Trust
Security policies
QEHS maintains a documented Information Security Management System (ISMS) with the 14 policies below, aligned to ISO 27001:2022 Annex A controls (certification planned, not yet certified). The program is owned by the executive team and reviewed on a quarterly cadence.
This page is the public policy register. Full policy text is available to customers and active prospects under NDA — request it through the procurement packet or your account team. For the wider security posture, see the Trust Center.
1. Information Security Policy
A.5 — Organizational controlsThe overarching ISMS policy: scope, objectives, leadership commitment, roles and responsibilities, and the framework all other policies sit under.
2. Access Control Policy
A.5.15–A.5.18, A.8.2–A.8.5Least-privilege access, role-based permissions, mandatory MFA, and joiner/mover/leaver provisioning across all production systems.
3. Cryptographic Controls Policy
A.8.24Encryption in transit (TLS) and at rest (AES-256), envelope encryption, and key lifecycle management for tenant and platform data.
4. Data Classification Policy
A.5.12Classification tiers and the handling, retention, and disclosure rules that apply to each tier of customer and corporate data.
5. Risk Assessment Policy
Clause 6, A.5The risk methodology, treatment decisions, and the cadence on which the risk register is reviewed and re-scored.
6. Change Management Policy
A.8.32Controlled changes to production: review, approval, testing, and rollback expectations for code and infrastructure.
7. Secure SDLC Policy
A.8.25–A.8.28Security requirements through the development lifecycle — design review, code review, automated testing, and dependency hygiene.
8. Vulnerability Management Policy
A.8.8Dependency and infrastructure scanning, remediation SLAs by severity, and the coordinated vulnerability disclosure process.
9. Incident Response Plan
A.5.24–A.5.28Detection, triage, escalation, customer communication, and post-incident review for security and availability incidents.
10. Backup & Recovery Policy
A.8.13Backup scope and frequency, encrypted offsite storage, and the schedule on which restores are tested for integrity.
11. Business Continuity & DR Plan
A.5.29–A.5.30Continuity objectives, recovery time and recovery point targets (RTO/RPO), and failover procedures for critical services.
12. Vendor Management Policy
A.5.19–A.5.22Third-party and subprocessor risk assessment, contractual safeguards, and ongoing review of suppliers with data access.
13. Onboarding & Offboarding Procedure
A.6.1–A.6.5Personnel security: background-appropriate access on joining, role changes, and prompt revocation on departure.
14. Code of Conduct
A.6.2, A.5Acceptable use, confidentiality, and the ethical and security expectations every member of staff agrees to.