Trust centre · role track

For IT and security reviewers

DRAFT — requires review by qualified counsel in each jurisdiction. Not in force.

You are checking qypu for a customer, an investor, or a partner. Every control is labelled In place or Planned. We hold no certifications and say so.

Read these first

  1. Security Overview

    The security controls qypu has in place today, the ones still planned, and the gaps we know about. We hold no security certification yet.

  2. Certifications

    We hold no security or privacy certifications yet. This page says what we hold, what we plan, in what order, and why.

  3. Subprocessors

    The companies that process customer data for us, what they do, where, and what data they touch. We give 30 days' notice before adding one.

  4. Data Processing Addendum

    The contract terms that apply when we process personal data for your business. It covers instructions, security, subprocessors, breaches, transfers, and deletion.

  5. Incident and Breach Notification

    What we do when something goes wrong with your data, and how fast we tell you and the regulators.

  6. Vulnerability Disclosure Policy

    How to report a security problem to us, what we promise in return, and the rules that keep your research safe and legal.

Also useful

  • Terms of Service: The rules for using qypu. You own your content and sign every post; we run the service with care and tell you before we change these terms.
  • Privacy Notice: What personal data we collect, why, who helps us process it, how long we keep it, and how you use your rights, with annexes for each country we serve.
  • Cookie Notice: We use only the cookies the site needs to work. If we ever add optional cookies, we will ask first, and "No" will be as easy as "Yes".
  • AI Transparency and Disclosure: Where we use AI, which providers we use, how we label AI content for your audience, and what AI is never allowed to do on its own.
  • Account Connection and Authorisation: How you connect your social channels to qypu, what access you give us, what we record, and how to take it back at any time.
  • Data Retention and Deletion: How long we keep each kind of data, and how you, your audience, or a platform can ask us to delete it.
  • Post-Quantum Readiness: How we prepare our encryption for future quantum computers, what is in place today, what is planned, and what nobody can do yet. There is no recognised post-quantum certification for a website, and we do not claim one.
  • Complaints and Contact: How to reach us, how we handle complaints and appeals, and where to go if we do not put things right.
  • Service Levels (draft): Our draft targets for uptime, support response, and publishing. They are aims, not guarantees, until we can measure them reliably.
  • Standard Agreement for Small-Business AI and Managed Services (v0.1 draft): A proposal for a short, open, plain-English standard contract between a small business and any AI or managed-services provider, built like Y Combinator's SAFE: one cover sheet of choices, fixed standard terms, and country modules.
  • Modern Slavery and Supply Chain: The law does not yet require us to publish a modern slavery statement. We still set basic standards for the suppliers we use.
  • Government and Law Enforcement Requests: We hand over customer data only when the law truly requires it, we push back on overbroad requests, and we tell you unless we are legally barred.
  • Who Does What: Keeping your business safe online is a shared job. This page shows clearly what qypu does, what you do, and what the platforms and our providers do.

Files you can check automatically