A trust page is worth nothing if you cannot tell which sentences were checked. These are the things a security questionnaire usually asks for that we cannot answer yes to.

  • No certification of our own. Amazon Web Services holds SOC 2, ISO 27001 and other certifications for the infrastructure we run on. Site Qwality holds none. An earlier version of this page was written in a way that blurred the two, and that was our error.
  • No third-party penetration test and no vulnerability-scanning programme. We do not run either today. The responsible-disclosure address below is the route that does exist, and we read it.
  • Encryption at rest is not universal. The stores named above are encrypted. Not every store we operate is, and bringing the remainder into line is scheduled work rather than finished work.
  • Not everything we hold expires on a schedule. Session-replay recordings, and the searchable copy of your logs, metrics and traces, are deleted automatically at the end of their window. A second archival copy of ingested log lines is written to object storage and is not on a deletion schedule today, so it outlives the window that governs the searchable copy. Several operational records have no enforced deletion window either. We would rather say so than imply a uniform policy. Our Data Retention page lists, category by category, either the window our systems enforce or a plain statement that nothing deletes it yet.
  • Our own infrastructure is in the United States. All storage and all compute take place in the AWS us-east-1 region. Every server, every database and every object store that holds your data runs there, and monitoring checks are executed from there as well. We do not offer an EU or UK data-residency option. That sentence is scoped to our own infrastructure on purpose: some of the providers we depend on run global networks, and our Subprocessors page states the processing location for each one and says plainly which are still unresolved.
  • Our content-delivery network terminates connections outside the region, and it is not only public assets. We run six distributions and all six use a price class that includes European edge locations, so a request from Europe is terminated in Europe rather than in Virginia. Two of the six serve public files only: the monitoring script and status-page logos. Two serve status pages, one of ours and one on a customer’s own domain. Two front our internal staff portal, and one of those proxies staff requests to our API, so staff traffic carrying customer account data is terminated at an edge too. None of the six has access logging enabled, so we keep no record at the edge of who requested what. An earlier version of this page called the CDN “the one thing that leaves the region” and described it as caching public assets. That named two of six and it was wrong.

If you are filling in a vendor assessment and an answer here is not enough detail, write to the address below and ask. We would rather send you a specific answer than have you infer a generous one.