Qilin.Cloud
Trust Center
At Qilin.Cloud, security, privacy and operational transparency are core architectural concerns.
Qilin.Cloud is an integration and orchestration platform that may connect business-critical systems, process operational data and execute workflows across organizational and technical boundaries. Security therefore needs to be considered throughout the platform architecture rather than added as a separate feature.
Qilin.Cloud is currently a development-stage, pre-production platform. This Trust Center distinguishes between security principles already implemented in the platform, controls that depend on the individual deployment environment, and capabilities that are currently being validated as part of our security assessment.
Security
We build security controls into multiple layers of the Qilin.Cloud platform, including identity, authorization, tenant context, APIs, application services, data access, credentials, runtime execution and operational traceability.
Our objective is defense in depth: security should not depend on a single technical control.
Availability
Qilin.Cloud is designed around modular services, asynchronous processing and separately managed persistence layers.
Current development and audit environments may intentionally use simplified infrastructure. Production availability, redundancy and recovery requirements are therefore evaluated for the specific target deployment rather than inferred from development infrastructure.
Privacy
Qilin.Cloud is designed with privacy and data-protection principles in mind.
The platform provides architectural mechanisms such as access control, logical tenant separation, controlled data flows and operational traceability. Actual regulatory obligations depend on the customer’s data, processing purposes, deployment and contractual setup.
Compliance
Qilin.Cloud uses established security, privacy and cloud-engineering practices as references for platform development.
We distinguish explicitly between using a standard as an engineering reference and holding a formal certification or attestation. Certifications are only claimed where their scope, issuing organization and validity can be demonstrated.
Security
The Qilin.Cloud technology platform is designed to provide security across multiple technical layers.
Qilin.Cloud separates platform management, data ingestion, domain services, execution and operational tracking into distinct responsibilities. Identity, tenant context, authorization, API management, data access and deployment controls are designed to work together rather than relying on a single security boundary.
Security controls are continuously reviewed as the platform develops. The current security assessment specifically validates whether these controls are consistently enforced across APIs, services, execution paths and data stores.
Managing data responsibly is of highest priority.
Qilin.Cloud is designed as a multi-tenant platform.
A Subscription represents the primary logical tenant boundary within the platform. Users, permissions, channels, pipelines and execution information are associated with subscription context.
Tenant identity is propagated through authenticated platform context and is intended to be enforced when application services access tenant-scoped resources.
Cross-tenant isolation is an explicit subject of the current security assessment and is being validated using separate audit subscriptions.
Physical security
Qilin.Cloud is deployed using cloud infrastructure such as Microsoft Azure and additional managed technology providers where required.
Physical security of cloud data centers is primarily provided by the respective infrastructure providers.
The exact providers, services, regions and infrastructure configuration may vary between Qilin.Cloud environments and should therefore be evaluated for the individual deployment.
Network Security
Externally exposed Qilin.Cloud services are designed to use encrypted HTTPS communication and modern TLS configurations.
Azure API Management is used as a central API-management layer for externally exposed Qilin APIs.
Depending on the service and environment, network and API controls may include:
- token validation;
- authorization;
- request routing;
- rate limits;
- quotas;
- diagnostics;
- service-specific network restrictions.
The security assessment also verifies whether application backends can be accessed in a way that bypasses intended API-management controls.
Development or audit environments may intentionally use less restrictive network configurations than a hardened production deployment. Such configurations are treated as environment-specific and are not presented as the intended production security baseline.
Backup and Recovery
Backup and recovery requirements differ between Qilin.Cloud services and storage technologies.
A complete recovery strategy needs to consider, among other things:
- source code;
- infrastructure definitions;
- application configuration;
- relational databases;
- document databases;
- cloud storage;
- credentials and identities;
- external managed services.
Qilin.Cloud does not currently claim that every production disaster-recovery scenario has already been operationally demonstrated.
Backup configuration, restore capability and recovery procedures are part of production-readiness validation for the respective environment.
Operational security
Qilin.Cloud uses version-controlled source code, documented deployment processes and Infrastructure as Code for substantial parts of the platform infrastructure.
Terraform is used for major Azure infrastructure components, while automated deployment workflows are used for major application components.
Some external dependencies and operational procedures still require environment-specific or manual configuration. These are documented separately rather than represented as fully automated.
Security-sensitive operational areas such as secrets, privileged access, deployment identities and runtime configuration are included in the current technical assessment.
Training and Awareness
Security is not treated solely as a technical problem.
Development and operational decisions are expected to consider secure handling of source code, credentials, personal data, infrastructure access and customer information.
Where employees, contractors or external partners receive access to Qilin.Cloud systems, appropriate confidentiality and access controls are expected to apply.
Availability
Qilin.Cloud is currently a development-stage, pre-production platform.
For this reason, Qilin.Cloud does not currently publish a general production availability SLA through this Trust Center.
The platform architecture separates API services, ingestion, persistent data, asynchronous processing, runtime execution and operational tracking. This separation is intended to support scalable and resilient production architectures.
Development, demonstration and audit environments may intentionally use simplified infrastructure. For example, selected runtime components may run on a limited number of virtual machines where this is appropriate for development or validation.
Such environments should not be interpreted as evidence of a production high-availability topology.
A production deployment may introduce additional resilience measures based on its requirements, including:
- horizontal scaling;
- redundant runtime nodes;
- database high availability;
- managed service scaling;
- regional redundancy;
- health monitoring;
- automated recovery.
Specific uptime targets, availability commitments and recovery objectives should be defined for the actual production architecture.
Planned Servicing Period
Maintenance and deployment processes depend on the applicable environment and service model.
For future production environments, planned maintenance, customer communication and operational maintenance windows should be defined as part of the applicable service-level agreement or operational agreement.
Qilin.Cloud does not currently publish a universal annual maintenance allowance.
Exclusions
Availability commitments, where agreed for a future production environment, should define exclusions explicitly.
Typical exclusions may include:
- planned maintenance;
- force majeure events;
- customer-controlled systems;
- third-party systems outside Qilin.Cloud’s operational responsibility;
- misuse of the platform;
- development, test, beta or demonstration environments.
The exact exclusions should be defined contractually for the relevant production deployment.
Privacy
Trust takes years to build, seconds to break and forever to repair
Qilin.Cloud believes that personal data should be handled deliberately, transparently and in accordance with applicable privacy and data-protection requirements.
Qilin.Cloud is designed to support customers in implementing controlled data flows across connected systems.
Because the type and amount of personal data processed depends heavily on the customer’s integrations and business processes, privacy requirements need to be evaluated for each deployment and use case.
For the purpose of this section, we use terminology consistent with the EU General Data Protection Regulation where applicable.
Personal Data:
Personal Data means information relating to an identified or identifiable natural person.
Data Subject:
A Data Subject is the natural person to whom Personal Data relates.
Processing:
Processing includes operations performed on Personal Data, such as collection, storage, use, transmission, modification or deletion.
Controller:
A Controller determines the purposes and means of processing Personal Data and is responsible for the obligations applicable to that processing.
Processor:
A Processor processes Personal Data on behalf of a Controller according to the applicable contractual and legal requirements.
Privacy at the Company
Privacy & Security Program
marcos software GmbH maintains organizational and technical practices for information security and privacy.
Qilin.Cloud security and privacy engineering is informed by established standards and regulatory frameworks, including principles from ISO/IEC 27001, ISO/IEC 27701 and the GDPR.
Reference to these standards describes engineering and management principles and does not by itself imply formal certification.
Audits & Certifications
Security and privacy controls may be reviewed through internal assessments, external technical reviews and customer- or transaction-specific audits.
A certification or formal attestation is only claimed where its exact scope, issuer and validity can be demonstrated.
Privacy Roles & Responsibilities
Responsibilities for privacy and information security are assigned according to organizational and legal requirements.
Where required, external specialists or advisors may support marcos software GmbH in privacy, legal or security matters.
Employee Trainings
Employees and contractors with access to sensitive systems or information are expected to follow applicable security and confidentiality requirements.
Training and awareness activities may be provided according to role and organizational need.
Confidentiality
Employees, contractors and relevant partners are required to protect confidential information according to their contractual obligations and applicable company policies.
Vendor Management
External service providers are evaluated according to their role and the risks associated with the service they provide.
Where legally required, appropriate data-processing agreements, contractual protections or international-transfer mechanisms are used.
Privacy Register
Where required by applicable law, processing activities and relevant data flows are documented.
The applicable documentation depends on the processing activity and the role of marcos software GmbH in that activity.
Data Subject Request
Requests relating to Data Subject rights are handled according to the applicable legal and contractual responsibilities.
Where Qilin.Cloud processes Personal Data on behalf of a customer, responsibilities between Controller and Processor are defined according to the relevant contractual relationship.
Security Incidents & Personal Data Breaches
Potential security incidents and Personal Data Breaches are assessed according to their technical and legal significance.
Where notification obligations apply, affected parties and authorities are informed according to applicable law and contractual obligations.
Risk Assessments
Security and privacy risks are assessed where relevant to the applicable processing activity, system or deployment.
Additional privacy or transfer-impact assessments may be required for specific customer scenarios.
Privacy at the Technology Platform
Qilin.Cloud is highly configurable.
The Personal Data processed through Qilin.Cloud depends on the systems connected to the platform, the configured pipelines and processors, and the customer’s individual business processes.
The platform is designed around privacy-oriented principles such as:
- access control;
- tenant separation;
- configurable processing;
- controlled data flows;
- traceability;
- data minimization where appropriate.
Software architecture alone, however, cannot guarantee regulatory compliance. Compliance also depends on deployment, configuration, organizational processes, contracts and the actual processing purpose.
Encryption
Externally exposed Qilin.Cloud services are designed to use encrypted transport through HTTPS and modern TLS configurations.
Managed database and storage technologies used by Qilin.Cloud provide encryption-at-rest capabilities.
Because the underlying storage technologies differ, encryption configuration and key management are validated individually for each relevant service rather than represented as one universal encryption algorithm.
Login Security
Qilin.Cloud’s current identity architecture is based on Microsoft Entra ID.
Authenticated identities can be enriched with Qilin-specific information such as:
- user identity;
- subscription identity;
- user type;
- permissions;
- plan information;
- usage limits.
Role- and permission-based access mechanisms are used within the platform.
Controls such as MFA, Conditional Access or IP restrictions may depend on the applicable Microsoft Entra and deployment configuration and are therefore not represented as universally enabled unless verified for the relevant environment.
Confidentiality
Qilin.Cloud provides role- and permission-based mechanisms intended to restrict access to subscription-scoped information.
Operational traceability is provided through mechanisms including Data Flow Tracking, pipeline execution records, processor execution records and identity-related activity information.
These systems provide auditability and operational history.
Qilin.Cloud does not describe these records as cryptographically tamper-proof unless that property has been separately implemented and demonstrated.
Data Deletion
Deletion and retention requirements depend on the type of data, service and customer use case.
Qilin.Cloud includes data-management capabilities, but retention and deletion policies should be configured and validated for the individual deployment.
SCC
Where Personal Data is transferred internationally and Standard Contractual Clauses are an appropriate transfer mechanism, the applicable current European Commission clauses may be used as part of the contractual setup.
The appropriate transfer mechanism depends on the specific parties, jurisdictions and processing activity.
Hosting location
Qilin.Cloud can be deployed using cloud infrastructure appropriate to the respective project.
Hosting region, data residency and any geographic restrictions should be explicitly defined for the applicable deployment.
Qilin.Cloud does not assume that every environment uses the same cloud region or geographic architecture.
Government Access
Any legally binding government or authority request would be assessed according to the applicable legal requirements and contractual obligations.
Where legally permitted and required, affected customers would be informed according to the applicable contractual and legal framework.
Compliance
We use established security and privacy frameworks as references for engineering and governance.
Standards and regulations can provide useful requirements and engineering principles.
However, using a standard as a reference is not the same as holding a certification or formal attestation.
Qilin.Cloud only claims a certification or formal compliance status where the certification, scope, issuing organization and validity can be explicitly demonstrated.
CCPA
California Consumer Privacy Act
PCI DSS
Payment Card Industry Data Security Standard
PIPL
Personal Information Protection Law of the People’s Republic of China
GDPR
General Data Protection Regulation
ISO 27001
Information Security Management System
ISO 27701
Privacy Information Management System
Ready for the leverage?
Choose the Qilin.Cloud technology platform for your business now.