Governance & security
These standards apply to every system Qelvyn designs and operates.
1. Security by design
Every system is built on these principles from the start, not as an afterthought: encrypted traffic in transit (HTTPS/TLS), separated environments, and access limited to what each person involved in a project actually needs.
2. Secrets and access management
Credentials, API keys and other technical secrets are never stored in public source code. Access to production systems is limited to people with a direct need for it.
3. Logging
Technical logs are kept only as long as needed for diagnostics and operational security, then deleted according to a retention period defined for each system.
4. Data governance
Data processed on behalf of a client is used only to deliver the service ordered. It is never sold or used for advertising targeting. Details are in our privacy policy.
5. Encryption and data location
Traffic to and from this site is encrypted in transit with TLS, enforced by HSTS. Data at rest is encrypted using the storage-level encryption provided by our infrastructure providers. For client systems, the storage location and encryption arrangement are agreed per project and stated in writing before work starts, because the right answer depends on the data involved and the jurisdiction it belongs to.
6. Hosting and technical subprocessors
This website is hosted by Cloudflare Pages, and DNS is operated by Cloudflare. Inquiries submitted through the contact form are transmitted by Formspree. These are the only third parties that process data through this site; it sets no analytics or advertising cookies, and loads no third-party scripts.
Systems delivered by Qelvyn run on established infrastructure providers. The full list of technical subprocessors relevant to a given project, including their location, is provided to that client before work starts and updated when it changes.
7. Reporting a vulnerability
If you identify a potential security issue in one of our systems, contact us through our Contact page describing what you observed. We acknowledge every legitimate report and address vulnerabilities in order of severity.