Security Q&A

Quaystone works to give you everything you need to satisfy your own data-protection obligations. Below you will find our published security references, along with answers to the questions we field most often.

What personal data does Quaystone handle?

Account records, billing details and the project content you upload, plus the technical logs generated when a site is published. A full field-by-field breakdown sits in the privacy reference.

Which staff can view Personal Data?

Personal Data belonging to both Customers and End Users is reachable only by Quaystone staff whose role genuinely requires it to carry out their duties. Our support engineers are one such role.

What is the retention period for Customer Data?

Active workspaces keep data for as long as the account is open. After a closure request, project content is purged within 34 days and backups roll off inside a further 90.

Does Quaystone meet PCI DSS?

Card details never touch our servers. Payments are handled by a PCI DSS Level 1 processor, and we hold a current SAQ-A attestation covering our side of the flow.

Is the platform HIPAA ready?

Not today. We do not sign Business Associate Agreements, so protected health information should not be stored in a workspace or collected through a published form.

In which regions is Customer Data processed?

Primary processing runs in the United States, with an optional European region for workspaces that require it. Edge caching is global; origin storage stays inside the region you pick.

Is customer data encrypted at rest?

Yes, with AES-256 at rest and TLS 1.3 in transit. Encryption keys are held in a managed key service, rotated on a fixed schedule and never shared between regions.

Can we sign a Data Processing Agreement (DPA)?

A standard DPA with the current transfer clauses is available to every paid workspace and can be countersigned from account settings without involving our legal team.

Are customers permitted to run penetration tests and vulnerability scans against the platform?

Testing against your own workspace is welcome once you have filed a short notice with us. Please keep automated scanning off shared infrastructure so other customers are not affected.

Is uptime published anywhere we can subscribe to?

A live status board covers publishing, the editor and hosted sites, with 90 days of history. Email and webhook alerts can be turned on for any individual component.