Qubi holds the commercial heart of a business: what you buy, from whom, at what price and at what margin. This page states, in terms you can verify, where that data physically sits, how it is kept apart from every other customer's, and which providers we run on. If you need more, the full documentation is available on request.
Database, uploaded documents and backups all sit in Zurich, on AWS infrastructure. Nothing is replicated elsewhere. This is a deliberate configuration, not a default.
Isolation between customers is enforced by PostgreSQL on every row of every query. A mistake in our software cannot leak your data to another restaurant, because it is the database that refuses.
TLS 1.2 or above on every connection, AES-256 at rest across the database, document storage and backups. Credentials you entrust to us for third-party portals are individually encrypted with a key that never leaves the database.
Automatic daily copies, encrypted, kept in the same jurisdiction as the data itself. They are never downloaded and never written to physical media.
No shared accounts. Two-factor authentication is enforced on every administrative account, passwords require at least twelve characters, and any password known to have appeared in a breach is rejected.
Every change to the software passes static analysis, over 2,900 automated tests and a blocking check on dependency vulnerabilities. Availability is measured by an independent service.
Qubi owns no servers and no data centre. The service runs on managed platforms, and every provider that physically holds data is audited by independent assessors.
AWS
Physical infrastructure, Zurich region
SOC 1, SOC 2, SOC 3, ISO 27001
Supabase
Database, document storage, backups
SOC 2 Type II, ISO 27001
Vercel
Application hosting
SOC 2 Type II
Clerk
Authentication and identity
SOC 2 Type II
OpenAI
AI features
SOC 2 Type II
Security policies, the business continuity plan, the sub-processor list and a data processing agreement are available on request under NDA. We are glad to complete supplier assessment questionnaires.
If you have found a vulnerability, write to sicurezza@qubisoftware.com. We acknowledge within one working day and we take no action against anyone reporting in good faith.
Live service statusWe complete security questionnaires, sign non-disclosure and data processing agreements, and are glad to arrange a technical call with whoever has to give the approval.
Talk to us