QIndex One is built with enterprise-grade security. We protect your client data with controls aligned to ISO 27001:2022 and Australian privacy regulations, and we are working toward formal SOC 2 Type 1 attestation (target Q3 2026).
Read our policies or download them as PDF documents for your records.
Version 3.0 • Effective 17 February 2026
Version 3.0 • Effective 17 February 2026
Version 3.0 • Effective 17 February 2026
Version 2.0 • Effective 17 February 2026
Version 2.0 • Effective 17 February 2026
Version 2.0 • Effective 17 February 2026
Version 1.0 • Effective 17 February 2026
A single look at every system that touches customer data on QIndex One. Each route is authenticated, encrypted in transit (TLS 1.3) and at rest (AES‑256).
Request path
You
Browser session
QIndex One Backend
FastAPI on Emergent Labs
Managed MongoDB
Account, client, task, link, folder, doc metadata, audit logs
Managed Object Storage
Uploaded document files (qindex-one/clients/{id}/...)
On-demand integrations
Managed AI Gateway
Gemini · GPT · Claude — no training on your data, audit-logged, org-toggleable
Resend
Transactional email — portal invites, password resets, weekly digests
Cloud File Picker SDKs
Dropbox · Google Drive · OneDrive — loaded only when you click "Link from cloud"; file contents are not transmitted to QIndex One
The full Sub-processors document, with provider names, role, data category and region for each row above, is downloadable as a PDF.
QIndex One is trusted by family offices and financial advisers across Australia. We're committed to maintaining the highest standards of security and compliance.
Made with Emergent