TRUST AND SECURITY

Built by the people who do your audits

Qity works inside regulated quality systems every day, as a consultancy and as an app vendor. The same discipline applies to how we build and run the apps, and to how we handle personal data.

Aikido Security Audit Report
ARCHITECTURE

We hold none of your quality data

The apps run on Atlassian Forge. Documents, records, approvals, and audit trails stay in your Atlassian Cloud site, under your admin controls and your data residency setting.

PRACTICE

Audited continuously, not annually

Code, dependencies, and cloud configuration are scanned continuously through Aikido. The audit report is public, and you can request a current copy at any time.

AI

Your data does not train models

Qity relies on Atlassian AI only, including Rovo and Forge LLM. Customer data is not used to train AI models unless a customer explicitly opts in where applicable.

Where your quality data lives

Qity apps run on Atlassian Forge. Your quality records stay in your own Atlassian Cloud site. Qity does not operate a separate backend that holds them.

Your Atlassian Cloud site

Documents, records, approvals, and audit trails are Jira and Confluence data in your tenant, under your admin controls and your data residency setting.

The Qity apps, on Forge

The apps run inside Atlassian's platform and read and write your data there. Qity has no separate copy of your quality records.

QITY, AS CONTROLLER

Website, support, and commercial data

Contact requests, support tickets, and commercial correspondence. Qity is the controller for this, and the privacy policy sets out the detail.

Which role Qity holds

ACTIVITYQITY'S ROLEWHAT GOVERNS IT
Quality records created in the Qity appsNot held by QityYour Atlassian Cloud agreement and admin settings. The apps read and write inside your tenant.
Website visits, contact and demo requestsControllerQity privacy policy, GDPR Article 6
Support tickets and defect reportsControllerQity privacy policy and the support terms
Consultancy, migration, validation, and DPO servicesProcessorA data processing agreement and the statement of work

Sub-processors

The full list used to deliver the apps and the services, with the purpose and processing location of each. Qity notifies customers of changes at least 30 days before a new sub-processor begins processing.

SUB-PROCESSORPURPOSEPROCESSING LOCATION
AtlassianPlatform hosting for the apps and app dataEU, UK, US
MicrosoftEmail, business communication, and productivityEU
Xray, SembiTest management and quality toolingEU

The transfer position for each is recorded in Annex 4 of the data processing agreement.

Documents

Seven are published. Two are issued on request, to customers and prospective customers under an NDA.

Aikido audit reportPUBLIC
Continuous scanning of code, dependencies, and cloud configuration. Generated on request, no NDA.
Security controls and the ISMSPUBLIC
DOC-262 Information Security Policy, the standards adopted, and all 28 subject policies.
Incident and breach procedurePUBLIC
DOC-836, reproduced in full: twelve activities, roles, and notification timelines.
Vulnerability managementPUBLIC
Sources of findings, published remediation targets, and the disclosure route.
Data processing agreementPUBLIC
Standard Article 28 terms with all four annexes, published for review.
Privacy policyPUBLIC
Version 1, effective 19 June 2026. Covers the processing for which Qity is controller.
Security whitepaperPUBLIC
Data protection accountability as controlled records. 21 pages, open access.
Statement of ApplicabilityON REQUEST
Which ISO/IEC 27001 Annex A controls are implemented, and which are excluded, with rationale.
Individual policiesON REQUEST
Any of the 28 subject policies, in full, for customers and prospective customers under NDA.
DATA PROTECTION CONTACT

Qity has a named data protection officer. Requests and questions go to dpo@qity.be, and the privacy policy sets out the full detail, including your rights.

SECURITY INCIDENT CONTACT

Report an actual or suspected security incident or vulnerability to security@qity.be. No NDA is required, and the procedure sets out the roles and notification timelines.

If something goes wrong

Qity maintains an incident and breach procedure. Incidents are recorded, assessed for personal data impact, and escalated to the data protection officer. Where a personal data breach is confirmed and notification is required, the controller notifies the supervisory authority within 72 hours of becoming aware, and Qity notifies affected customers without undue delay where Qity acts as processor. The full procedure is summarised at How Qity handles security incidents, and the complete controlled document is available on request.

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA