Security & resilience principles

Security is a shared foundation across every QWASP business line. This page describes the principles at a public, non-sensitive level. Implementation detail, credentials and internal architecture are deliberately not published here.

Identity & access

Key-based administrative access, least privilege, and multi-factor authentication for administrators.

Secure data handling

Data classification and a documented legal basis before any workload processes personal or client data.

Logging & evidence

Access and change logging that supports later review, without becoming a data-protection risk in itself.

Backup & recovery

Off-server backups with periodically tested restores; an untested backup is not treated as protection.

For QWASP's specialist security and resilience proposition, see Qwasp Security and OBTRASEC.