Security Statement

Last Updated: June 15, 2026

1. Infrastructure & Hosting

QueueDesk runs on enterprise-grade cloud infrastructure operated by providers who hold SOC 2 Type II certification. Physical access controls, environmental monitoring, and power redundancy are managed by our hosting partners. All production workloads are deployed in isolated environments with no shared compute between tenants.

2. Tenant Data Isolation

Every data access in QueueDesk is scoped to the authenticated organisation. Our application layer enforces an explicit organisation-level filter on every database query — it is not possible for a query to execute without a validated tenant context. This logical isolation is complemented by database-level row security policies that act as an independent failsafe against cross-tenant data access.

3. Encryption in Transit and at Rest

All communication between clients and QueueDesk is encrypted using TLS 1.3. Data at rest — including database records, file attachments, and configuration — is encrypted using AES-256. Encryption keys are managed by our cloud providers' dedicated key management services, separate from the data they protect.

4. Authentication & Access Control

QueueDesk enforces role-based access control (RBAC) across five distinct user roles: owner, admin, agent, employee, and super admin. Authentication uses industry-standard session management with secure, HTTP-only cookies scoped to the platform domain. Each role is restricted to its own route namespace and API surface — employees cannot access agent tooling, agents cannot access billing or admin settings, and so on. Session cookies are not cached in third-party edge networks to avoid exposure of session material.

5. Email Security

All outbound email sent by QueueDesk is cryptographically signed using DKIM, protecting against spoofing and ensuring message integrity. Inbound email processing uses a multi-stage pipeline with deduplication and strict MIME parsing. Inbound messages are stored transiently in a secure, access-controlled object store before being processed and persisted; raw email content is not retained beyond what is needed for ticket creation.

6. AI Processing

AI-assisted triage runs in isolated inference environments in the same region as your data. Ticket content sent for AI processing is not used to train models. AI outputs are advisory — no automated action is taken without explicit configuration and a human-confirmable step where applicable.

7. Vulnerability Disclosure

If you discover a security vulnerability in QueueDesk, please report it responsibly to security@queuedesk.com. We review all reports and aim to respond within 48 hours. We do not pursue legal action against good-faith security researchers.

Questions about security?

For security questions, data processing agreements, or compliance requests, contact security@queuedesk.com.