Security, Privacy and Compliance Information

Content

Our primary objective in creating this page is to provide an open and transparent overview of our internal Security, Privacy and Compliance governance program. We believe in fostering a culture of clarity, where all stakeholders, including customers and partners, can readily access and understand our principles, guidelines, and practices. By sharing this information, our goal is to promote trust, accountability, and informed decision-making as we work to continuously improve our program.

Quadient emphasizes compliance with multiple certifications, frameworks, and legal requirements such as ISO27001, ISO9001, HITRUST, PCI-DSS, SOC2, NIST Cybersecurity Framework, GDPR, HIPAA, or CCPA. These controls are regularly reviewed by internal auditors and independent external auditors to provide that all controls are in place, working as intended and in line with both Quadient and its customers’ expectations.

Quadient employs a dedicated team responsible for managing the Quadient ICA Compliance, which includes:

  • Information Security Management System (ISMS)
  • Privacy Information Management System (PIMS)
  • Quality Management System (QMS)
  • Environmental Management System (EMS)

Various roles such as Security and Compliance Managers, Data Protection Officers, Cyber Security Analysts, Penetration Testers, Quality Engineers, and Environmental Mamagers are dedicated to manage or support above mentioned management systems. These professionals hold relevant certifications and their education is continually improved.

The links below contain more information about the comprehensive security and governance program implemented by Quadient ICA, including security awareness training for employees, acceptable use policies, access control, availability and continuity measures, asset management, backups, business continuity planning, change management, cyber insurance, disaster recovery, encryption, hardening measures, HR security practices, incident management, internal and external audits, logging, monitoring, network security, data loss prevention, password management, and more.

If you have any additional questions, you can reach out to us at privacyteam (at) quadient.com for privacy relevant questions or security (at) quadient.com or security relevant questions.

Finally, our Quadient University can provide you a wide list of topics relevant to Quadient ICA products.

Main Security, Privacy and Compliance Areas

This chapter serves as an overview of Compliance, Security and Privacy controls implemented by Quadient group (hereinafter, “Quadient”). Such controls are applied on the Software as a Service (SaaS) solution Quadient Intelligent Communication Automation (“ICA”) platform including Impress, Inspire, Quadient Account Payable by Beanworks and Quadient Account Receivable by YayPay as further explained below. These controls are regularly reviewed by internal auditors and independent external auditors to provide that all controls are in place, working as intended and in line with both Quadient and its customers’ expectations.

ICA Services

The following ICA Services are provided as SaaS from the ICA platform for which Quadient uses Microsoft Azure (Azure) and Amazon Web Services (AWS):

Customer Experience Management (CXM)

Referring to Inspire solutions. For enterprises who wish to create exceptional customer experiences, we provide omnichannel software solutions and expertise that deliver compliant and meaningful customer interactions. This includes Inspire Evolve, Inspire Flex, Inspire Journey and Digital Boost.

Intelligent Documentation Automation (IDA)

Referring to Impress solutions. For businesses who want to streamline document production processes and departmental workflows, we provide digital solutions that help automate communications and accelerate cash flow. This includes Impress Automate, Impress Distribute and Impress Invoice.

Account Receivables (AR)

Referring to “Quadient AR, by YayPay”. Automate Accounts Receivable to simplify the collection Process and reduce DSO.

Account Payables (AP)

Referring to “Quadient AP, by Beanworks”. Approve invoices and pay vendors remotely while reducing AP costs.

Applicable Certifications and Assessments

Quadient ICA products are subject to many certifications, assessments and legal requirements, which are regularly externally validated.

Please note, that not all below mentioned are valid for all Quadient ICA products. Please reach out to your Account Manager to verify, which are applicable for the product you are interested in or you are already using.

Compliance

Overview Committees

Policies

Team

Datacenters

Customer Data Separation

Quadient Access to Customer Data

Sub Processors

Awareness

Acceptable Use

Access Control

Availability and Continuity

Asset Management

Backups

Business Continuity

Change Management

Cyber Insurance

Disaster Recovery

Encryption

Hardening

HR Security

Incident Management

Internal and External Audits

Logging

Monitoring

Network Security

Password Management

Physical Security

Quality Assurance

Risk Management

Secure Development

Security Bulletin / Status

Shared Responsibility

Third Party Management

Vulnerability Management

Data Protection Officer

Data Breach Notification

Data Subjects Rights

Data Retention

Data Erasure

How to Contact Us

Privacy Statement

What can be shared

Latest Updates on Cybersecurity and Compliance

This page is intended to inform our customers and partners about the latest security updates for Quadient ICA.

For a full list of vulnerabilities and hot fixes, please visit our solutions Knowledge base

March 8, 2022 - Statement on IT security against cyberthreat

Page Type
Protected
Off