Quzek

Security

Security at Quzek

Your practice trusts you with sensitive personal and health information, and you trust us to keep it safe. Security is built into how Quzek is designed and operated — not bolted on afterwards.

This page describes the technical and organisational measures we use to protect your data. Security is a shared responsibility: we secure the platform, and you help by managing your users, permissions and credentials well. If you need details for a vendor-security or due-diligence review, contact [email protected].

How we protect your data

  • 🗄

    Per-practice isolation

    Every practice runs in its own separate database. Your information is never mixed with another practice's data.

  • 🔐

    Encryption in transit & at rest

    Data is encrypted in transit with TLS and at rest with strong, industry-standard encryption — including field-level encryption of sensitive clinical notes.

  • 🔑

    Two-factor authentication

    Optional app-based 2FA (TOTP) protects staff accounts, with encrypted secrets and one-time recovery codes.

  • 👤

    Role-based access

    Access within a practice is controlled by roles and permissions you manage, so people only see what they should.

  • 🕵️

    Audit trail

    Access to sensitive records is recorded — who viewed, changed, exported or erased what, and when.

  • 📁

    Private file storage

    Uploaded files and documents are stored on private storage and served only to authorised users — never on public URLs.

  • 💾

    Encrypted backups

    Data is backed up on an encrypted, scheduled basis so your practice can be recovered after a failure — and you can export your data any time.

  • ⏲️

    Automatic logoff

    Sessions end automatically after inactivity, reducing the risk from an unattended device.

Infrastructure and hosting

The Service runs on reputable cloud infrastructure providers that maintain robust physical and network security and their own industry certifications. Production systems are protected by network controls, and administrative access is restricted to authorised personnel on a need-to-know basis.

Encryption

All traffic between you and the Service is encrypted in transit using TLS. Data is encrypted at rest using strong, industry-standard algorithms, and particularly sensitive free-text clinical fields are additionally encrypted at the field level so they are protected even within the database. Passwords are stored only as salted, one-way hashes — never in plain text.

Access control and authentication

Access within each practice is governed by role-based permissions that you administer, following the principle of least privilege. We support two-factor authentication (TOTP), a configurable password policy, and automatic session timeout. Owners control who can see and do what, and privileged actions are gated accordingly.

Tenant isolation

Quzek is multi-tenant by design but strongly isolated: each practice's data lives in its own dedicated database, so one practice can never access another's information. This containment also limits the blast radius of any issue.

Logging, monitoring and audit trail

We log system and application events to detect and investigate issues. Within the product, an append-only audit trail records access to sensitive records — including views, changes, exports and erasures — supporting your accountability obligations under regimes such as HIPAA and PHIPA.

Backups and disaster recovery

Data is backed up on a scheduled basis, and backups can be encrypted. We design for durability so that, in the event of a failure, a practice's data can be recovered. You can also export your own data at any time, so you are never locked in.

Secure development

Security is considered throughout our development process. We follow secure-coding practices, keep dependencies up to date, protect against common web vulnerabilities (such as those in the OWASP Top 10), and review changes before they reach production.

Vulnerability management and responsible disclosure

We monitor for and remediate vulnerabilities in our systems and dependencies. We welcome reports from the security community — if you believe you have found a vulnerability, please email [email protected] with details, and we will acknowledge your report and work with you in good faith to resolve it. Please do not access or modify data that is not yours while testing.

Vendor and sub-processor management

We engage a limited set of sub-processors (for hosting, email, SMS, payments and monitoring), each bound by data-protection and confidentiality obligations. See our Privacy Policy and Data Processing Agreement for detail; a current sub-processor list is available on request.

Compliance alignment

Quzek is built to support the privacy and security obligations of GDPR, HIPAA, the Australian Privacy Principles, PIPEDA, CCPA and POPIA, and we follow enterprise-grade security practices aligned with recognised standards such as ISO 27001. We are transparent about which formal certifications we do and do not currently hold — contact us for the latest details for a due-diligence review, and see our Compliance page. For US healthcare providers we can provide a Business Associate Agreement (BAA); for GDPR we can provide a Data Processing Agreement (DPA).

Incident response

We maintain an incident-response process to detect, contain and remediate security incidents. If a personal-data breach affects a practice's data, we will notify the affected practice without undue delay and provide the information reasonably needed for it to meet its own notification duties (for example the GDPR 72-hour rule, the Australian NDB scheme, or the HIPAA Breach Rule).

Your role in security

You can strengthen your practice's security by enabling two-factor authentication, giving each team member their own account with the least access they need, using strong unique passwords, reviewing your users regularly, and logging out on shared devices. Quzek gives you the tools; using them well keeps your clients' information safe.

Security questions, answered

Is my data encrypted?
Yes — in transit with TLS and at rest with strong encryption, plus field-level encryption for sensitive clinical notes. Passwords are stored only as one-way hashes.
Can another practice see my data?
No. Each practice runs in its own isolated database, so your data is never accessible to another practice.
Do you support two-factor authentication?
Yes. Optional app-based 2FA (TOTP) is available for every staff account, with encrypted secrets and one-time recovery codes.
How do I report a security issue?
Email [email protected] with details. We acknowledge reports and work with researchers in good faith to resolve them.

Run your practice on a platform you can trust

Start a free 14-day trial and see how Quzek keeps your schedule and your data safe.

Start your free trial