How we protect your evidence
You are handing us the artefacts that prove your security program. This page states plainly where they live, who can reach them, how they are encrypted and backed up, and which third parties are involved — so your procurement and security teams can check every claim.
We complete SIG, CAIQ and custom vendor questionnaires under NDA.
Data locations
Compliance portal & database
Oracle Cloud Infrastructure, Mumbai region (India). Application and PostgreSQL run on dedicated Praxis-Q-managed infrastructure.
Client evidence files
Wasabi object storage, ap-southeast-1 (Singapore), in a dedicated Praxis-Q bucket.
Backups
Wasabi object storage, ap-southeast-1 (Singapore), versioned bucket separate from live data.
Transactional email
Amazon SES, ap-south-1 (Mumbai).
Controls in place today
Only what is running now. Nothing on this page is a roadmap item.
Encryption
- TLS 1.3 for every connection to praxis-q.com and portal.praxis-q.com.
- Evidence objects and backups encrypted at rest by the storage provider (AES-256).
- Database volumes encrypted at rest by the cloud provider.
- Credentials and environment configuration are kept out of source control.
Access control
- Role-based access: Client, Auditor and Administrator roles with separate permissions; clients see only their own audits.
- Email one-time-code second factor on every portal login (10-minute expiry, attempt-limited).
- Sessions expire after 12 hours; authentication endpoints are rate-limited.
Audit trail
- Every evidence upload, review decision and status change is logged with user, timestamp and action.
- Certificates carry a QR code and can be verified by anyone at praxis-q.com/verify.
Backups & resilience
- Daily automated database backups (02:00 UTC) to a versioned, separate bucket.
- Rolling 7-day snapshot retention; monthly automated restore tests.
- Backup credentials are write-only; they cannot delete or alter existing backup versions.
Retention & deletion
- Evidence is retained for the engagement plus the period the relevant standard requires, then deleted.
- Clients can request export or deletion of their evidence at any time after an engagement closes.
Our own certifications
We hold the same certifications we help clients achieve. Full certificate scans are linked.
ISO/IEC 27001:2022
Certificate 305026090132IS, valid 1 Sep 2026 – 31 Aug 2029. Issued by QRO Certification LLP, accredited by EGAC (IAF MLA signatory).
View certificate →ISO 9001:2015
Certificate 305026090131Q, valid 1 Sep 2026 – 31 Aug 2029. Issued by QRO Certification LLP, accredited by EGAC (IAF MLA signatory).
View certificate →Subprocessors
Third parties that may process client data as part of delivering the Services.
| Provider | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Portal application and database hosting | Mumbai, India |
| Wasabi Technologies | Evidence and backup object storage | Singapore (ap-southeast-1) |
| Amazon Web Services (SES) | Transactional email | Mumbai, India (ap-south-1) |
| Anthropic | AI evidence and audit scoring, policy drafting (API; not used to train models) | United States |
| Google Workspace | Business email and calendar | Global |
Report a vulnerability
Found something in praxis-q.com or the portal? Email hello@praxis-q.com with steps to reproduce. We acknowledge every report and will not pursue good-faith researchers.
Contracts & data processing
Contracting entities, governing law and liability are in our Terms. A data processing agreement is available on request and forms part of every engagement where we process personal data.