Security
Security at Quzek
Your practice trusts you with sensitive personal and health information, and you trust us to keep it safe. Security is built into how Quzek is designed and operated — not bolted on afterwards.
This page describes the technical and organisational measures we use to protect your data. Security is a shared responsibility: we secure the platform, and you help by managing your users, permissions and credentials well. If you need details for a vendor-security or due-diligence review, contact [email protected].
How we protect your data
-
🗄
Per-practice isolation
Every practice runs in its own separate database. Your information is never mixed with another practice's data.
-
🔐
Encryption in transit & at rest
Data is encrypted in transit with TLS and at rest with strong, industry-standard encryption — including field-level encryption of sensitive clinical notes.
-
🔑
Two-factor authentication
Optional app-based 2FA (TOTP) protects staff accounts, with encrypted secrets and one-time recovery codes.
-
👤
Role-based access
Access within a practice is controlled by roles and permissions you manage, so people only see what they should.
-
🕵️
Audit trail
Access to sensitive records is recorded — who viewed, changed, exported or erased what, and when.
-
📁
Private file storage
Uploaded files and documents are stored on private storage and served only to authorised users — never on public URLs.
-
💾
Encrypted backups
Data is backed up on an encrypted, scheduled basis so your practice can be recovered after a failure — and you can export your data any time.
-
⏲️
Automatic logoff
Sessions end automatically after inactivity, reducing the risk from an unattended device.
-
📣
Responsible disclosure
We welcome security researchers. If you believe you have found a vulnerability, contact us and we will work with you to fix it.
Learn more →
Infrastructure and hosting
The Service runs on reputable cloud infrastructure providers that maintain robust physical and network security and their own industry certifications. Production systems are protected by network controls, and administrative access is restricted to authorised personnel on a need-to-know basis.
Encryption
All traffic between you and the Service is encrypted in transit using TLS. Data is encrypted at rest using strong, industry-standard algorithms, and particularly sensitive free-text clinical fields are additionally encrypted at the field level so they are protected even within the database. Passwords are stored only as salted, one-way hashes — never in plain text.
Access control and authentication
Access within each practice is governed by role-based permissions that you administer, following the principle of least privilege. We support two-factor authentication (TOTP), a configurable password policy, and automatic session timeout. Owners control who can see and do what, and privileged actions are gated accordingly.
Tenant isolation
Quzek is multi-tenant by design but strongly isolated: each practice's data lives in its own dedicated database, so one practice can never access another's information. This containment also limits the blast radius of any issue.
Logging, monitoring and audit trail
We log system and application events to detect and investigate issues. Within the product, an append-only audit trail records access to sensitive records — including views, changes, exports and erasures — supporting your accountability obligations under regimes such as HIPAA and PHIPA.
Backups and disaster recovery
Data is backed up on a scheduled basis, and backups can be encrypted. We design for durability so that, in the event of a failure, a practice's data can be recovered. You can also export your own data at any time, so you are never locked in.
Secure development
Security is considered throughout our development process. We follow secure-coding practices, keep dependencies up to date, protect against common web vulnerabilities (such as those in the OWASP Top 10), and review changes before they reach production.
Vulnerability management and responsible disclosure
We monitor for and remediate vulnerabilities in our systems and dependencies. We welcome reports from the security community — if you believe you have found a vulnerability, please email [email protected] with details, and we will acknowledge your report and work with you in good faith to resolve it. Please do not access or modify data that is not yours while testing.
Vendor and sub-processor management
We engage a limited set of sub-processors (for hosting, email, SMS, payments and monitoring), each bound by data-protection and confidentiality obligations. See our Privacy Policy and Data Processing Agreement for detail; a current sub-processor list is available on request.
Compliance alignment
Quzek is built to support the privacy and security obligations of GDPR, HIPAA, the Australian Privacy Principles, PIPEDA, CCPA and POPIA, and we follow enterprise-grade security practices aligned with recognised standards such as ISO 27001. We are transparent about which formal certifications we do and do not currently hold — contact us for the latest details for a due-diligence review, and see our Compliance page. For US healthcare providers we can provide a Business Associate Agreement (BAA); for GDPR we can provide a Data Processing Agreement (DPA).
Incident response
We maintain an incident-response process to detect, contain and remediate security incidents. If a personal-data breach affects a practice's data, we will notify the affected practice without undue delay and provide the information reasonably needed for it to meet its own notification duties (for example the GDPR 72-hour rule, the Australian NDB scheme, or the HIPAA Breach Rule).
Your role in security
You can strengthen your practice's security by enabling two-factor authentication, giving each team member their own account with the least access they need, using strong unique passwords, reviewing your users regularly, and logging out on shared devices. Quzek gives you the tools; using them well keeps your clients' information safe.
Security questions, answered
Is my data encrypted?
Can another practice see my data?
Do you support two-factor authentication?
How do I report a security issue?
Run your practice on a platform you can trust
Start a free 14-day trial and see how Quzek keeps your schedule and your data safe.
Start your free trial