TRUST CENTER
How Qpher protects your documents, stated plainly
Private keys are generated and used only inside an isolated key service; on client-side paths Qpher never sees the plaintext. Qpher is not zero-knowledge.
Security
Non-exportable keys, AES-256-GCM encryption at rest, tenant isolation at four layers, and an API policy engine that fails closed.
Compliance
What Qpher implements (NIST FIPS 203, 204 and 205), what has not been validated or audited yet, and how we handle GDPR and CCPA.
Data Handling
Where data is stored (the United States), how long it is kept, what deleting an account removes, and how backups work.
Incident Response
How we respond to incidents, notify customers of a personal-data breach within 72 hours, and take vulnerability reports.