Security · version 0.1.0 · effective: DRAFT

Certifications

DRAFT — requires review by qualified counsel in each jurisdiction. Not in force.

In one line

We hold no security or privacy certifications yet. This page says what we hold, what we plan, in what order, and why.

The short version

This short version helps you understand the full text. Read the full text for the complete terms.

  • We hold no certifications or audit reports today. We will not claim one until an independent auditor issues it. (Full text, section 1)
  • Our first steps are the UK Cyber Essentials badge and a public cloud-security questionnaire. (Section 2)
  • Next, an independent auditor will check us for a SOC 2 report, and later for ISO/IEC 27001. (Section 2)
  • No one certifies a website as "post-quantum ready." We follow the US standards body NIST's post-quantum methods where our providers support them. (Section 3)
  • Our providers hold their own certifications. That helps, but it does not certify qypu. (Section 4)

Full text

Read the full text (about 2 minutes)

1. Where we are today

qypu is a new, small service. We hold no security, privacy, or AI certification, and no audit report. Each item below is labelled In place or Planned. Planned means we intend to do it; it is not a promise of a date.

2. Our plan, in order

  • Planned: UK Cyber Essentials. A UK government-backed check of five basic controls: firewalls, safe settings, who has access, malware protection, and updates.
  • Planned: A public answer sheet to the Cloud Security Alliance questionnaire (STAR Level 1). It answers the questions IT reviewers ask most.
  • Planned: UK Cyber Essentials Plus. The same five controls, tested hands-on by an assessor.
  • Planned: A SOC 2 report from an independent accounting firm. It first checks that our controls are well designed, then that they worked over several months. We plan to cover security and confidentiality first, and privacy later.
  • Planned: ISO/IEC 27001, the international standard for managing information security.
  • Planned, later: privacy and AI standards such as ISO/IEC 27701 and ISO/IEC 42001, and the EU Cloud Code of Conduct.

When an audit starts, we will say so here. When a report or certificate is issued, we will show its date, its scope, and how to request a copy.

3. Post-quantum

Future quantum computers may break some of today's encryption. There is no recognised certification that a website or service is "post-quantum ready," so we do not claim one. In August 2024, NIST published its first post-quantum standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). We follow them where our providers support them.

  • In place: Connections through Cloudflare can use post-quantum key exchange when your browser supports it.
  • Planned: Post-quantum protection for long-lived secrets, such as account tokens and signed approvals.

4. Our providers

Our hosting, database, network, and AI providers hold their own certifications, such as SOC 2 and ISO/IEC 27001. You can find them on our subprocessors page. Their certificates cover their services, not ours.

5. Rules we follow without a certificate

Some rules have no certificate. We follow them anyway: GDPR and UK GDPR for personal data, and the EU AI Act's rule that AI-made content must be labelled. See AI transparency and security.

Change log

  • 2026-10-10 · 0.1.0 · First version.

Open questions for counsel

We publish these while the page is a draft, so you can see what is not settled yet.

  • Confirm the Cloudflare post-quantum statement against current Cloudflare documentation before publishing.
  • Confirm that naming planned certifications does not create a contractual commitment.

Useful for: Business owners, IT and security reviewers, Platform reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.