2. Accounts and authentication
CRM accounts use Supabase authentication with account/session handling and password/invitation/recovery flows. Application access depends on authenticated identity, account state and role checks.
This statement does not represent that multi-factor authentication is enforced for all CRM accounts. Customers should review the authentication controls actually available and agree any additional requirements before relying on them.
3. Organization and permission controls
The service uses organization-scoped records, server-side permission checks and database row-level security on core operational tables. Assigned professionals and clients have restricted workflows and data projections. Privileged service operations require separate authorization and organization scoping.
These controls are not a claim that every authorization path has passed an independent security assessment. Organizations must review roles, assignments and releases and remove access when staff leave or responsibilities change.
4. Documents and sensitive records
Case documents are stored through private storage and controlled retrieval paths. Customer branding assets can be public; they must not contain confidential case information. Document uploads have file-type/content-signature checks in relevant flows.
File validation does not establish that every document has been malware-scanned or that its contents are safe or lawful. Customers should submit only necessary information and restrict medical, police, identity, financial and dependant records to authorized users.
5. Network protection and infrastructure
The production service and reviewed provider API connections use HTTPS. This page makes no separate unverified claim about every provider’s encryption-at-rest configuration, key management or customer-managed keys.
The reviewed primary database configuration is in Canada; the web/function runtime is in the United States. Provider support, backups and onward processing can have a different scope. See the Subprocessor List and Privacy Notice before agreeing residency requirements.
6. Audit records and accountability
The application records selected account, workflow, document, export, integration and permission events for accountability and troubleshooting. Coverage varies by operation; this is not a promise that every action is logged or that logs are immutable.
Audit records can contain personal information and changes to records. Access and retention require the same care as other confidential information. A recovery manifest contains service metadata and does not replace a database or file backup.
7. Development and dependency checks
The source includes build checks, TypeScript/lint checks and targeted regression tests, including permission and tenant-boundary tests. These are engineering checks, not evidence of a penetration test, continuous vulnerability monitoring or independent certification.
Identified weaknesses must be prioritized and remediated according to risk. No SOC 2, ISO 27001, 24/7 monitoring, WAF configuration or completed independent penetration-test claim is made here.
8. Backups, recovery and exports
Backup coverage, file-object coverage, retention and recovery objectives must be established under the actual provider plan and customer agreement. This page does not promise a verified restore test, fixed recovery time or complete backup deletion cycle.
The Manager organization export excludes document and attachment binary files and is not a complete backup. Customers should agree complete return/archival arrangements and maintain any independent archive required by their professional obligations.
9. Incidents and notifications
HQL will investigate suspected security incidents, take reasonable containment and remediation steps and provide notifications to affected customers, individuals or authorities where required by applicable law and contracts. A completed investigation is not a prerequisite to any earlier notification required by applicable law or contract. The customer remains responsible for duties attached to its role; HQL retains its own non-transferable duties.
Notifications depend on the incident and legal regime. There is no single worldwide notification deadline. Preserve relevant evidence and report suspected compromise promptly through the authorized contact.
10. Connected services and AI
Enabled integrations can transfer information beyond the CRM’s primary infrastructure. AI document analysis can send complete file contents to an external model service. Customers must assess necessity, sensitivity, provider terms and transfer arrangements before enabling these functions.
A vendor’s security documentation or certification does not certify HQL’s application or establish that every optional service is configured appropriately. See AI processing in the Privacy Notice.
11. Customer security responsibilities
- Protect credentials, avoid shared personal accounts and use secure, supported devices and networks.
- Review access, assignments and offboarding, and train users on phishing and confidentiality.
- Limit sensitive uploads and exports to a lawful purpose and authorized recipients.
- Assess and authorize integrations and any additional controls required by law or professional rules.
- Report suspected access, accidental disclosure, lost devices or compromised credentials promptly.
12. Vulnerability reporting and contact
Report suspected vulnerabilities or security incidents privately to Prasad Bhange at admin@hqlsolutions.com, the shared HQL legal, privacy and security contact. Provide a description and minimal reproduction steps; avoid sending client files or secrets. Postal correspondence may be sent to G1 Carlisle Court, Clover Village, Wanawadi, Pune 411040, Maharashtra, India. Do not access other users’ data, disrupt the service or exploit an issue beyond authorized research.
This page does not establish a bug bounty or unrestricted authorization to probe the service. Responsible reporting and any restrictions remain subject to applicable mandatory law.
13. Limitations and review
No internet-connected system can be guaranteed completely secure. Requirements such as enforced MFA, independent testing, residency or recovery objectives must be checked and expressly agreed where needed. Review the applicable agreement and the page’s revision date before relying on a specific control.
