This Security Policy explains the operational security principles, infrastructure protection measures, cybersecurity practices, monitoring systems, access controls, and digital risk management approaches associated with Quantum Intelligence Hub LTD and the broader QIH ecosystem.
This Security Policy explains the public-facing security framework used by Quantum Intelligence Hub Ltd (“QIH”, “we”, “us” or “our”) for QIHHUB.COM and related QIH-operated services, including websites, hosting and automation environments, AI Digital Reception services, customer portals, communication channels and supporting infrastructure.
This policy is a high-level operational summary. It does not disclose confidential system architecture, credentials, internal control records, detection rules or other information that could weaken security.
Our security programme is intended to support:
Security controls are selected and reviewed using a risk-based approach. Depending on the service and risk, QIH may document asset ownership, access requirements, supplier dependencies, data flows, recovery priorities and incident-response responsibilities.
Security is reviewed throughout the lifecycle of a service, including design, implementation, operation, material change and termination. Controls may be adjusted where a risk assessment, legal requirement, supplier change, security event or material technical development makes this appropriate.
Security is shared between QIH, the customer and relevant infrastructure or channel providers. QIH is responsible for security measures within systems and processes under its control. Customers remain responsible for their own users, devices, networks, accounts, content, instructions, legal permissions and third-party services they select or administer.
Each party is responsible for loss, misuse or non-compliance caused by its own acts, omissions, credentials, personnel or systems, subject to the applicable agreement and mandatory law.
QIH may apply controls such as:
Passwords, API secret keys, webhook signing secrets, access tokens and recovery codes must be treated as confidential. QIH and customers should:
QIH may reject incorrectly formatted credentials or temporarily disable an integration where necessary to protect customers or systems.
Depending on the service architecture and provider capabilities, QIH may use secure configuration, transport encryption, firewalls, traffic filtering, environment separation, protected administrative interfaces, security updates, availability controls and cloud-provider safeguards.
Infrastructure may be hosted or processed through independent cloud, hosting, telecommunications and software providers. Their controls and availability form part of the overall service dependency chain.
For QIH-developed or configured systems, security considerations may include input validation, authentication and authorisation checks, secure error handling, dependency review, change control, separation of test and production data, logging of material events and testing proportionate to the change and risk.
No publication of this policy represents a guarantee that software is free from defects or vulnerabilities. Identified issues are assessed and addressed according to severity, exploitability, customer impact and available remediation.
AI Digital Reception services may connect with telephone, web chat, email, WhatsApp, social media, forms, calendars, CRM systems and other customer-selected channels. Security depends partly on the configuration and protection of each connected provider account.
QIH seeks to minimise personal information and restrict access according to purpose. Encryption in transit is used where supported and appropriate. Encryption or equivalent provider safeguards for stored information may be used according to the service, risk and platform capability.
Encryption reduces risk but does not eliminate it. Customers must also secure endpoints, exports, downloaded files, local backups and information copied into their own systems.
QIH and its providers may record security, access, authentication, integration, system-performance and error events for security, fraud prevention, troubleshooting, service continuity and legal compliance. Monitoring may detect unusual access, repeated failures, malicious automation, spam, misuse or infrastructure instability.
Monitoring is not continuous human surveillance and cannot detect every event. Logs are restricted and retained only for a proportionate operational or legal period.
QIH assesses relevant vulnerabilities and security updates according to risk. Remediation priority may consider severity, credible exploitation, internet exposure, information sensitivity, operational impact, supplier availability and safe deployment requirements.
Customers must keep their own devices, browsers, plugins, integrations and connected systems supported and reasonably up to date.
QIH may use hosting, cloud, payment, telephony, messaging, analytics, automation and support providers. Supplier selection and review may consider service criticality, security information, contractual safeguards, data location, access scope, resilience and incident procedures.
A supplier relationship does not transfer responsibility for that supplier’s independent acts to QIH beyond the allocation required by the applicable agreement and law.
Where included in the relevant service, QIH or its providers may maintain backups, redundancy, recovery procedures and continuity measures proportionate to service criticality. Backup frequency, retention and restoration capability differ by service and must not be assumed unless documented.
Customers remain responsible for independent copies of information they are required to retain and for a practical continuity plan where interruption could materially affect their operations.
QIH assesses suspected incidents, seeks to contain confirmed threats, preserves relevant evidence where appropriate, coordinates with affected providers and restores service according to priority. Where QIH becomes aware of a personal-data breach or significant service-security risk requiring notice, communication will be made to the relevant customer or authority in accordance with applicable law and contractual roles.
Customers must promptly report suspected compromise, revoke exposed credentials where possible, preserve relevant evidence and cooperate with reasonable containment steps.
Security testing must not be performed against QIH systems without prior written authorisation. Researchers who believe they have identified a vulnerability should avoid privacy violations, data access, persistence, disruption, extortion or public disclosure before QIH has had a reasonable opportunity to investigate.
See our Security Disclosure Policy or contact security@qihhub.com.
QIH may restrict an integration, credential, feature or account where reasonably necessary to contain a threat, investigate misuse, protect affected persons, comply with law or preserve infrastructure. Where practicable, the scope and duration of a restriction will be limited to what is reasonably necessary.
Responsibility for an incident rests with the party whose breach, negligence, unlawful instruction, insecure configuration, personnel or controlled system caused it, subject to causation, contributory fault, the governing agreement and mandatory law.
This policy does not create an absolute security warranty, guaranteed uptime commitment or certification. Service-specific security obligations, service levels, data-processing terms and liability provisions are governed by the applicable contract. Nothing in this policy excludes liability that cannot lawfully be excluded.
QIH may update this policy to reflect changes in services, risks, technology, law or operational controls. Material changes will be published with an updated date.
For security reports or operational security enquiries:
QUANTUM INTELLIGENCE HUB LTD
71–75 Shelton Street
Covent Garden
London, WC2H 9JQ
United Kingdom
Security: security@qihhub.com
Privacy: privacy@qihhub.com
Legal: legal@qihhub.com
General: info@qihhub.com

Quantum Intelligence Hub uses cookies and similar technologies to improve website security, performance, analytics and user experience. You may accept all cookies, reject non-essential cookies, or manage your preferences at any time.