Security and reliability

Your own environment, secured and run for you.

Every QuellDesk customer runs in a dedicated environment with private networking, a web application firewall and encryption in transit and at rest. We run it, and the controls are on in every tier.

Your agents and customers, over HTTPS
Web application firewall
Your dedicated environment, private network
QuellDeskContainers that scale
PostgreSQL 16Encrypted at rest
BackupsEncrypted, run for you
Monitored, patched and upgraded by the QuellDesk team

Infrastructure

Isolated by design, not by a filter.

Your environment is yours alone. That is the simplest answer to where your data lives and who can reach it.

Dedicated to you

Your own environment on AWS. Your data never shares a deployment with another customer’s.

Private networking

Your environment runs on private networking, as standard in every tier.

Web application firewall

A web application firewall stands in front of your environment.

Encrypted in transit and at rest

HTTPS with HSTS on the way in. Encrypted disks and encrypted backups at rest.

Scales with load

Containers that scale with demand, on PostgreSQL 16.

Run for you

Monitoring, patching, upgrades and backups are done by the QuellDesk team.

Application security

Controls that are on by default.

Built into the product rather than sold as an add-on, and the same in every tier.

Customer data separation

Enforced on every query, so one customer’s records cannot reach another.

Encryption everywhere

HTTPS with HSTS in transit. Encrypted disks and backups at rest. Secrets sealed with AES-256.

Strong sign-in

Two-factor sign-in, and single sign-on with OpenID Connect.

Passwords and lockout

Passwords hashed with bcrypt, and accounts locked after repeated failed attempts.

Protected writes, limited requests

Protection on every write, and request limits that slow down abuse.

Tamper proof audit trail

Who changed what, and when, with the values before and after.

Private network and firewall

Your environment sits on private networking behind a web application firewall.

Locked dependencies

Every dependency version is pinned, so what was tested is what runs.

Measured, not asserted

Checked against the standards that matter.

automated tests run on every change
8,000+
checked automatically on every release
Every screen
accessibility target for the whole product
WCAG 2.2 AA
and CWE Top 25 (2025): the product is measured against both
OWASP Top 10

The product is measured against the OWASP Top 10 (2025) and the MITRE CWE Top 25 (2025). More than 8,000 automated tests run on every change, every screen is checked automatically on every release, and WCAG 2.2 AA is the accessibility target.

Reliability

Recovery objectives, written down per tier.

Every tier is monitored, patched, upgraded and backed up for you. The tiers differ in how much they can survive and how fast they recover.

Uptime, recovery point and recovery time objectives, resilience and support hours for each service tier
Tier Monthly uptime Most data at risk Time to restore Keeps running if Support hours
Standard 99.5% 1 hour 8 hours a server fails 8x5, US Eastern
Business 99.9% 15 minutes 4 hours a data centre zone fails 12x5, urgent issues 24x7
Premium 99.95% 5 minutes 1 hour a whole region fails 24x7, every issue

Your data

Yours, separated, and accounted for.

  • Separated on every query. Customer data separation is enforced on every query, not left to each screen to filter.

  • Every change accounted for. A tamper proof audit trail records who changed what, with the values before and after.

  • Yours to take. You can ask for a complete export of your data in open formats.

Bring your security questions to the demo.

Walk through the environment, the controls and the recovery objectives with the team that runs them.

30 minute demo Tailored to your setup

Book a demo