Security and compliance
Qvera’s organizational controls are independently examined under SOC 2 Type 2. QIE provides authentication, authorization, encryption, logging, and data-retention controls within customers’ own deployments.
Qvera’s independent SOC 2 Type 2 report dated November 24, 2025 covers the period from October 1, 2024 through September 30, 2025. ControlCase SOC Audit Services examined Qvera’s Software and Services System against the Security, Availability, and Confidentiality Trust Services Criteria.
The report addresses Qvera’s controls for its software and services, including management, hosting, and professional services. The report does not extend to customer-operated QIE environments. The QIE controls described below are product capabilities that each customer configures within its own deployment.
The report is restricted-use material. Customers and qualified prospective customers can request a copy from Qvera.
Qvera enters into Business Associate Agreements where applicable for services involving protected health information (PHI). The scope depends on the service being provided. A QIE license for software running entirely in a customer-controlled environment does not, by itself, place that customer’s PHI in Qvera’s possession.
When Qvera provides hosting or managed services that involve PHI, Qvera’s policies require PHI to be used and disclosed only as permitted by HIPAA and applicable agreements. Qvera’s public privacy policy also states that it does not sell personal information for promotional purposes unrelated to its business or its own products and services.
QIE can run on customer-controlled Windows or Linux servers, in Docker or Kubernetes, or in a customer’s own cloud environment. Messages and configuration are stored in a customer-configured Microsoft SQL Server, MySQL, or MariaDB database. Customers configure message persistence by channel and set retention policies at the system or channel level.
For Qvera-hosted engagements, PHI is stored and processed within segregated customer environments in Qvera’s hosted infrastructure. Data location, access, and retention requirements are governed by the applicable service agreement and BAA, where applicable.
Qvera performs independent external network and application penetration testing annually and after significant changes. Qvera’s November 18, 2025 test was performed by TraceSecurity.
Qvera uses Rapid7 for ongoing vulnerability management. Product and third-party vulnerabilities are assessed using CVSS, prioritized by severity, and addressed through the appropriate hotfix, configuration guidance, or product release. Security advisories are communicated through product release notes.
To report a suspected QIE or Qvera product security issue, email support@qvera.com.
These controls are configurable. Their effectiveness depends on how QIE and its surrounding operating system, database, network, and identity services are deployed and administered.
Qvera can provide its November 24, 2025 SOC 2 Type 2 report to customers and qualified prospective customers, discuss whether a BAA applies to the planned services, and respond to security and vendor-risk questions about the proposed deployment.