TRUST AND SECURITY

Built by the people who do your audits

Qity works inside regulated quality systems every day, as a consultancy and as an app vendor. The same discipline applies to how we build and run the apps, and to how we handle personal data.

Aikido Security Audit Report
ARCHITECTURE

We hold none of your quality data

The apps run on Atlassian Forge. Documents, records, approvals, and audit trails stay in your Atlassian Cloud site, under your admin controls and your data residency setting.

PRACTICE

Audited continuously, not annually

Code, dependencies, and cloud configuration are scanned continuously through Aikido. The audit report is public, and you can request a current copy at any time.

AI

Your data does not train models

Qity relies on Atlassian AI only, including Rovo and Forge LLM. Customer data is not used to train AI models unless a customer explicitly opts in where applicable.

Where your quality data lives

Qity apps run on Atlassian Forge. Your quality records stay in your own Atlassian Cloud site. Qity does not operate a separate backend that holds them.

Your Atlassian Cloud site

Documents, records, approvals, and audit trails are Jira and Confluence data in your tenant, under your admin controls and your data residency setting.

The Qity apps, on Forge

The apps run inside Atlassian's platform and read and write your data there. Qity has no separate copy of your quality records.

QITY, AS CONTROLLER

Website, support, and commercial data

Contact requests, support tickets, and commercial correspondence. Qity is the controller for this, and the privacy policy sets out the detail.

Which role Qity holds

ACTIVITYQITY'S ROLEWHAT GOVERNS IT
Quality records created in the Qity appsNot held by QityYour Atlassian Cloud agreement and admin settings. The apps read and write inside your tenant.
Website visits, contact and demo requestsControllerQity privacy policy, GDPR Article 6
Support tickets and defect reportsControllerQity privacy policy and the support terms
Consultancy, migration, validation, and DPO servicesProcessorA data processing agreement and the statement of work

Sub-processors

The full list of sub-processors used to deliver the apps and the services, with the purpose and processing location of each.

AtlassianPlatform hosting for the apps and app dataEU, UK, US
MicrosoftEmail, business communication, and productivityEU
Xray, SembiTest management and quality toolingEU

Qity notifies customers of changes to this list before a new sub-processor starts processing.

Documents

Aikido audit report

Generated on request, no NDA

PUBLIC
Privacy policy

Version 1, effective 19 June 2026

PUBLIC
Sub-processor list

Published on this page

PUBLIC
Security whitepaper

Architecture, access control, and secure development

ON REQUEST
Data processing agreement

Template for the services engagements

ON REQUEST
Incident and breach procedure

Summarised below, full procedure on request

ON REQUEST
DATA PROTECTION CONTACT

Qity has a named data protection officer. Requests and questions go to dpo@qity.be, and the privacy policy sets out the full detail, including your rights.

If something goes wrong

Qity maintains an incident and breach procedure. Incidents are recorded, assessed for personal data impact, and escalated to the data protection officer. Where a personal data breach is confirmed and notification is required, the controller notifies the supervisory authority within 72 hours of becoming aware, and Qity notifies affected customers without undue delay where Qity acts as processor. The full procedure is available on request.

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA