Security and reliability
Your own environment, secured and run for you.
Every QuellDesk customer runs in a dedicated environment with private networking, a web application firewall and encryption in transit and at rest. We run it, and the controls are on in every tier.
Infrastructure
Isolated by design, not by a filter.
Your environment is yours alone. That is the simplest answer to where your data lives and who can reach it.
Dedicated to you
Your own environment on AWS. Your data never shares a deployment with another customer’s.
Private networking
Your environment runs on private networking, as standard in every tier.
Web application firewall
A web application firewall stands in front of your environment.
Encrypted in transit and at rest
HTTPS with HSTS on the way in. Encrypted disks and encrypted backups at rest.
Scales with load
Containers that scale with demand, on PostgreSQL 16.
Run for you
Monitoring, patching, upgrades and backups are done by the QuellDesk team.
Application security
Controls that are on by default.
Built into the product rather than sold as an add-on, and the same in every tier.
Customer data separation
Enforced on every query, so one customer’s records cannot reach another.
Encryption everywhere
HTTPS with HSTS in transit. Encrypted disks and backups at rest. Secrets sealed with AES-256.
Strong sign-in
Two-factor sign-in, and single sign-on with OpenID Connect.
Passwords and lockout
Passwords hashed with bcrypt, and accounts locked after repeated failed attempts.
Protected writes, limited requests
Protection on every write, and request limits that slow down abuse.
Tamper proof audit trail
Who changed what, and when, with the values before and after.
Private network and firewall
Your environment sits on private networking behind a web application firewall.
Locked dependencies
Every dependency version is pinned, so what was tested is what runs.
Measured, not asserted
Checked against the standards that matter.
- automated tests run on every change
- 8,000+
- checked automatically on every release
- Every screen
- accessibility target for the whole product
- WCAG 2.2 AA
- and CWE Top 25 (2025): the product is measured against both
- OWASP Top 10
The product is measured against the OWASP Top 10 (2025) and the MITRE CWE Top 25 (2025). More than 8,000 automated tests run on every change, every screen is checked automatically on every release, and WCAG 2.2 AA is the accessibility target.
Reliability
Recovery objectives, written down per tier.
Every tier is monitored, patched, upgraded and backed up for you. The tiers differ in how much they can survive and how fast they recover.
| Tier | Monthly uptime | Most data at risk | Time to restore | Keeps running if | Support hours |
|---|---|---|---|---|---|
| Standard | 99.5% | 1 hour | 8 hours | a server fails | 8x5, US Eastern |
| Business | 99.9% | 15 minutes | 4 hours | a data centre zone fails | 12x5, urgent issues 24x7 |
| Premium | 99.95% | 5 minutes | 1 hour | a whole region fails | 24x7, every issue |
Your data
Yours, separated, and accounted for.
Separated on every query. Customer data separation is enforced on every query, not left to each screen to filter.
Every change accounted for. A tamper proof audit trail records who changed what, with the values before and after.
Yours to take. You can ask for a complete export of your data in open formats.
Bring your security questions to the demo.
Walk through the environment, the controls and the recovery objectives with the team that runs them.