Security

Last updated: July 25, 2026

Certifications

We don't hold a SOC 2 or ISO 27001 certification today, and we don't run a formal bug bounty program or publish third-party penetration test reports. We'd rather tell you that plainly than imply otherwise. Below is what we actually do.

What we do today

  • Encrypt traffic in transit with TLS.
  • Hash passwords with bcrypt, and check new and changed passwords against a database of known-breached passwords before accepting them.
  • Support optional two-factor authentication for individual accounts, and org owners can require it for every member of their organization.
  • Keep an audit log of membership and settings changes that organization owners and admins can review and export.
  • Rate-limit login, signup, and password-reset endpoints against automated abuse.
  • Expire sessions after a fixed maximum length rather than keeping them valid indefinitely.
  • Offer a signed Data Processing Agreement on request for GDPR compliance — see our Privacy Policy.

Reporting a security issue

If you believe you've found a security vulnerability in QuikRing, please email security@quikring.com with enough detail to reproduce it. We'll acknowledge your report and won't pursue legal action against good-faith research that doesn't access, modify, or destroy other users' data. Please give us a reasonable chance to fix an issue before disclosing it publicly.

More information

See our Privacy Policy for how we handle personal data, or our Sub-processors page for the third parties we rely on. For a vendor security review, contact support@quikring.com.

Security - QuikRing