Security And Data Protection

Overview

Welcome to Qwaiting Trust Center- Your security and privacy are our top priorities, and we continuously try to provide you with a safe and reliable experience.

Our Security, Governance, Risk, and Compliance (GRC) and Privacy programs are designed to protect our clients' data's confidentiality and availability.

Compliance

GDPR
AICPA
HIPAA
ISO/IEC 27001:2022

Documents

HIPA
GDPR
ISO/IEC 27001:2022
SOC2 Type 2

Security Categories

Product Security

  • Audit Logs
  • Data Security and Privacy
  • Data Masking

Data Security

  • Access Monitoring
  • Erasure of Data
  • Enabled Backups

Application Security

  • Code Analysis
  • Credential Management
  • Secure Development Training

Legal

  • Subprocessors
  • Privacy Policy
  • Terms and Condition

Access Control

  • Data Access
  • Logging
  • Password Security

Infrastructure

Endpoint Security

  • Disk Encryption
  • Endpoint Detection & Response
  • No Access to Removable Storage Media

Network Security

  • Firewall
  • IDS/IPS
  • Traffic Filtering

Corporate Security

  • Employee Training
  • Email Protection
  • Human Resource Security
Audit Logs Product Security

We ensure that our product as a whole is secure and generally will not work on any embedded systems.

  • Audit Logs

    Our product logs provide information about who has accessed the software and what activities he or she has performed.

  • Data Security and Privacy

    Qwaiting implements the following data security standards:

    • Secure Sockets Layer (SSL) encryption.
    • Hashing algorithms for password protection.
    • Secure File Transfer Protocol (SFTP) for data exchange.
    • Regular security audits and monitoring.
    • Data backups also undergo encryption when stored.
  • Data Masking

    We use advanced security measures, like using a Data Masking feature. This method adds an extra layer of protection and confidentiality to your data, effectively preventing unauthorized access.

  • Two-Step Verification

    Our product offers strong support for two-step verification, allowing users to boost the security of their accounts. One available option is OTP-based MFA, which lets users safeguard their accounts with an extra layer of security beyond the usual login credentials.

  • Role-Based Access Control

    Our system grants administrators the flexibility to manage user permissions based on their roles and the needs of the business.

  • Integration Power

    Qwaiting easily integrates with a range of widely-used business software, including:

    • Office365
    • Whatsapp
    • Gmail
    • Slack
    • Jumpcloud
  • Single Sign-On (SSO) Support

    Our product supports SSO for easy business deployments, allowing users to use one set of credentials to log in to multiple applications. You can integrate Qwaiting with your business software using SAML SSO.

Access Monitoring Data Security

We safeguard your digital information against unauthorized access, corruption, or theft, ensuring a secure and protected experience.

  • Access Monitoring

    We record and monitor all access attempts to Qwaiting resources. So you can easily identify and respond to any unauthorized activities related to your data.

  • Erasure of Data

    We have a well-defined process in place, supported by established guidelines, to address data deletion and de-identification requests.

  • Enabled Backups

    Qwaiting uses various methods such as continuous configuration, and complete and incremental backups. They also perform regular checks to ensure the effectiveness of the restoration process. To keep data safe, Qwaiting encrypts its backups using built-in encryption.

  • At-Rest Encryption

    We secure data at rest by employing AWS-provided Elastic Block Store encryption, utilizing the widely accepted AES 256-bit encryption standard.

  • In-Transit Encryption

    For communication in transit, we exclusively use secure and encrypted channels, implementing Transport Layer Security.

  • Physical Security

    Qwaiting products are hosted on Amazon Web Services (AWS), where the physical and environmental security policies of the hosting environments are overseen by AWS.

Code Analysis Application Security

We ensure that our application is equipped with advanced security features to safeguard against potential risks and cyber threats.

  • Code Analysis

    We perform static code analysis using automated tools to detect and address vulnerabilities in the code. Identified vulnerabilities are diligently monitored until resolved.

  • Credential Management

    Credential secrets are handled through the AWS Key Management Service, with regular key rotations to enhance security.

  • Secure Development Training

    Our developers receive regular training on secure coding practices.

  • Software Development Lifecycle

    Qwaiting follows a well-documented secure SDLC process. This includes implementing access controls and conducting peer code reviews to prevent the introduction of vulnerabilities. Automated tools are employed for code scanning.

  • Firewall for Web Applications

    Qwaiting uses Amazon Web Services (AWS) Web Application Firewall to protect our web applications from common attacks.

  • Vulnerability Management

    Regular infrastructure and application-level vulnerability assessments are carried out, and the identified vulnerabilities are tracked until the closure.

Data Access Access Control

You can rely on us to protect your environment with advanced access control systems, giving you peace of mind and the highest level of security.

  • Data Access

    Qwaiting ensures data access is restricted to individuals with a genuine need, specifically for providing customer services. Access privileges are limited to the minimum necessary as per the job responsibilities. To enhance security, Qwaiting mandates two-factor authentication and VPN for secure access.

  • Logging

    Qwaiting maintains different types of logs for access and user activity, such as application logs, OS logs, database logs, firewall logs, and IDS/IPS logs. These logs are used to monitor unusual activity, inappropriate resource usage, and the overall operational status and health of the platform. We utilize security information and event management (SIEM) tools for analysis and alerting.

  • Password Security

    Stringent password security policies and Multi-Factor Authentication (MFA) are mandated for all Qwaiting employees via a central active directory.

Status Monitoring Infrastructure

We safeguard the physical and digital assets of a business's information technology (IT) infrastructure.

  • Status Monitoring

  • Amazon Web Services

    Qwaiting product is hosted on AWS.

    The Amazon Web Service data centers are located as follows:

    • North Virginia
    • Singapore
  • Availability

    Qwaiting systems operate across multiple AWS Availability Zones, ensuring resilience. They support on-demand scaling of stateless server farms, and the hosting infrastructure is designed to handle both hardware failures and availability zone issues.

  • Anti-DDoS Protection

    Qwaiting relies on AWS Shield, an advanced DDoS protection service provided by Amazon Web Services. This managed solution helps to secure Qwaiting applications by autonomously identifying and mitigating complex network-level DDoS events. It ensures uninterrupted service availability, safeguarding the overall performance of the application.

  • Infrastructure Security

    Qwaiting follows Center for Internet Security (CIS) benchmarks to protect its infrastructure. API Throttling has been activated for added security, and all cloud systems are equipped with antivirus protection.

  • Network Time Protocol (NTP)

    We utilize Amazon Web Services NTP servers to synchronize time across our systems.

  • Business Continuity & Disaster Recovery Plan

    Qwaiting has a Business Continuity Plan in place, with procedures for implementation in the event of a disturbance. Regular testing and validation are carried out to ensure the ongoing effectiveness of the Business Continuity Plan.

  • Separate Production Environment

    Qwaiting maintains separate production, testing, and development environments for its products. Each of these environments is carefully segregated to guarantee proper isolation.

Disk Encryption Endpoint Security

We specialize in comprehensive Endpoint Security, ensuring advanced protection for your digital assets.

  • Disk Encryption

    To secure data on our corporate laptops, we employ FileVault and VeraCrypt for advanced disk encryption.

  • Endpoint Detection & Response

    Microsoft Defender is utilized for endpoint protection, with Endpoint Detection and Response (EDR) activated on all endpoints. This ensures the detection and response to any malicious activities as soon as possible.

  • No Access to Removable Storage Media

    As a default measure, removable storage media access is blocked on all endpoints.

  • Mobile Device Management

    Qwaiting centrally manages all mobile devices, implementing controls such as automatic screen lock, strong passwords and patterns, and regular operating system (OS) updates. Mobile devices are both password-protected and encrypted to enhance security.

  • Threat Detection

    Our comprehensive threat detection strategy includes IDS/IPS at the network gateway level, ATP for the email gateway, and Defender for endpoint security.

Firewall Network Security

We will take care of network security, ensuring the highest level of protection for your digital infrastructure.

  • Firewall

    We use a firewall to safeguard networked company resources.

  • IDS/IPS

    Identification of malicious inbound and outbound traffic is carried out using an IDS. Also, we utilize an IPS to provide real-time protection for critical infrastructure, data, and vulnerable applications, safeguarding against known, and unknown vulnerabilities without compromising network performance.

  • Traffic Filtering

    Our network traffic is filtered for known malicious domains at both the network and host levels.

  • Wireless Security

    We utilize WPA2-Enterprise for wireless authentication on our internal network. Also, we have a distinct, isolated wireless network for guest devices.

  • Virtual Private Cloud

    We implement a virtual private cloud to maintain a secured segregated environment, separate from other public cloud tenants.

  • Security Information and Event Management

    We use security information and event management (SIEM) tools to observe security events within our infrastructure.

Employee Training Corporate Security

We follow a broad range of practices and policies for corporate security, ensuring the safety and continuity of business operations.

  • Employee Training

    All employees must attend security and privacy training at the time of hire and annually thereafter. These sessions involve assessments, and a passing score is required to complete the training.

  • Email Protection

    Qwaiting makes sure that emails are secure by using a secure email gateway with strong protections. It filters out suspicious emails to keep users safe. The system also identifies emails from external users and has extra measures to prevent data loss.

  • Human Resource Security

    Our HR security protocols are as follows:

    • Employee Screening
    • Security Training for Employees
    • Disciplinary Process
    • Termination or Change of Employment
    • Terms & Conditions of Employment
  • Internal Assessments

    On an annual basis, internal audits and assessments are conducted according to industry standards such as SOC2, ISO 27001, ISO 27701, and PCI-DSS.

  • Internal SSO

    To enhance security, Qwaiting has implemented Single Sign-On (SSO) using Azure AD, making it mandatory for employees to use SSO to access company resources.

  • Security Incident Reporting

    Incident response procedures address any unauthorized access, disclosure, use, or deletion of information that could compromise confidentiality and availability.

  • Penetration Testing

    Regular vulnerability assessments and penetration tests are carried out on IT and Cloud Infrastructure. Application Security Testing follows guidelines such as OWASP Top 10, CWE/SANS Top 25, PCI DSS Penetration Testing Guidelines, and other industry best practices as applicable.

Trusted by 65K+ Businesses Worldwide

Join the industry leaders who trust Qwaiting for their queue management

Daleel Alzowar
Hospital At Maayo
Ministry Of Hajj And Umrah
Tatapwer Ddl
PSB
Jtc
Nus
Dhl
Singapore Polytechnic
Skechers
Nirvana
NTUC FairPrice
Ministry Of Education
Msq
MND Singapore
Current Corporate Signature
MOH
BL
Changi
Subway
Grab
Inland Revenue Authority
Ministry Of Manpower
NLB
Ntuc Learning Hub
Raffles Medical Group
Service SG
SIM SOC
Singapore Medical
Apollo Hospitals
Get Free Trial WhatsApp