Trusted. Safe.Secure.
TrustCV Ltd takes the security of the Qsend platform, and of every piece of data entrusted to us by our customers, seriously - not just the data we host on your behalf, but any data we hold about you as a customer or individual. Report a security concern: security@qsend.cc
Encryption
Data transmitted between your device and the Qsend platform is encrypted in transit using industry-standard TLS encryption. Data at rest within our databases and backups is encrypted using industry-standard encryption algorithms. Our website and applications are served exclusively over HTTPS.
Hosting and infrastructure
Qsend is hosted on infrastructure provided by reputable cloud providers which maintain independently audited certifications including ISO 27001 and SOC 2. Our infrastructure is designed with redundancy, network segmentation, and monitoring to reduce the risk and impact of any single point of failure.
Access control
Access to production systems and customer data is restricted to authorised personnel on a least-privilege, need-to-know basis, and is logged and reviewed periodically. We support and encourage the use of strong, unique passwords, and offer (or are working towards offering) multi-factor authentication (MFA) for customer accounts. You are responsible for enabling and maintaining MFA where it is available, and for keeping your own credentials confidential.
Monitoring and testing
We monitor our systems for availability, performance, and security events on an ongoing basis. We periodically review our security posture and, where appropriate, engage independent third parties to carry out vulnerability scanning and penetration testing of our platform.
Staff practices
Our staff and contractors are subject to confidentiality obligations and are trained in data protection and security best practice appropriate to their role. Access to customer data is granted only where necessary to perform support, development, or operational duties, and is revoked promptly when no longer required.
Sub-processors
We use a limited number of vetted third-party sub-processors (for example, cloud hosting, email delivery, and analytics providers) to help us deliver the Services. Each sub-processor is subject to contractual obligations regarding confidentiality, security, and data protection. A list of key sub-processors is available on request.
Incident response
We maintain procedures to identify, investigate, and respond to security incidents. Where a personal data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, we will notify affected customers without undue delay and in accordance with our obligations under applicable data protection law, and will support customers in meeting their own regulatory notification obligations where we are the processor.
Your responsibilities
Security is a shared responsibility. You are responsible for: keeping your account credentials confidential; enabling MFA where available; ensuring only authorised personnel have access to your Qsend account; and promptly notifying us of any suspected unauthorised access, at support@qsend.cc.
No guarantee and limitation of liability
While we implement and maintain the measures described in this policy, no system can be guaranteed to be 100% secure, and no method of electronic transmission or storage is completely secure. To the maximum extent permitted by law, we make no warranty, express or implied, that the Services are immune from unauthorised access, and our liability in connection with any security incident is subject to the limitation of liability set out in our Terms and Conditions.
Further information & disclosure
For details of how we collect, use, and protect personal data, see our Privacy Policy and Cookie Policy. To report a security concern or suspected vulnerability, please contact security@qsend.cc. We appreciate responsible disclosure and will respond to genuine reports as a priority.