Technology & infrastructure principles
Technology serves governance at QWASP, not the other way around. The principles below apply across all four business lines, adapted per workload.
1. Governance & architecture
Every workload has an owner, a documented current and target state, and decisions recorded as they are made.
2. Method & intellectual property
The Verhulsdonck Method and QWASP's own brands are treated as governed IP, not informal know-how.
3. Identity & access
Key-based access, least privilege, and multi-factor authentication for administrative accounts.
4. Secure data handling
Data is classified before it moves, with a documented legal basis for processing.
5. Security & resilience
Hardened by default; see Security & resilience principles.
6. Logging & evidence
Changes and access are logged in a way that supports later review.
7. Backup & recovery
Off-server backups with periodic, actually-tested restores. A backup without a tested restore is not treated as protection.
8. European-first infrastructure
Hosting and processing choices favour EU-based providers and data residency.
9. Web3 & distributed infrastructure
Applied selectively, where it improves resilience and sovereignty. See Web3 & distributed infrastructure.
10. Vendor independence
Architecture designed so no single supplier can lock QWASP or its clients in.
This page describes principles at a public, non-sensitive level. It does not disclose IP addresses, internal hostnames, account identifiers, credentials, firewall configuration or supplier account details.
