Security & Compliance
InspectQC is built on enterprise-grade infrastructure with security and compliance as core design principles. Learn how we protect your data.
Data Location
Microsoft Azure
United States Data Centers
Encryption
TLS 1.2+
HTTPS for all data in transit
Uptime SLA
99.9%
Enterprise reliability
Security Certifications & Standards
Azure Compliance Framework
- ✓ SOC 2 Type II
- ✓ ISO 27001 / ISO 27018
- ✓ HIPAA & BAA
Additional Standards
- ✓ FedRAMP
- ✓ PCI DSS
- ✓ GDPR & CCPA Ready
Frequently Asked Questions
Where is customer data stored?▼
All customer and inspection data is stored securely in Microsoft Azure data centers located in the United States. This ensures compliance with data residency requirements and provides robust infrastructure redundancy.
What security certifications and compliance standards does Azure meet?▼
Microsoft Azure holds multiple security certifications including SOC 2 Type II, ISO 27001, ISO 27018, HIPAA, FedRAMP, and PCI DSS. Azure undergoes regular third-party audits and maintains compliance with industry-leading security standards. InspectQC leverages these certifications to protect your data.
Is all communication encrypted?▼
Yes. All communication between your browser and InspectQC servers is encrypted using TLS 1.2 or higher (HTTPS). This ensures that data in transit, including login credentials and inspection data, cannot be intercepted or modified by unauthorized parties.
How do you protect customer data?▼
We employ multiple layers of protection: end-to-end HTTPS encryption, role-based access controls (RBAC), multi-factor authentication (MFA), encrypted database storage, regular security audits, and strict access policies. Tenant data is logically isolated, and access is restricted to authorized users only.
What is your data retention policy?▼
Active tenant data is retained for the duration of your subscription. Upon account termination or deletion request, we retain data as required by law for compliance purposes (typically 30-90 days), after which it is securely purged. Backup copies are retained per Azure's standard retention policies.
How is MFA (Multi-Factor Authentication) implemented?▼
InspectQC supports time-based one-time passwords (TOTP) via authenticator apps like Google Authenticator, Microsoft Authenticator, and Authy. MFA is optional but strongly recommended for all user accounts to prevent unauthorized access.
Do you perform security audits and penetration testing?▼
We conduct regular security assessments and are committed to ongoing security improvements. As part of our compliance framework, we work with security partners to identify and address potential vulnerabilities.
How do you handle data breaches?▼
In the unlikely event of a confirmed data breach, we follow responsible disclosure practices and notify affected users without unreasonable delay. We maintain cyber liability insurance and work with security experts to contain and remediate incidents.
Is InspectQC SOC 2 compliant?▼
InspectQC inherits security and compliance benefits from Microsoft Azure's SOC 2 Type II certification. Our infrastructure, data storage, and access controls meet SOC 2 standards. We are committed to obtaining our own SOC 2 Type II certification as we scale.
Can I export my data?▼
Yes. You can export inspection data and reports through the InspectQC portal in standard formats (CSV, PDF). This ensures you maintain portability and ownership of your data.
How often are backups performed?▼
Azure automatically performs continuous backups of all customer data with geographic redundancy. This ensures data is protected against hardware failures and disasters.
What happens if InspectQC experiences an outage?▼
InspectQC is built on Azure's globally distributed infrastructure with automatic failover and redundancy. We maintain a 99.9% uptime SLA. In rare cases of outages, we post real-time updates on our status page and work to restore service as quickly as possible.
How are passwords stored?▼
Passwords are hashed using industry-standard algorithms (bcrypt) with salting. We never store plaintext passwords, and even our engineers cannot retrieve user passwords.
Do you share customer data with third parties?▼
We only share data with carefully vetted subprocessors necessary to operate the service (e.g., payment processors, email providers, hosting providers). These partners are contractually bound to protect your data and are subject to our Data Processing Addendum (DPA).
What should I do if I suspect a security issue?▼
Please report any security concerns to security@inspectqc.com with detailed information. We take all reports seriously and will respond promptly. Please allow reasonable time for us to investigate and address the issue before public disclosure.
Security Questions or Concerns?
If you have security questions, suspect a vulnerability, or need additional compliance documentation (BAA, DPA, SOC 2 reports, etc.), please contact us at security@inspectqc.com.