QX is built for the same auditors that review your payments. Encryption, permissions and immutable audit logs are the defaults — not add-ons.
Payment flows use certified acquirers and tokenized card data. Cardholder data never touches QX servers.
TLS 1.2+ in transit, AES-256 at rest. Secrets managed in an isolated vault with automatic rotation.
Fine-grained roles for owners, managers, cashiers and auditors — enforced at the row and column level.
Immutable event log for every sensitive action: pricing, refunds, permission changes and exports.
Guests are stored under phone-hashed identifiers. Personal data is minimized, exportable and deletable on request.
Isolated tenant environments, hardened base images, private networking and least-privilege service accounts.
99.99% platform SLA, multi-AZ failover, live status page and 24/7 on-call for P1 incidents.
KSA-native storage for tenants that require it. Regional replicas for latency-sensitive branches.
Under NDA we share our architecture overview, controls matrix, pen-test summary and incident-response playbook.
Our security team will walk your CISO or auditors through architecture, controls and incident playbooks — on your calendar.