Business data deserves clear controls.
DLQ Technos uses layered technical and organisational controls to protect customer information and restrict unauthorised access. This page states what is in place and what is not.
Certifications: what we hold today
We do not currently hold SOC 2 or ISO/IEC 27001 certification. Our security programme is structured with reference to ISO/IEC 27001 principles, but no independent audit has been completed and no certificate exists. We will say so here the day that changes, with the scope and the certifying body named.
If your procurement process requires a certification we do not hold, tell us early. We would rather lose the deal than misrepresent our position.
Controls in place
Tenant isolation
Row-level security in the database separates each company's data. Enforced by the database, not by application code that could be bypassed.
Encryption
In transit and at rest. Government identity numbers are encrypted separately from the rest of the record.
Role-based access
Per-module, per-action permissions. Branch access is a list, so a regional role sees only its own sites.
Audit trail
Every create, edit and delete recorded with the person, the time and the record — readable inside the product, not just in a log file.
Two-factor sign-in
Optional, per account.
Access revocation
An exited employee loses access immediately, without their history being deleted.
Backups
Managed by our infrastructure provider, with point-in-time recovery.
Least-privilege service access
Server-side keys never reach the browser.
Being built
Listed because a security page that only shows strengths tells a buyer nothing they can use.
Reporting a vulnerability
If you believe you have found a security issue, email admin@dlqtechnos.com with enough detail to reproduce it. We will acknowledge within one working day. Please give us a reasonable window to fix it before disclosing publicly.