QualityOS Docs
Docs/Security & Compliance/Enterprise & DPA

Enterprise & DPA

Data Processing Agreement availability, compliance roadmap, and what's included in the Enterprise security package.

Data Processing Agreement

A standard DPA (GDPR Article 28 compliant) is available for all Enterprise customers on the $499/month plan. It covers:

  • Subject matter and duration of processing
  • Nature and purpose of the processing
  • Type of personal data and categories of data subjects
  • Obligations and rights of the controller
  • Sub-processor list with DPA references

Request a DPA

Email us with the subject line Enterprise security review — QualityOS.

Send email →

Compliance roadmap

Encryption in transit (TLS 1.2+)

Live

Encryption at rest (AES-256)

Live

Org-level row isolation

Live

API key scoping per org

Live

DPA available on request

Live

GDPR — data minimisation

Partial

CCPA — deletion on request

Partial

SSO / SAML (Clerk Enterprise)

Q3 2026

SOC 2 Type II

Q4 2026

Enterprise security package

Enterprise customers ($499/month) receive the following on request:

Signed DPA

GDPR Article 28 compliant. Returned within 5 business days.

Sub-processor list

Complete list with individual DPA references for each vendor.

Security questionnaires

Pre-completed VSA and SIG Lite questionnaires for your procurement team.

Custom data retention

Configure scorecard retention periods beyond the default account lifetime.

Dedicated Slack channel

Direct line to the QualityOS team for incident communication and support.

Auditor engagement letter

If your procurement requires SOC 2 before Q4 2026, we provide a letter of engagement from our auditor.

Ready to start an enterprise security review?

We aim to acknowledge all requests within 48 hours.

Request enterprise security review →