Encryption in transit and at rest
Traffic is encrypted with current TLS. Stored data and backups are encrypted at rest, with managed key rotation.
Quecorex is built to protect health information and to fit the rules of the country it runs in. This page explains how we handle data protection, security and interoperability, and what is configured per jurisdiction.
This is a plain-language summary for evaluation. The binding terms are in your service agreement and data processing addendum.
The platform is built around the principles common to modern privacy law, so the same design holds wherever it is deployed.
These controls are part of the product and its infrastructure, not optional add-ons.
Traffic is encrypted with current TLS. Stored data and backups are encrypted at rest, with managed key rotation.
Role-based access per site with least-privilege defaults, and configurable password, multi-factor and session-timeout policies.
Every create, edit, view and delete of a record is written to an append-only log that users cannot alter.
Each organisation data is isolated, and access is scoped to the site and role of the signed-in user.
Automated backups with off-site and separate-region copies, and a documented, tested recovery plan.
Platform activity is monitored, with alerting on unusual access patterns and administrative actions.
Uploaded files are validated, stored in private object storage and served through short-lived signed links.
Changes go through code review and automated checks before release, and dependencies are kept current.
Built on international health-data standards so it exchanges data with the systems and instruments you already run.
The regulatory layer is set to your country and your health authority, so the platform fits your regulator rather than the other way round.
A defined process runs on discovery of a security or privacy incident. Notification timelines follow the rules of your jurisdiction.
On discovery, the event is triaged and its severity and likely scope are assessed.
The first priority is to limit exposure and stop any ongoing access.
We establish the scope, the cause, and which data and organisations are affected.
Affected organisations and regulators are notified within the timelines your jurisdiction requires.
A written review records what happened and the corrective actions taken.
The platform, its infrastructure, its code, encryption, backups, monitoring and the security of the hosting environment.
Your users and their roles, local configuration, who is granted access to which records, and staff training. Onboarding sets out where the line sits.
We respond to data-protection and security enquiries, including requests from patients exercising their rights through a provider.