Security at QuotaGuard

No payload stored in any mode.
Decryption in exactly one mode, by design.

How QuotaGuard Static and QuotaGuard Shield handle your traffic, what we log, what we never see, and the documentation behind every claim on this page.

Certifications

QuotaGuard is not certified. It does not hold a SOC 2 report, HITRUST certification, or an independent HIPAA audit report. QuotaGuard re-evaluates its certification posture annually. The controls QuotaGuard operates are described in its published Information Security Policy and Data Flow documents, with detailed operational documents available under NDA.

HIPAA

QuotaGuard is designed to support HIPAA workloads. QuotaGuard Shield routes encrypted traffic without decrypting customer application payload, and QuotaGuard does not receive customer TLS private keys. A Business Associate Agreement is available on qualifying QuotaGuard Shield plans. QuotaGuard does not offer QuotaGuard Static for HIPAA workloads; Shield is the supported product for regulated data.

PCI-DSS

QuotaGuard helps customers maintain PCI-DSS scope boundaries. Shield's passthrough design keeps QuotaGuard outside the path of decrypted cardholder data. QuotaGuard does not represent itself as PCI-DSS certified.

Track record and contact

QuotaGuard has had no reportable security incidents in the 36 months preceding June 2026. Security inquiries and reports are received at security@quotaguard.com.

Security documentation

Detailed documentation under NDA

Available under NDA

For security reviews and vendor assessments, QuotaGuard provides its detailed operational documentation under a single mutual confidentiality agreement:

  • Access Control and Provisioning Note
  • Incident Response Policy
  • Vulnerability and Patch Management Statement
  • Business Continuity and Disaster Recovery Summary
  • Subprocessor List, detailed version (regions and data categories)

Request access