ON THE ROAD · Meet QliqSOFT at Florida Hospice & Palliative Care Association, Orlando, FL →NEW SITE · We rebuilt qliqsoft.com. Current customers: browse it and grade our work → CUSTOMERS: SIGN IN NOW LIVES IN THE TOP BAR →NEW · RPAplus agentic EMR integration: connected even without an API →NOW PUBLIC · How our pricing works: per staff, per patient, published in full →SINCE 2011 · 1,000+ healthcare organizations run on QliqSOFT →ON THE ROAD · Meet QliqSOFT at Florida Hospice & Palliative Care Association, Orlando, FL →NEW SITE · We rebuilt qliqsoft.com. Current customers: browse it and grade our work → CUSTOMERS: SIGN IN NOW LIVES IN THE TOP BAR →NEW · RPAplus agentic EMR integration: connected even without an API →NOW PUBLIC · How our pricing works: per staff, per patient, published in full →SINCE 2011 · 1,000+ healthcare organizations run on QliqSOFT →
Trust CenterSystem Status
Home / Security

Security

Security you can audit, not just admire.

The complete posture on one crawlable page: attestation, compliance, encryption scoped honestly by product, device containment, AI governance, and how to report a vulnerability. Independent verification lives in the Trust Center; quick answers live in the FAQs.

Attestation and compliance

Independently examined, over time.

QliqSOFT is SOC 2 Type II attested: examined independently and over a period of time, not just at a point in time, against strict standards for security, availability, and confidentiality. The platform is HIPAA compliant with a Business Associate Agreement included in every customer relationship, and that BAA coverage extends down the stack to the third-party AI providers behind our AI features. Reports and questionnaires are available through the Trust Center.

Encryption, scoped honestly

Two products, two architectures.

QliqCHAT team communication uses per-user public/private key encryption: 2048-bit RSA for messages and 256-bit AES for attachments, with retention, expiration, and archiving under your organization’s control, including an archive that can live behind your own firewall. Quincy patient and family conversations run over encrypted connections and are protected by the same platform-level HIPAA compliance, BAA coverage, access controls, and audit trails. We state the boundary because a security page you can audit is worth more than one you can only admire.

Devices and access

BYOD containment and access control.

QliqCHAT is built for BYOD: the app is a sealed container with its own encrypted database, an in-app camera whose photos never touch the camera roll or cloud backups, restrictable copy and paste, auto-lock behind PIN or biometric, and remote lock and wipe of the app data only, nothing personal. Access runs on admin-set password policies, optional two-factor authentication, Active Directory integration with SSO, and role-based permissions, with provisioning and offboarding on the same AD rails.

AI governance

Automation as support, not substitution.

Our standing policy for AI in clinical communication: AI classifies, routes, translates, and reminds; clinicians make the clinical decisions. Scored assessments classify against thresholds your organization tunes, and every AI-driven workflow carries a human escalation path by rule. AI features run inside the same HIPAA-compliant, BAA-covered platform as everything else, and the third-party LLM and voice AI providers behind them (including speech-to-text and text-to-speech) operate under Business Associate Agreements with QliqSOFT that require your data stay secure, private, and never used to train their models. Voice-agent interactions are logged to the patient thread like any other touchpoint. Feature-level data-handling specifics are provided in security review through the Trust Center. Independent editorial coverage: Medtech Insight on collecting sensitive data with AI chatbots.

Responsible disclosure

Found something? Tell us.

We welcome good-faith security research on our products and this website. If you believe you have found a vulnerability, email security.incidents@qliqsoft.com with steps to reproduce and any relevant details. We will acknowledge your report, keep you informed as we investigate and remediate, and credit researchers who wish to be credited. We ask that you give us reasonable time to remediate before any public disclosure, avoid accessing or modifying data that is not yours, and never test against systems carrying real patient information. Machine-readable details live at /.well-known/security.txt.