WARQLINE
WQL.MODULE.TRUST// ONLINE
/ 06 — TRUST

Trust Center

How this site and the services around it are built, in enough detail to be checked.

Certifications we do not hold

Warqline is not SOC 2 or ISO 27001 certified, and we are not going to imply otherwise on a page whose entire purpose is being trustworthy. We build and audit systems that meet those frameworks for clients; that is not the same as holding the certification ourselves. If your procurement process requires one, tell us early and we will tell you plainly where we stand.

CONTROLS

How it is built

Each of these describes the running system, not an intention.

Where data is processed

The application and its database run in europe-west1 (Belgium). Static assets are served from a global content delivery network, so they are distributed worldwide by design. Authentication is operated by Google and may be processed outside the EU.

Encryption

Traffic is served over HTTPS with automatically renewed certificates; HTTP is redirected. Data at rest is encrypted by the underlying Google Cloud services. Credentials are held in a dedicated secret store, never in the repository or in container images.

Access control

Administrative functions require an authenticated session and a verified administrator claim, checked on the server for every request rather than in the browser. Client portal accounts are provisioned by Warqline; there is no self-service sign-up.

Deployment credentials

Continuous deployment authenticates with Workload Identity Federation and short-lived tokens. There is no long-lived cloud key stored in the repository or in CI, and the identity provider is restricted to this single repository.

Service accounts

Deployment and runtime use separate identities with different permissions. The runtime identity can read one secret and write to one database; it cannot deploy. Least privilege is the arrangement, not an aspiration.

Data retention

Contact enquiries are deleted 24 months after they arrive, enforced by a database-level policy rather than by a scheduled job someone has to remember to run.

Backups and recovery

Site content is versioned in git and deployable from source at any commit; hosting keeps prior releases and can roll back. Enquiry data is held in a managed database with the provider's point-in-time recovery.

Third parties

Deliberately few. Google Cloud hosts the site, its database and authentication. Resend delivers contact email and is based in the United States. Google Analytics counts page views, and is the only one that needs your agreement — it is not loaded unless you give it. Typefaces are served from our own servers, so if you decline analytics, viewing the site contacts no third party at all.

GDPR

Data protection

Warqline Technologies is the data controller for personal data collected through this site. What we collect, why, where it goes and how long we keep it is set out in full in the privacy policy, and what the site stores in your browser is in the cookie policy.

You can ask us for a copy of your data, corrections, or deletion, at partner@warqline.com. If you are not satisfied with our response you can complain to the Autoriteit Persoonsgegevens.

REPORTING

Found something?

If you believe you have found a vulnerability in our systems, we want to hear about it before anyone else does.

Security contact
partner@warqline.com

Include enough detail to reproduce the issue. We will acknowledge your report and keep you informed while we work on it. Please give us a reasonable window to fix the problem before publishing, and do not access or modify data that is not yours while testing.

We do not currently run a paid bug bounty. We would rather say so than let you find out after the work.

Security questions before you sign anything

Send them over. We would rather answer a long questionnaire early than discover a blocker at contract stage.

Talk to an Engineer