Talk to an expert! Fill in the fields below!
          
security-and-compliance-Qualiex

Security and Compliance

The Qualiex is committed to the security of our clients’ information. WWe are certified toISO 9001, ISO 27001, ISO 27701, and ISO 27018,ensuring international standards for quality management, information security, and privacy.

Learn about Qualiex's security policies

Accommodations

ForLogic implements comprehensive technical measures to protect Qualiex's systems and data. The platform is hosted on Microsoft Azure, which features world-class infrastructure certified for security and privacy.

Firewall

Network security is ensured by firewalls with continuously updated rules, an active WAF (Web Application Firewall), and intrusion detection systems (IDS) for monitoring
suspicious traffic

Safety Tests

Security tests are conducted every six months or with each major update, following the PTES and OWASP Top 10 methodologies, with secure coding practices, code reviews, and tests based on OWASP WSTG. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256, managed by Microsoft).

Backups

ForLogic has formal backup and disaster recovery policies, including a tested disaster recovery plan, a contractual uptime guarantee of 99%, and geographic redundancy between Brazil and the U.S. 

FAQ - Frequently Asked Questions

Yes. Data may be shared with third-party service providers necessary for the operation of the service,
including SendGrid (email delivery), HubSpot (CRM/support), and Microsoft (cloud infrastructure).

Yes. The system processes personal data such as name, email address, and role-based access control (RBAC) informati
, which is necessary for the technical operation of the system. Only the minimum amount of personal information
required is collected and used.

The data is stored on AWS and Microsoft Azure servers located in Brazil, with
geo-replication to the United States, ensuring redundancy and continuity.

Data in transit is encrypted using TLS, version 1.2 or higher. Data at rest is encrypted
using AES-256-bit encryption, managed by Microsoft Azure.

Yes. The APIs use strong authentication mechanisms such as OAuth2 or equivalent, with granular control over permissions and scopes. Unauthorized calls are automatically rejected and logged for auditing and security purposes.

The system supports SSO via Microsoft Entra ID (Azure AD). Integration with SAML is currently in the
deployment phase.

Authentication is protected by multiple layers:

  • Login with username and password, with support for MFA (multi-factor authentication) and SSO.
    Restricted access via VPN, with control based on authorized IP addresses and devices.
  • Logs of all access attempts: successful logins, failed attempts, date, time, IP address, and history of
    activities.
  • Native audit trail that records the user's ID, UTC timestamp, previous value, and new value
    for each change—cannot be disabled.

Passwords are stored in hashed and salted form in accordance with industry best practices. Vendor-standard passwords and other standard security parameters are implemented in the solution. The system also offers customizable password policy configuration at the organizational level, allowing customers to define requirements for complexity, minimum length, and password change frequency according to their specific needs.

Logs are retained for a maximum of 6 months. Access is controlled, and audit logs are available for review. If a customer wishes to have the logs deleted early or exported before this period expires, they must submit a formal request to ForLogic, in accordance with the current data retention and disposal policy.

Backups are performed daily using a differential strategy for application files and full/differential/
log backups for databases:

  • Encrypted backups stored with geo-redundancy between Brazil (primary) and the U.S. (secondary) on the Azure
    .
  • Recovery Time Objective (RTO): 2 hours.
  • Recovery Point Objective (RPO): 1 hour.
  • A documented Disaster Recovery Plan that includes recovery strategies, replication, responsibilities, and periodic validation tests.

Yes. ForLogic guarantees 99% uptime. Technical and operational support have SLAs with response times defined according to the urgency level of each request.

Support is provided via chat and email, with SLAs and response times based on the urgency of the request. Currently, there are no different support plan tiers—all customers receive the same level of service.

Yes. ForLogic, the company that developed Qualiex, holds the following certifications:

  • ISO 9001 — Quality Management
  • ISO 27001 — Information Security
  • ISO 27701 — Data Privacy Management
  • ISO 27018 — Protection of Personal Data in the Cloud

Yes. Integration is possible via the REST API. Qualiex provides documented endpoints that enable data exchange with external systems, including SIEMs and other enterprise tools. For technical details on available endpoints, authentication formats, and data scope, please contact ForLogic support.

ForLogic has formalized policies and guidelines for managing information security incidents. The
process includes:

  • Procedure for notifying the competent authority (ANPD) and data subjects, when applicable.
    Formal procedure for investigating, recording, and handling incidents involving personal data breaches
    .
  • A dedicated channel for data subjects to exercise their rights and ask questions.
  • Customer support via chat and email, with SLAs based on urgency and a maximum response time of 24 hours for
    after the incident has been identified.