Trust & security fact sheet

Trust & Security

How qReflector handles vulnerability scan reports and the cryptographic evidence they contain: where the data runs, how environments are isolated, who has access, and who operates the product.

Back to Product

How Customer Evidence Is Handled

The first review starts with the vulnerability scan reports your team chooses to provide — Nessus, OpenVAS or Qualys XML. Everything below applies to that evidence and the findings derived from it.

Hosting and Data Location

qReflector runs as a hosted application in a data centre in Prague, in the EU. Uploaded reports and derived findings are processed there.

Environment Isolation

Each customer receives a separately provisioned environment, kept isolated from other customer environments.

Access Control

Access to a customer environment is limited to the customer's authorised users and ITS support.

Selected Uploads

Teams begin with files they already control. Deeper discovery can be discussed later, when the scope and deployment model are clear.

Traceable Findings

Each cryptographic finding stays connected to the host and service it was detected on, so teams can verify why it was flagged.

Certifications

ITS a.s. holds ISO 27001 (information security) and ISO 9001 (quality management) certification for its company management system, within which qReflector is developed and operated.

Operator

qReflector is developed and operated by ITS a.s., a Czech IT company working in cybersecurity, infrastructure, cloud services and B2B application delivery.

Czech IT Company Since 1990 ITS has operated in the Czech IT market since 1990.
50+ IT Experts The ITS team brings cybersecurity, infrastructure, cloud and application delivery experience into the product.
200+ Customers ITS has experience from more than 200 customer deliveries.
Own Separated Data Centres ITS operates its own geographically separated data centres.

Deployment details, data handling and retention are agreed during access setup, before customer evidence is processed.

Security Review Contact

Questions about hosting, isolation, access control or data handling — before any evidence is provided — go to [email protected].

Back to Product