Security

Secure Customer Flow Management

Queulan is built with security, privacy, and operational accountability in mind. From role-based access and encryption to audit trails and session controls, the platform gives your team the tools to manage customer flow responsibly.

Built with security, privacy, and operational accountability in mind.

Every layer of Queulan — from check-in to analytics — is designed to protect customer information and give your organization a clear, auditable record of activity.

Capabilities

Security Capabilities

Core controls that protect data across check-in, forms, queues, and analytics.

Role-Based Access

Granular permissions for agents, supervisors, and administrators.

Multi-Factor Authentication

Optional MFA for admin and supervisor accounts.

Encryption in Transit

TLS encryption for all data in motion.

Encryption at Rest

Encrypted storage for sensitive customer data.

Audit Logs

Comprehensive action logging for accountability.

Session Timeouts

Automatic kiosk and dashboard session clearing.

Secure Continuation Codes

One-time codes for save-and-continue form sessions.

One-Time SMS Verification

OTP verification for sensitive kiosk actions.

Kiosk-Session Clearing

All customer data removed after each kiosk session.

Data-Retention Controls

Configurable retention periods for visit data.

Consent Tracking

Record and store customer consent for processing.

Input Validation

Server-side validation prevents malformed submissions.

API Rate Limiting

Protection against API abuse and automated attacks.

Backup & Disaster Recovery

Backup support and recovery procedures.

Practices

Security Practices

Operational safeguards that reinforce the platform's core controls.

  • Input Validation

    Server-side validation rejects malformed or unexpected submissions before they are processed or stored.

  • API Rate Limiting

    Rate limits on public and authenticated APIs protect against automated abuse and brute-force attempts.

  • Backup & Disaster Recovery

    Backup support and documented recovery procedures help your organization restore service after an incident.

  • Session Timeouts

    Agent and supervisor sessions expire automatically after a configurable period of inactivity.

  • Kiosk-Session Clearing

    Customer-entered data is purged from the kiosk at the end of every session so nothing carries over.

  • Data-Retention Controls

    Administrators configure how long visit records and associated documents are retained before removal.

  • Consent Tracking

    Customer consent for data processing is captured, timestamped, and stored alongside the related record.

Do not claim security certifications that have not been formally obtained.

The controls described on this page reflect the capabilities Queulan provides. Security should be evaluated based on your organization's specific requirements, regulatory environment, and risk posture. Queulan does not hold formal security certifications unless explicitly documented and verified. Contact our team to discuss your security review and compliance needs.

Want to learn more about Queulan security?

Schedule a walkthrough with our team to review Queulan's security controls, deployment options, and how they map to your organization's requirements.