Security
How your data is protected
You are putting your client list, your pricing and your payment history into QuipDesk. Here is a straight account of how that is looked after — no certifications we do not hold, no vague reassurance.
The essentials
Six things worth knowing
Encrypted in transit and at rest
Every connection to QuipDesk runs over HTTPS with a valid certificate, and stored data is encrypted at rest by the underlying platform.
Your data is isolated from everyone else's
Separation between businesses is enforced at the database level with row-level security, not by application code remembering to filter. A query from one workspace cannot return another workspace's rows.
Gateway credentials stay encrypted
Your PayFast, Yoco or Paystack keys are stored encrypted and decrypted server-side only when a payment is created or a webhook is verified. They are never sent to the browser.
We never hold card details
Card data is entered on your payment gateway's own hosted page. It does not pass through QuipDesk, so your card exposure stays with a PCI-compliant provider.
Audit trail on the things that matter
Document changes, sends, payments, portal access and workspace administration are logged with who did what and when, so an unexpected change can be traced.
Backups and recovery
The database is backed up automatically on a rolling schedule with point-in-time recovery on the managed platform, and self-hosted deployments ship with a scripted backup routine.
Access control inside your workspace
Team members are invited to a specific workspace with a role that determines what they can see and do. Client portal access uses a long random token per client, which you can revoke and reissue at any time from the client's profile — useful if a link was forwarded to someone it should not have been.
Sign-in
You can sign in with an email and password, with a magic link sent to your inbox, or with Google. Password sign-up enforces a strength check, and sessions can be kept or dropped at the end of a browser session using the "remember me" option.
Your data belongs to you
Every list and report exports to CSV or PDF, at any time, on every plan. If you decide QuipDesk is not for you, you leave with your data. There is no export fee and no waiting period.
POPIA
For the information you enter about your own clients, you are the responsible party and QuipDesk acts as an operator on your behalf. The privacy and POPIA statement sets out what we collect, how long it is kept and how to make a request.
Reporting a security issue
If you believe you have found a vulnerability, please report it to us directly rather than publicly. Send the details to info@quipdesk.co.za and we will acknowledge it and keep you updated on the fix. We will not take action against anyone reporting an issue in good faith.
