Security and compliance

Qvera’s organizational controls are independently examined under SOC 2 Type 2. QIE provides authentication, authorization, encryption, logging, and data-retention controls within customers’ own deployments.

What does Qvera’s SOC 2 Type 2 report cover?

Qvera’s second independent SOC 2 Type 2 report, dated November 24, 2025, covers the period from October 1, 2024 through September 30, 2025. ControlCase SOC Audit Services examined Qvera’s Software and Services System against the Security, Availability, and Confidentiality Trust Services Criteria.

Examination Report date Coverage
SOC 2 Type 1 June 10, 2024 As of May 31, 2024
First SOC 2 Type 2 December 2, 2024 April 1–September 30, 2024
Second SOC 2 Type 2 November 24, 2025 October 1, 2024–September 30, 2025

The report addresses Qvera’s controls for its software and services, including management, hosting, and professional services. The report does not extend to customer-operated QIE environments. The QIE controls described below are product capabilities that each customer configures within its own deployment.

The report is restricted-use material. Customers and qualified prospective customers can request a copy from Qvera.

Qvera SOC 2 Type 2 attestation

How does Qvera handle HIPAA and Business Associate Agreements?

Qvera enters into Business Associate Agreements where applicable for services involving protected health information (PHI). The scope depends on the service being provided. A QIE license for software running entirely in a customer-controlled environment does not, by itself, place that customer’s PHI in Qvera’s possession.

When Qvera provides hosting or managed services that involve PHI, Qvera’s policies require PHI to be used and disclosed only as permitted by HIPAA and applicable agreements.

Where is customer data stored?

QIE can run on customer-controlled Windows or Linux servers, in Docker or Kubernetes, or in a customer’s own cloud environment. Messages and configuration are stored in a customer-configured Microsoft SQL Server, MySQL, or MariaDB database. Customers configure message persistence by channel and set retention policies at the system or channel level.

For Qvera-hosted engagements, PHI is stored and processed within segregated customer environments in Qvera’s hosted infrastructure. Data location, access, and retention requirements are governed by the applicable service agreement and BAA, where applicable.

How does Qvera test and manage security?

Qvera performs independent external network and application penetration testing annually and after significant changes. Qvera’s November 18, 2025 test was performed by TraceSecurity.

Qvera uses Rapid7 for ongoing vulnerability management. Product and third-party vulnerabilities are assessed using CVSS, prioritized by severity, and addressed through the appropriate hotfix, configuration guidance, or product release. Security advisories are communicated through product release notes.

To report a suspected QIE or Qvera product security issue, email support@qvera.com.

What security controls are built into QIE?

  • Authentication. Local accounts, LDAP directory authentication (including LDAPS), and OpenID Connect (OIDC) identity providers. LDAP groups and OIDC claims can map to QIE roles.
  • Role-based access. Permissions are scoped by zone, with access levels for viewing, managing, editing, and resolving message errors. Zones isolate channels and their connections, variables, mappings, certificates, and keys.
  • Connection security. Administrators can configure HTTPS for the management console and TLS or mutual TLS on supported inbound and outbound interface connections. Built-in certificate management includes expiration alerts.
  • Message storage. Message content written to the QIE database is compressed and encrypted by QIE before it is stored, using an encryption key generated when the system is installed. This is QIE’s own application level encryption and applies independently of any database or disk encryption the customer also uses.
  • Credential protection. Connection credentials, application secrets and OAuth tokens are stored encrypted. Local passwords are stored as salted hashes rather than clear text.
  • Auditability. QIE logs successful and failed authentication events, administrative actions, and channel and message activity. It also maintains user-attributed revision history for audited configuration changes. Text logs can be exported or sent to a SIEM.
  • Persistence and retention. Administrators choose message persistence levels and retention periods to match the deployment’s operational and compliance requirements.

The Qvera DICOM Router (QDR) and the Remote Management Hub (RMH) share these same security controls.

These controls are configurable. Their effectiveness depends on how QIE and its surrounding operating system, database, network, and identity services are deployed and administered.

What can Qvera provide for a vendor risk assessment?

Qvera can provide its November 24, 2025 SOC 2 Type 2 report to customers and qualified prospective customers, discuss whether a BAA applies to the planned services, and respond to security and vendor-risk questions about the proposed deployment.

Need the report, a BAA, or help with a security questionnaire?

© Copyright 2026 - Qvera - All rights reserved  |  Privacy Policy