Security at QuotaGuard
No payload stored in any mode.
Decryption in exactly one mode, by design.
How QuotaGuard Static and QuotaGuard Shield handle your traffic, what we log, what we never see, and the documentation behind every claim on this page.
Certifications
QuotaGuard is not certified. It does not hold a SOC 2 report, HITRUST certification, or an independent HIPAA audit report. QuotaGuard re-evaluates its certification posture annually. The controls QuotaGuard operates are described in its published Information Security Policy and Data Flow documents, with detailed operational documents available under NDA.
HIPAA
QuotaGuard is designed to support HIPAA workloads. QuotaGuard Shield routes encrypted traffic without decrypting customer application payload, and QuotaGuard does not receive customer TLS private keys. A Business Associate Agreement is available on qualifying QuotaGuard Shield plans. QuotaGuard does not offer QuotaGuard Static for HIPAA workloads; Shield is the supported product for regulated data.
PCI-DSS
QuotaGuard helps customers maintain PCI-DSS scope boundaries. Shield's passthrough design keeps QuotaGuard outside the path of decrypted cardholder data. QuotaGuard does not represent itself as PCI-DSS certified.
Track record and contact
QuotaGuard has had no reportable security incidents in the 36 months preceding June 2026. Security inquiries and reports are received at security@quotaguard.com.
Security documentation
Information Security Policy
Access control, encryption, data classification, and the governing data-handling principle.
PublicData Flow
What is decrypted, logged, and stored in each of the four traffic modes, with diagrams.
PublicSubprocessors
Every third-party provider in the QuotaGuard service, and what each one is for.
Detailed documentation under NDA
For security reviews and vendor assessments, QuotaGuard provides its detailed operational documentation under a single mutual confidentiality agreement:
- Access Control and Provisioning Note
- Incident Response Policy
- Vulnerability and Patch Management Statement
- Business Continuity and Disaster Recovery Summary
- Subprocessor List, detailed version (regions and data categories)