Security & trust · Last updated 23 September 2026

How we protect your evidence

You are handing us the artefacts that prove your security program. This page states plainly where they live, who can reach them, how they are encrypted and backed up, and which third parties are involved — so your procurement and security teams can check every claim.

We complete SIG, CAIQ and custom vendor questionnaires under NDA.

Data locations

Compliance portal & database

Oracle Cloud Infrastructure, Mumbai region (India). Application and PostgreSQL run on dedicated Praxis-Q-managed infrastructure.

Client evidence files

Wasabi object storage, ap-southeast-1 (Singapore), in a dedicated Praxis-Q bucket.

Backups

Wasabi object storage, ap-southeast-1 (Singapore), versioned bucket separate from live data.

Transactional email

Amazon SES, ap-south-1 (Mumbai).

Controls in place today

Only what is running now. Nothing on this page is a roadmap item.

Encryption

  • TLS 1.3 for every connection to praxis-q.com and portal.praxis-q.com.
  • Evidence objects and backups encrypted at rest by the storage provider (AES-256).
  • Database volumes encrypted at rest by the cloud provider.
  • Credentials and environment configuration are kept out of source control.

Access control

  • Role-based access: Client, Auditor and Administrator roles with separate permissions; clients see only their own audits.
  • Email one-time-code second factor on every portal login (10-minute expiry, attempt-limited).
  • Sessions expire after 12 hours; authentication endpoints are rate-limited.

Audit trail

  • Every evidence upload, review decision and status change is logged with user, timestamp and action.
  • Certificates carry a QR code and can be verified by anyone at praxis-q.com/verify.

Backups & resilience

  • Daily automated database backups (02:00 UTC) to a versioned, separate bucket.
  • Rolling 7-day snapshot retention; monthly automated restore tests.
  • Backup credentials are write-only; they cannot delete or alter existing backup versions.

Retention & deletion

  • Evidence is retained for the engagement plus the period the relevant standard requires, then deleted.
  • Clients can request export or deletion of their evidence at any time after an engagement closes.

Our own certifications

We hold the same certifications we help clients achieve. Full certificate scans are linked.

Subprocessors

Third parties that may process client data as part of delivering the Services.

ProviderPurposeLocation
Oracle Cloud InfrastructurePortal application and database hostingMumbai, India
Wasabi TechnologiesEvidence and backup object storageSingapore (ap-southeast-1)
Amazon Web Services (SES)Transactional emailMumbai, India (ap-south-1)
AnthropicAI evidence and audit scoring, policy drafting (API; not used to train models)United States
Google WorkspaceBusiness email and calendarGlobal

Report a vulnerability

Found something in praxis-q.com or the portal? Email hello@praxis-q.com with steps to reproduce. We acknowledge every report and will not pursue good-faith researchers.

Contracts & data processing

Contracting entities, governing law and liability are in our Terms. A data processing agreement is available on request and forms part of every engagement where we process personal data.