Skip to content
Qelvyn
Our standards

Governance & security

These standards apply to every system Qelvyn designs and operates.

1. Security by design

Every system is built on these principles from the start, not as an afterthought: encrypted traffic in transit (HTTPS/TLS), separated environments, and access limited to what each person involved in a project actually needs.

2. Secrets and access management

Credentials, API keys and other technical secrets are never stored in public source code. Access to production systems is limited to people with a direct need for it.

3. Logging

Technical logs are kept only as long as needed for diagnostics and operational security, then deleted according to a retention period defined for each system.

4. Data governance

Data processed on behalf of a client is used only to deliver the service ordered. It is never sold or used for advertising targeting. Details are in our privacy policy.

5. Hosting and technical subprocessors

Systems delivered by Qelvyn run on established infrastructure providers. The list of technical subprocessors relevant to a given project is shared with that client before work starts.

6. Reporting a vulnerability

If you identify a potential security issue in one of our systems, contact us through our Contact page describing what you observed. We acknowledge every legitimate report and address vulnerabilities in order of severity.