Transparency and consent
Privacy policy, Terms of Service, login consent text, and policy links are surfaced in the app experience.
QualiRise AI
Compliance readiness
QualiRise AI is built with core GDPR, SOC 2, ISO 27001, NIS2, and EU AI Act readiness controls already in place, giving customers a clear foundation for procurement, security review, and responsible AI adoption.
GDPR readiness
QualiRise AI includes product controls that support transparency, data-subject rights, minimization, retention, and secure processing.
Privacy policy, Terms of Service, login consent text, and policy links are surfaced in the app experience.
Authenticated users can export their data and request erasure of UI preferences and personal audit identifiers.
PII redaction, configurable retention periods, ephemeral sessions, and non-persistent Jira credentials reduce exposure.
SOC 2 readiness
The app includes technical security controls commonly mapped to SOC 2 Trust Services Criteria for access, monitoring, change, and risk management.
Signed HttpOnly sessions, constant-time secret comparison, HTTP security headers, and auth rate limiting protect access flows.
Login, logout, OAuth, and data-rights events are recorded to the audit trail for traceability.
CI checks, tests, builds, and dependency audit checks support controlled delivery and vulnerability awareness.
ISO 27001 readiness
QualiRise AI maintains an ISMS documentation set and maps product controls to ISO 27001:2022 Annex A security expectations.
ISMS scope, clauses 4-10, risk assessment, and a starter risk register are tracked for governance review.
All 93 Annex A:2022 controls are represented in a Statement of Applicability with implementation references.
Access control, cryptography, data masking, deletion, logging, vulnerability handling, and change controls are mapped.
NIS2 readiness
QualiRise AI tracks NIS2 cybersecurity risk-management measures, incident reporting, governance accountability, and vulnerability handling.
Article 21 cybersecurity measures are mapped to product controls and operational documentation.
The NIS2 reporting workflow is documented around the 24-hour, 72-hour, and one-month notification milestones.
Responsible disclosure and dependency audit checks support vulnerability detection and response readiness.
EU AI Act readiness
QualiRise AI treats AI-generated QA artifacts as a governed workflow: labelled, reviewed by people, and recorded with provider and model context.
The product is documented as limited-risk for AI Act readiness, focused on transparency obligations.
Generated acceptance criteria and test cases display an AI-generated badge with provider and model details.
Users review generated QA artifacts before applying changes or opening pull requests, preserving accountability.
Customer assurance
These controls help customers evaluate QualiRise AI across privacy, security, cyber-risk, and responsible AI requirements before adoption.
Readiness controls are documented so security and procurement teams can review the product faster.
AI-generated QA artifacts stay transparent, traceable, and subject to human review before use.
Formal legal applicability, contractual terms, and certifications depend on customer context and qualified counsel review.