Skip to content
Qeet Group

Foundation

Security

What we protect, how, and what we have not done yet.

What we can state

Qeet Group holds no security certifications today. Formal attestation is on the roadmap and is not claimed here, because a compliance badge is the single easiest claim for a buyer to verify and the most damaging one to get wrong.

What can be stated is the baseline every product is built to.

The baseline

Least privilege. Access is granted narrowly and explicitly. Nothing is permitted because it was convenient at the time.

Secure by default. The safe configuration is the one you get without asking. Relaxing it is a deliberate act with a name attached.

Tenant isolation. One customer's data is separated from another's by the architecture, not by the correctness of a query someone wrote on a Friday.

Zero implicit trust. Being inside the network is not a credential. Every request establishes who is asking and what they may do.

Auditability. Consequential actions are recorded so they can be produced later, and so that alteration is detectable rather than assumed away.

Defence in depth. No single control is load-bearing. Anything important is protected more than once, because controls fail.

Reporting a problem

Security reports go to security@qeet.in. We would rather hear about something uncomfortable early than read about it later.