Technology & infrastructure principles

Technology serves governance at QWASP, not the other way around. The principles below apply across all four business lines, adapted per workload.

1. Governance & architecture

Every workload has an owner, a documented current and target state, and decisions recorded as they are made.

2. Method & intellectual property

The Verhulsdonck Method and QWASP's own brands are treated as governed IP, not informal know-how.

3. Identity & access

Key-based access, least privilege, and multi-factor authentication for administrative accounts.

4. Secure data handling

Data is classified before it moves, with a documented legal basis for processing.

5. Security & resilience

Hardened by default; see Security & resilience principles.

6. Logging & evidence

Changes and access are logged in a way that supports later review.

7. Backup & recovery

Off-server backups with periodic, actually-tested restores. A backup without a tested restore is not treated as protection.

8. European-first infrastructure

Hosting and processing choices favour EU-based providers and data residency.

9. Web3 & distributed infrastructure

Applied selectively, where it improves resilience and sovereignty. See Web3 & distributed infrastructure.

10. Vendor independence

Architecture designed so no single supplier can lock QWASP or its clients in.

This page describes principles at a public, non-sensitive level. It does not disclose IP addresses, internal hostnames, account identifiers, credentials, firewall configuration or supplier account details.