Security
Last updated: July 25, 2026
Certifications
We don't hold a SOC 2 or ISO 27001 certification today, and we don't run a formal bug bounty program or publish third-party penetration test reports. We'd rather tell you that plainly than imply otherwise. Below is what we actually do.
What we do today
- Encrypt traffic in transit with TLS.
- Hash passwords with bcrypt, and check new and changed passwords against a database of known-breached passwords before accepting them.
- Support optional two-factor authentication for individual accounts, and org owners can require it for every member of their organization.
- Keep an audit log of membership and settings changes that organization owners and admins can review and export.
- Rate-limit login, signup, and password-reset endpoints against automated abuse.
- Expire sessions after a fixed maximum length rather than keeping them valid indefinitely.
- Offer a signed Data Processing Agreement on request for GDPR compliance — see our Privacy Policy.
Reporting a security issue
If you believe you've found a security vulnerability in QuikRing, please email security@quikring.com with enough detail to reproduce it. We'll acknowledge your report and won't pursue legal action against good-faith research that doesn't access, modify, or destroy other users' data. Please give us a reasonable chance to fix an issue before disclosing it publicly.
More information
See our Privacy Policy for how we handle personal data, or our Sub-processors page for the third parties we rely on. For a vendor security review, contact support@quikring.com.