field. IP allow-listing. MFA enforcement and session controls.

  • SAML 2.0 + SCIM 2.0
  • Field-level RBAC
  • IP allow-listing
  • Mandatory MFA

Get the details

Security whitepaper

32 pages on architecture, controls, and certifications.

SOC 2 Type II report

Available under NDA via the Trust Center.

Pen test summary

Most recent third-party penetration test results.

DPA & BAA templates

Pre-signed Data Processing Addendum and HIPAA BAA.

security@quays.io

Responsible disclosure

We welcome security research. If you believe you’ve found a vulnerability, please email security@quays.io with details. We commit to acknowledging within 48 hours and providing a triage update within 5 business days. Coordinated disclosure preferred. Public Bug Bounty live on HackerOne.

Unlock world-class
quality management

Join 2,000+ organizations that trust Quays to manage quality, compliance, and continuous improvement. See how it works for your team.