A unified platform for HR, payroll, operations, CRM and AI-assisted work. Explore the platform
QTechDL Quantum Technos
Security by Design

Business data deserves clear controls.

DLQ Technos uses layered technical and organisational controls to protect customer information and restrict unauthorised access. This page states what is in place and what is not.

Certifications: what we hold today

We do not currently hold SOC 2 or ISO/IEC 27001 certification. Our security programme is structured with reference to ISO/IEC 27001 principles, but no independent audit has been completed and no certificate exists. We will say so here the day that changes, with the scope and the certifying body named.

If your procurement process requires a certification we do not hold, tell us early. We would rather lose the deal than misrepresent our position.

Controls in place

Tenant isolation

Row-level security in the database separates each company's data. Enforced by the database, not by application code that could be bypassed.

Encryption

In transit and at rest. Government identity numbers are encrypted separately from the rest of the record.

Role-based access

Per-module, per-action permissions. Branch access is a list, so a regional role sees only its own sites.

Audit trail

Every create, edit and delete recorded with the person, the time and the record — readable inside the product, not just in a log file.

Two-factor sign-in

Optional, per account.

Access revocation

An exited employee loses access immediately, without their history being deleted.

Backups

Managed by our infrastructure provider, with point-in-time recovery.

Least-privilege service access

Server-side keys never reach the browser.

Being built

Listed because a security page that only shows strengths tells a buyer nothing they can use.

Backup restoration testingBackups exist. A documented restore drill does not yet.
Documented risk assessmentBeing written.
Vulnerability management processBeing defined.
Incident response planBeing written.
Business continuity planBeing written.
Supplier risk reviewsSubprocessors are published; formal reviews are not yet in place.
Security awareness trainingNot yet formalised.
Independent penetration testNot yet commissioned.

Reporting a vulnerability

If you believe you have found a security issue, email admin@dlqtechnos.com with enough detail to reproduce it. We will acknowledge within one working day. Please give us a reasonable window to fix it before disclosing publicly.