For IT and security reviewers
You are checking qypu for a customer, an investor, or a partner. Every control is labelled In place or Planned. We hold no certifications and say so.
Read these first
- Security Overview
The security controls qypu has in place today, the ones still planned, and the gaps we know about. We hold no security certification yet.
- Certifications
We hold no security or privacy certifications yet. This page says what we hold, what we plan, in what order, and why.
- Subprocessors
The companies that process customer data for us, what they do, where, and what data they touch. We give 30 days' notice before adding one.
- Data Processing Addendum
The contract terms that apply when we process personal data for your business. It covers instructions, security, subprocessors, breaches, transfers, and deletion.
- Incident and Breach Notification
What we do when something goes wrong with your data, and how fast we tell you and the regulators.
- Vulnerability Disclosure Policy
How to report a security problem to us, what we promise in return, and the rules that keep your research safe and legal.
Also useful
- Terms of Service: The rules for using qypu. You own your content and sign every post; we run the service with care and tell you before we change these terms.
- Privacy Notice: What personal data we collect, why, who helps us process it, how long we keep it, and how you use your rights, with annexes for each country we serve.
- Cookie Notice: We use only the cookies the site needs to work. If we ever add optional cookies, we will ask first, and "No" will be as easy as "Yes".
- AI Transparency and Disclosure: Where we use AI, which providers we use, how we label AI content for your audience, and what AI is never allowed to do on its own.
- Account Connection and Authorisation: How you connect your social channels to qypu, what access you give us, what we record, and how to take it back at any time.
- Data Retention and Deletion: How long we keep each kind of data, and how you, your audience, or a platform can ask us to delete it.
- Post-Quantum Readiness: How we prepare our encryption for future quantum computers, what is in place today, what is planned, and what nobody can do yet. There is no recognised post-quantum certification for a website, and we do not claim one.
- Complaints and Contact: How to reach us, how we handle complaints and appeals, and where to go if we do not put things right.
- Service Levels (draft): Our draft targets for uptime, support response, and publishing. They are aims, not guarantees, until we can measure them reliably.
- Standard Agreement for Small-Business AI and Managed Services (v0.1 draft): A proposal for a short, open, plain-English standard contract between a small business and any AI or managed-services provider, built like Y Combinator's SAFE: one cover sheet of choices, fixed standard terms, and country modules.
- Modern Slavery and Supply Chain: The law does not yet require us to publish a modern slavery statement. We still set basic standards for the suppliers we use.
- Government and Law Enforcement Requests: We hand over customer data only when the law truly requires it, we push back on overbroad requests, and we tell you unless we are legally barred.
- Who Does What: Keeping your business safe online is a shared job. This page shows clearly what qypu does, what you do, and what the platforms and our providers do.