Logo
Home
Pricing
Contact
Security

Where your data lives, and who can see it

Qubi holds the commercial heart of a business: what you buy, from whom, at what price and at what margin. This page states, in terms you can verify, where that data physically sits, how it is kept apart from every other customer's, and which providers we run on. If you need more, the full documentation is available on request.

Your data is held in Switzerland

Database, uploaded documents and backups all sit in Zurich, on AWS infrastructure. Nothing is replicated elsewhere. This is a deliberate configuration, not a default.

Separated by the database, not the code

Isolation between customers is enforced by PostgreSQL on every row of every query. A mistake in our software cannot leak your data to another restaurant, because it is the database that refuses.

Encrypted in transit and at rest

TLS 1.2 or above on every connection, AES-256 at rest across the database, document storage and backups. Credentials you entrust to us for third-party portals are individually encrypted with a key that never leaves the database.

Backed up daily

Automatic daily copies, encrypted, kept in the same jurisdiction as the data itself. They are never downloaded and never written to physical media.

Named access, verified

No shared accounts. Two-factor authentication is enforced on every administrative account, passwords require at least twelve characters, and any password known to have appeared in a breach is rejected.

Continuously checked

Every change to the software passes static analysis, over 2,900 automated tests and a blocking check on dependency vulnerabilities. Availability is measured by an independent service.


Who we run on

Qubi owns no servers and no data centre. The service runs on managed platforms, and every provider that physically holds data is audited by independent assessors.

AWS

Physical infrastructure, Zurich region

SOC 1, SOC 2, SOC 3, ISO 27001


Supabase

Database, document storage, backups

SOC 2 Type II, ISO 27001


Vercel

Application hosting

SOC 2 Type II


Clerk

Authentication and identity

SOC 2 Type II


OpenAI

AI features

SOC 2 Type II

How we work

  • Your data trains no AI model. We train none and fine-tune none, and the provider we use does not employ data submitted through its interface for training.
  • No production data is used for development or testing: the environments are separate projects with distinct databases and credentials.
  • No change reaches production without passing the automated checks, and every release can be rolled back instantly.
  • If a breach affects your data we tell you within 24 hours, with what we know at that point and with updates through to a written final report.
  • You can export everything that is yours, in open formats, at any time. At the end of the relationship your data is deleted and we confirm it in writing.

Full documentation

Security policies, the business continuity plan, the sub-processor list and a data processing agreement are available on request under NDA. We are glad to complete supplier assessment questionnaires.

Reporting a problem

If you have found a vulnerability, write to sicurezza@qubisoftware.com. We acknowledge within one working day and we take no action against anyone reporting in good faith.

Live service status

Do you need to assess us as a supplier?

We complete security questionnaires, sign non-disclosure and data processing agreements, and are glad to arrange a technical call with whoever has to give the approval.

Talk to us