Login

It's all about trust

Safe, compliant, and transparent by design.

Payments

Segregated funds

We keep customer funds in separate trust accounts. Your money never mixes with ours.

We don’t touch the money

Payments flow through licensed partners. Qualy facilitates, but never holds or moves your funds directly.

Licensed global partners

We only work with regulated payment providers who are licensed in their jurisdictions.

Fast disbursements

As soon as funds clear, we disburse them to schools or agents. No unnecessary delays. Minimizing risk and impact in case of breach.

Transparent payment flow

Every payment has a full audit trail. You can track when it's paid, cleared, and disbursed.

PCI DSS compliance

Card data is handled only by PCI DSS-compliant providers. Qualy never stores card info.

No card data storage

We never store card details on our systems. All sensitive data is handled by our partners.

Chargeback protection

We have systems in place to handle chargebacks and disputes efficiently, minimizing impact on schools and agents.

Technology

Google Cloud hosted

We run on secure Google Cloud infrastructure with best-in-class uptime and security.

Encryption at rest

All customer data is encrypted at rest using strong encryption standards.

Data in-transit protection, HSTS and TLS 1.2+

We enforce HTTPS with HSTS and use end-to-end TLS 1.2+ for secure communications.

SLSA Level 3

Our build systems follow SLSA 3 standards, protecting against tampering and supply chain attacks.

No direct production access

Nobody has manual access to production systems. Everything goes through audited pipelines.

Isolated tenants

Each client’s data is siloed. No data leaks between schools, agents, or users.

Firewalls are always on

We use multiple layers of firewalls to protect our infrastructure.

24/7 monitoring

Our infrastructure is monitored 24/7 for uptime, anomalies, and potential threats.

DDoS protection

We use platform-level protections to defend against DDoS and other common attacks.

Zero standing privileges (ZSP)

Our systems use ZSP, meaning no one has permanent access to production environments. Access is granted only when needed and logged.

Strict DMARC policy

We enforce a “reject” policy on DMARC to prevent spoofed emails from being delivered.

DNSSEC enabled

DNSSEC is enabled on our primary domains, ensuring DNS lookups are verified and tamper-resistant.

Email delivery monitoring

Outbound email reputation and delivery are continuously monitored to avoid issues with missing invoices or payment links.

Subdomain isolation

We isolate transactional email from marketing or internal communication to reduce reputational risk.

Brute force protection

We have measures in place to prevent brute force attacks on user accounts, including rate limiting and account lockouts. Our authentication system is powered by Google.

Protection from malicious payload exploits

Our vigilant, adaptive firewall is primed to block any unsolicited traffic or malicious payloads, ensuring constant protection against potential vulnerabilities.

People

Role-based access

Our team members only see what they need to do their job. No broad access granted.

Background checks

All team members handling sensitive systems undergo background verification.

Security training

All staff complete regular security and compliance training sessions.

Two-factor auth (2FA)

2FA is required for all internal systems, and available for all users on the platform.

Least privilege principle

We follow the principle of least privilege, ensuring team members only have access to what they need.

Compliance

Operating only with licensed partners

While Qualy is not a financial license holder, our partners are fully licensed and compliant.

Local regulation aligned

We adapt to each region's rules—like Brazilian BACEN rules or Australia's AML laws—through our partners and with our own controls.

Audit-ready logs

All payments and system actions are logged and time-stamped for audit-readiness.

Customer Due Diligence (CDD)

We perform CDD on all customers to ensure compliance with local regulations.

GDPR compliant

We follow GDPR principles, ensuring data privacy and user rights are respected.

Brazil-specific compliance

We comply with Brazilian regulations, including the Lei Geral de Proteção de Dados (LGPD) and BACEN rules for payment handling.

Operations

Shared security responsibility model

We share security responsibilities with you, our suppliers, and our partners ensuring a comprehensive approach to security.

Disaster recovery ready

We use queues, backups, and replication to ensure the platform can recover quickly from issues.

Automated failover

If something fails, systems switch to backups without user disruption.

Reliable message queues

All payments and processes are queued and retried safely in case of failures.

Regular backups

We take regular backups of all critical data, ensuring we can restore quickly if needed.

Release freeze windows

We have scheduled release freeze windows to minimize risk during critical periods.

Error tracking & alerting

We use advanced error tracking and alerting to catch issues before they affect users.

Incident response plan

We know whom to call, what to do, and how to communicate in case of incidents. Our incident response plan is ready and tested.

Transparency

Customer transparency

We never hide who our upstream partners are—we believe transparency builds trust.

Open communication

We communicate openly about incidents, outages, and changes that affect customers.

Public status page

Our status page shows real-time system health, incidents, and maintenance updates.

Clear pricing

Our pricing is straightforward, with no hidden fees or surprises.

Leave anytime

We don’t lock you in with contracts. You can leave anytime, no questions asked.

Automate your tuition fee and commission payments.

Qualy was designed for collecting payments for the international education industry. It helps colleges, schools, and education agents of all sizes.

  • Start with a pilot with no strings attached
  • Implementation & training included
  • No setup fees