Security & resilience principles
Security is a shared foundation across every QWASP business line. This page describes the principles at a public, non-sensitive level. Implementation detail, credentials and internal architecture are deliberately not published here.
Identity & access
Key-based administrative access, least privilege, and multi-factor authentication for administrators.
Secure data handling
Data classification and a documented legal basis before any workload processes personal or client data.
Logging & evidence
Access and change logging that supports later review, without becoming a data-protection risk in itself.
Backup & recovery
Off-server backups with periodically tested restores; an untested backup is not treated as protection.
For QWASP's specialist security and resilience proposition, see Qwasp Security and OBTRASEC.
