# Security & compliance

What DataQ does with the data it sees, how it authenticates and authorises people, and
the documents a privacy or security review will ask for.

<div class="grid cards" markdown>

-   :material-shield-lock:{ .lg .middle } **Security & data handling**

    ---

    Authentication modes, workspace roles, secret storage, PII redaction, retention and
    the audit trail — in plain language.

    [:octicons-arrow-right-24: Security overview](overview.md)

-   :material-clipboard-check:{ .lg .middle } **Compliance pack**

    ---

    Processor-side artifacts for GDPR, CCPA and HIPAA reviews.

    [:octicons-arrow-right-24: Sub-processors](compliance/sub-processors.md) ·
    [DPIA input sheet](compliance/dpia-input-sheet.md) ·
    [Data-subject rights](compliance/data-subject-rights-runbook.md) ·
    [Breach notification](compliance/breach-notification-runbook.md) ·
    [DPA / BAA templates](compliance/dpa-baa-templates.md)

</div>

!!! note "Scope"
    These pages describe the controls DataQ implements as a data **processor**. Lawful
    basis, consent, and contractual terms remain the deploying organisation's
    responsibility, and the DPA / BAA drafts are counsel-gated templates, not executed
    agreements.
