At a glance
A summary of the sections below.
- No SOC 2 report today. We sign a data processing agreement (DPA) on request.
- Named subprocessors. The services that host, store or send QOPE data are listed with the data each one receives.
- Fixed retention limits. Activity records and most logs are deleted after 30 to 180 days.
- Two-factor authentication. Any user can turn on authenticator app codes in Settings.
01Infrastructure and Subprocessors
These services host, store or process data for QOPE. The last column lists the data each one receives.
| Service | What it does for QOPE | Data involved |
|---|---|---|
| Vercel | Hosts the QOPE website and app, and runs scheduled jobs | Every request to qope.org, including IP address and browser details, and application logs |
| Supabase | Database, sign-in and file storage | Everything in QOPE's database and file storage: account, team and billing records, email addresses, sign-in data, saved lists, searches and notes, activity records, contact form messages and profile pictures |
| Stripe | Payments and subscriptions | Email address, plan, and the payment details you enter in Stripe's checkout form. QOPE keeps Stripe customer and subscription IDs, never card numbers. |
| Resend | Sends account and product emails | Recipient email address and email content |
| Google (Sign in with Google) | Optional sign-in | Only if you choose it: your Google account name, email address and profile picture |
| Google Analytics 4 | Product analytics, loaded only after you accept analytics cookies | Pages viewed, product events, browser and device details, and for signed-in users the QOPE user ID. No email address or name. |
| Amazon Web Services | Hosts the QOPE data backend (api.qope.org) | Dataset queries (table, filters, search text) sent by QOPE's servers. No account identity or email address. |
Any service your browser connects to directly also sees your IP address, as it would for any website.
02Public Data Services
Some features load public government and map data from the services below. The last column shows whether the request comes from your browser or from QOPE's servers.
| Service | Used for | Request comes from |
|---|---|---|
| openpaymentsdata.cms.gov | CMS Open Payments figures on provider pages and the Map | Your browser |
| data.medicaid.gov | NADAC drug prices in Radar | Your browser |
| tiles.openfreemap.org | Map tiles and labels | Your browser |
| www.openstreetmap.org | The embedded map on provider pages | Your browser |
| nominatim.openstreetmap.org | Turning provider and facility addresses into map coordinates | QOPE's servers |
| npiregistry.cms.hhs.gov | NPI Registry details on provider pages | QOPE's servers |
Requests carry only what the lookup needs, such as an NPI number, a drug name, an address or map coordinates. They do not include your name, email address or QOPE account. Requests made from your browser also show the service your IP address.
03Application Security Controls
- HTTPS only. QOPE is served over HTTPS, and browsers are told to keep using HTTPS for the site (HSTS).
- Content Security Policy. A nonce issued on every request limits which scripts can run and which services a page can contact. Other sites cannot embed QOPE pages.
- Security headers. Pages are sent with X-Content-Type-Options, a no-referrer Referrer-Policy, X-Frame-Options and same-origin opener and resource policies.
- Request forgery checks. Server actions sent from another site are rejected by an origin check, and other form posts need a CSRF token.
- Row-level security.Every table in QOPE's database schema has row-level security turned on, so reads made as a signed-in user are limited by access policies.
- Server-side data access.Data requests need a signed-in account. The key for QOPE's data backend stays on QOPE's servers, your browser never calls the data backend directly, and table filters are checked against an allowlist before they are passed on.
- Usage limits.Dataset requests are checked on the server against the signed-in account's plan and usage limit, and results are withheld when the check fails.
- Export controls. Team owners can turn off data export for individual members, and the server refuses exports for those seats.
- Safe CSV exports. Cells that start with =, +, - or @ are escaped so spreadsheet software does not run them as formulas.
- Staff admin area. Access is checked on the server for the staff admin role. Everyone else gets a 404 page.
04Account Security
- Sign-in methods. Email and password, or Sign in with Google.
- Two-factor authentication. Optional for every user. Turn it on in Settings with an authenticator app (TOTP). Once it is on, QOPE asks for a code before opening your workspace.
- Account deletion. You can delete your account in Settings after confirming a one-time code sent to your email address. This deletes your sign-in and the data stored under your account. The records in the retention schedule below follow their own limits.
05Data Retention Schedule
Where a limit is listed, a scheduled job deletes records that pass it. The jobs run weekly for activity, Radar and notification records, and twice a day for logs, so a record can remain until the next run after its limit.
| Data | Kept for |
|---|---|
| Your account and billing records, team memberships, saved lists, searches, notes, watchlists and usage counters | While the account exists. Deleted when you delete the account. |
| Product activity log: datasets, records and features opened, and exports | 180 days |
| Radar change feed entries | 90 days |
| In-app notifications | 7 days after they expire, or 30 days after they were sent once dismissed |
| Application error reports, which can include the user ID and email address of the person affected | 30 days after last seen once resolved, 90 days if unresolved |
| Log of emails sent by QOPE staff | 180 days |
| Scheduled job logs (no personal data) | 90 days |
| Data backend health checks (no personal data) | 90 days |
| Messages sent through the contact form | No automatic deletion |
| Log of actions QOPE staff take on accounts | No automatic deletion |
06Compliance Status
QOPE does not hold a SOC 2 report today.
We sign a data processing agreement (DPA) on request. Email info@qope.org.
How QOPE handles personal data is described in our Privacy Policy.
07Responsible Disclosure
If you find a security issue in QOPE, email info@qope.orgwith the steps to reproduce it. Please do not access or change other people's data, do not degrade the service, and give us time to fix the issue before you share details.