SECURITY & COMPLIANCE
Built on a foundation
of trust
Qalyptus solutions are designed to deliver reliable, scalable, and secure reporting environments. Whether you deploy Qalyptus on‑premises or choose Qalyptus Cloud, our architecture and user experience are built to help you meet your requirements for security, governance, compliance, and privacy.
ISO/IEC 27001:2022
Internationally certified
information security
Qalyptus has achieved ISO 27001 certification, the gold standard for information security management systems. This certification is awarded after a rigorous independent audit of our systems, policies, and controls.

ISO/IEC 27001:2022 Certified
This certification applies to both Qalyptus Cloud and Qalyptus Self-hosted, giving your procurement and IT security teams the documentation they need.
What this certification covers
The scope of our ISO 27001 certification encompasses all systems, processes, and infrastructure used to design, develop, deliver, and operate Qalyptus products.
-
✓
Cloud infrastructure and data storage systems
-
✓
Access control and identity management
-
✓
Incident response and business continuity
-
✓
Software development and deployment pipelines
-
✓
Vendor and third-party risk management
-
✓
Regular surveillance audits and continuous improvement
SECURITY PRACTICES
How we protect
your data
Security is built into every layer of Qalyptus, from the way we store data to how we manage secrets to how we connect to your Qlik Sense environment.
Minimal data retention
Qalyptus Cloud does not retain any data generated from Qlik Sense. We store only report template files and your configuration settings. Qalyptus Self-hosted works entirely offline.
Secure software development lifecycle
Qalyptus uses an adapted SAFe model and QA best practices. We embed security into development through static code analysis, threat modeling, and third‑party vulnerability scanning.
Secret-less architecture
Sensitive data is encrypted with private keys stored in a Key Vault. Our secret-less strategy ensures that encrypted data cannot be read even if services are compromised.
Automatic API key rotation
Qalyptus Cloud connects to your Qlik Sense tenant via a Qlik Sense API key that is automatically rotated. We recommend using a short expiration window for your initial key.
Regular security audits
We conduct regular security audits and vulnerability assessments to proactively identify and remediate risks before they can be exploited.
Privacy
Your data is critical. Qalyptus protects it through security and privacy-by-design approaches, ensuring compliance with global regulations such as the GDPR.
SHARED RESPONSIBILITY
Security is a partnership
Whether you choose Qalyptus Cloud or deploy Qalyptus yourself, we provide a world-class architecture designed to meet your security, compliance, and privacy needs.
-
✓
Qalyptus Cloud: fully managed infrastructure, security, and compliance handled by us
-
✓
Qalyptus Self-hosted: deploy in your own environment with full control over your data and network
-
✓
ISO 27001 certification applies to both deployment models
-
✓
All our cloud providers hold internationally recognized information security certifications, such as ISO/IEC 27001 and SOC 2
-
✓
Security documentation and certificate available on request for compliance reviews
Have a security question?
Our team is happy to provide documentation, answer compliance questionnaires, or walk you through our security architecture.
