Security

How we protect emails submitted to the QPN Catalyst Network.

Who operates this

What this protects against

The system is designed to minimize exposure of sensitive content by default, restrict access through least-privilege controls, and ensure that operational tasks never require access to raw submission data.

How submissions are protected

Encryption at rest. Every email is encrypted at the moment it is stored — there is no unencrypted persistence in our storage layer. Encryption is performed with encryption keys managed under our AWS account (AWS KMS customer-managed keys), and two separate keys are used:

This separation means operational tasks (e.g., daily intake counts, response mode distribution) never require access to email content.

Encryption in transit. All access to stored data is over HTTPS. Inbound email uses opportunistic TLS — encryption is used whenever the sending server supports it, per the SMTP standard.

Automatic key rotation is enabled on both keys.

Who can access stored data

Access to stored data is controlled through AWS IAM roles assigned to specific services and, in limited cases, to authorized human operators of Quantum Privacy LLC under the constraints described below.

Audit and monitoring

What we don’t log

Data jurisdiction and retention

Security incident notification

If Quantum Privacy LLC confirms a security incident involving stored submissions, affected contributors will be notified at the email address from which their submissions were sent.

Contact

Security questions, deletion requests, or concerns about a specific submission can be sent to info@qpncatalyst.io.

Known limitations