Security and compliance

Qvera’s organizational controls are independently examined under SOC 2 Type 2. QIE provides authentication, authorization, encryption, logging, and data-retention controls within customers’ own deployments.

What does Qvera’s SOC 2 Type 2 report cover?

Qvera’s independent SOC 2 Type 2 report dated November 24, 2025 covers the period from October 1, 2024 through September 30, 2025. ControlCase SOC Audit Services examined Qvera’s Software and Services System against the Security, Availability, and Confidentiality Trust Services Criteria.

The report addresses Qvera’s controls for its software and services, including management, hosting, and professional services. The report does not extend to customer-operated QIE environments. The QIE controls described below are product capabilities that each customer configures within its own deployment.

The report is restricted-use material. Customers and qualified prospective customers can request a copy from Qvera.

Qvera SOC 2 Type 2 attestation

How does Qvera handle HIPAA and Business Associate Agreements?

Qvera enters into Business Associate Agreements where applicable for services involving protected health information (PHI). The scope depends on the service being provided. A QIE license for software running entirely in a customer-controlled environment does not, by itself, place that customer’s PHI in Qvera’s possession.

When Qvera provides hosting or managed services that involve PHI, Qvera’s policies require PHI to be used and disclosed only as permitted by HIPAA and applicable agreements. Qvera’s public privacy policy also states that it does not sell personal information for promotional purposes unrelated to its business or its own products and services.

Where is customer data stored?

QIE can run on customer-controlled Windows or Linux servers, in Docker or Kubernetes, or in a customer’s own cloud environment. Messages and configuration are stored in a customer-configured Microsoft SQL Server, MySQL, or MariaDB database. Customers configure message persistence by channel and set retention policies at the system or channel level.

For Qvera-hosted engagements, PHI is stored and processed within segregated customer environments in Qvera’s hosted infrastructure. Data location, access, and retention requirements are governed by the applicable service agreement and BAA, where applicable.

How does Qvera test and manage security?

Qvera performs independent external network and application penetration testing annually and after significant changes. Qvera’s November 18, 2025 test was performed by TraceSecurity.

Qvera uses Rapid7 for ongoing vulnerability management. Product and third-party vulnerabilities are assessed using CVSS, prioritized by severity, and addressed through the appropriate hotfix, configuration guidance, or product release. Security advisories are communicated through product release notes.

To report a suspected QIE or Qvera product security issue, email support@qvera.com.

What security controls are built into QIE?

  • Authentication. Local accounts, LDAP directory authentication (including LDAPS), and OpenID Connect (OIDC) identity providers. LDAP groups and OIDC claims can map to QIE roles.
  • Role-based access. Permissions are scoped by zone, with access levels for viewing, managing, editing, and resolving message errors. Zones isolate channels and their connections, variables, mappings, certificates, and keys.
  • Connection security. Administrators can configure HTTPS for the management console and TLS or mutual TLS on supported inbound and outbound interface connections. Built-in certificate management includes expiration alerts.
  • Credential protection. Connection credentials, application secrets and OAuth tokens are stored encrypted. Local passwords are stored as salted hashes rather than clear text.
  • Auditability. QIE logs successful and failed authentication events, administrative actions, and channel and message activity. It also maintains user-attributed revision history for audited configuration changes. Text logs can be exported or sent to a SIEM.
  • Persistence and retention. Administrators choose message persistence levels and retention periods to match the deployment’s operational and compliance requirements.

These controls are configurable. Their effectiveness depends on how QIE and its surrounding operating system, database, network, and identity services are deployed and administered.

What can Qvera provide for a vendor risk assessment?

Qvera can provide its November 24, 2025 SOC 2 Type 2 report to customers and qualified prospective customers, discuss whether a BAA applies to the planned services, and respond to security and vendor-risk questions about the proposed deployment.

Need the report, a BAA, or help with a security questionnaire?

© Copyright 2026 - Qvera - All rights reserved  |  Privacy Policy