Key featuresFeaturesPricingSecurityDocsChangelog
Log inStart for free

The issue tracker you use with your AI agent. Your agent fixes; QA Note keeps the record.

Made in Seoul · © 2026 QA Note
ProductKey featuresFeaturesPricingSecurityChangelog
ResourcesDocsMCP guideChrome Extension
CompanyBrandTerms of ServicePrivacy Policy

ffgg|CEO: Songwook Han

Business Registration No.: 746-54-00870[Verify]|E-Commerce License No.: 2024-Seoul Mapo-2178

Address: 5F, 26 World Cup buk-ro 6-gil, Mapo-gu, Seoul, Republic of Korea

Email: support@qanote.app|Hosting Provider: Vercel Inc.

© 2026 QA Note. All rights reserved.

Terms of ServicePrivacy PolicyCookie Policy

Security

QA Note keeps your QA data safe and secure

Last updated: June 12, 2026

Overview

QA Note prioritizes customer data protection. We maintain industry-standard security practices and comply with GDPR standards.

Compliance

  • PIPA 2025: Compliance with key provisions
  • GDPR: EU General Data Protection Regulation compliance
  • ICT Network Act: Communication privacy and spam prevention
  • Cloud Computing Act: User data protection and portability
  • Public privacy policy
  • Cookie consent management
ISMS-P Certification Roadmap: We plan to pursue KISA Information Security Management System certification as the service grows.

Data Encryption

  • In transit: TLS 1.2+ (HTTPS enforced, HSTS preload)
  • At rest: Infrastructure-level AES-256 encryption (database and file storage)
  • Passwords: argon2id hashing (OWASP-recommended parameters)
  • Tokens: Session tokens stored as SHA-256 hashes; external integration tokens (GitHub, Slack, etc.) encrypted with AES-256-GCM

Infrastructure Security

  • Hosting: Vercel (AWS-based, SOC 2 certified)
  • Database: Supabase (AWS, SOC 2 certified)
  • File storage: Cloudflare R2 (SOC 2 · ISO 27001 certified)

All infrastructure providers hold industry-standard security certifications.

Access Control

  • RBAC (Role-Based Access Control): Organization (Owner, Admin, Member) · Project (Admin, Member, Viewer)
  • Principle of least privilege applied
  • Independent permissions per project
  • Invitation-based member onboarding

Data Ownership

  • Customer data is entirely owned by the customer
  • Data is never sold or shared with third parties
  • All data permanently deleted 30 days after account deletion (including R2 files)

Sensitive Data Protection

  • Pattern-based automatic sensitive data filtering in network requests
  • Auto-masking of auth headers, API keys, tokens, and session IDs
  • Removal of sensitive fields from URL parameters and request/response bodies (pattern-based — non-standard fields can be controlled via capture settings)

Backup & Recovery

  • Supabase managed automatic database backups
  • Weekly automated storage–database consistency checks
  • Automatic cleanup per data retention policy (deletion evidence recorded in audit logs)

Monitoring & Auditing

  • Security audit logging (failed logins, rate limit blocks, permission changes, account deletions, data deletion evidence, etc.)
  • Real-time security alerts to the operations team on risky events
  • Continuous monitoring of abuse signals such as signup and storage spikes

Application Security

  • Security headers on every page (CSP, HSTS preload, clickjacking protection)
  • Tiered rate limiting on login, signup, email sending, uploads, and AI calls
  • API input schema validation (Zod), open redirect and SSRF protection

Integration Security

  • OAuth 2.0 standard (GitHub, Google)
  • Slack integration: OAuth V2 authentication
  • HMAC signature verification on all inbound webhooks (GitHub, payments, email)
  • Strict CORS policy

Payment Security

  • New Pilot payments paused · PortOne processing when enabled
  • Card information is never stored directly
  • All payment communications encrypted

AI Data Policy

  • No training: User data is never used to train our own or third-party AI models
  • Minimal transfer: Only minimal metadata is sent when using AI features
  • No retention: AI providers do not use API inputs for training and purge them after short-term retention for abuse monitoring
  • Injection defense: Externally sourced content (reports, inbound bodies) is isolated in fenced blocks, and the context passed to AI is separated from execution permissions

Vulnerability Reporting

If you discover a security vulnerability, please contact us at security@qanote.app. We support Responsible Disclosure. Reported vulnerabilities are prioritized.