MaestroQA, Inc. | Trust Center
MaestroQA Trust Center
MaestroQA is committed to the security of our customers and their data. Here is how we protect information and comply with industry standards and regulations.
See Resources


SOC 2 Type 2

Service Organization Controls (SOC 2) (Type II) - Security, Confidentiality and Privacy

ISO 27001

ISO/IEC 27001 information security, cybersecurity and privacy protection


PCI DSS 4.0 Level 1 Service Provider AOC


Type 1 Attestation (AT-C 105, AT-C 205 and AT- C 315) HIPAA / HITECH


Protect the personal data and privacy of EU and UK citizens for transactions that occur within EU member states and UK


California Consumer Privacy Act, is legislation designed to improve the data privacy of California residents

MaestroQA Overview and Security


MaestroQA is a Quality Management, Coaching, and Analytics Solution that helps assess areas of improvement within the customer experience to drive customer loyalty and satisfaction. We help organizations achieve this through workflow automations, human-driven assessments, and in-depth reporting. MaestroQA was founded in November 2013 with the objective of helping companies improve the quality of their customer experiences. MaestroQA allows companies to monitor, quantify, and improve their support by providing a platform for review and collaboration on customer conversations. The organization is based in New York City and serves customers around the world with their cloud based solution. MaestroQA services many industries and organizations around the world, varying from small and medium businesses to Fortune 500 enterprises.

MaestroQA is also the recommended Quality Assurance partner for Zendesk and Salesforce.


MaestroQA is committed to the security of our customers and their data. As a cloud-based company entrusted with some of our customers’ most valuable data, we are focused on keeping you and your data safe. MaestroQA undergoes periodic penetration testing and vulnerability assessments, is designed to be GDPR-compliant, and encrypts data at rest and in-transit.‍ Our customers entrust sensitive data to our care. Keeping customer data safe is our priority.

Secure and Reliable Infrastructure

MaestroQA uses Amazon Web Services (AWS) for secure and resilient hosting of staging and production environments. MaestroQA leverages multiple availability zones to redundantly store customer data. AWS data centers are monitored by 24×7 security, biometric scanning, video surveillance and are continuously certified across a variety of global security and compliance frameworks.

Customer Data

Data used - Employee performance data entered into the system through use of our product. Our product pulls ticket data as defined by the credentials provided to MaestroQA during initial configuration/setup with customers. MaestroQA also provides an option to limit/tag certain fields within the ticket and block the data for the marked fields to be pulled.

All data is encrypted at rest, in transit, and during backup. Access to data is limited to authorized personnel. Data retention in configurable, and data deletion process is in place.

Bug Bounty

We partner with HackerOne to run a private bug bounty program to help surface and resolve security vulnerabilities before they can be exploited.

Privacy Documents

Acceptable Use Policy Link to MaestroQA Acceptable Use Policy.
Cookie Policy [Please refer to the Resources section]
Security Contact - [email protected]
MaestroQA Privacy Policy


SOC 2 Type 2 Report

Security, Confidentiality and Privacy Criteria; Period - January 1, 2023 - September 30, 2023

ISO27001 Certificate

Current Certificate valid until: January 6, 2025


Level 1 Service Provider

HIPAA report

Information Security Policy

Penetration Test Report

MaestroQA Cookie Policy


Amazon Web Services

Data Hosting - Available options - US and EU


Data Processing


Monitoring operations of MaestroQA Services


Product analytics and debugging - no end user data shared


Product Analytics - no end user data shared


Powered by


Organizational Management

Background Checks
Background checks or their equivalent are performed before or promptly after a new hires start date, as permitted by local laws.
Information Security Program Review
Management is responsible for the design, implementation, and management of the organization’s security policies and procedures. The policies and procedures are reviewed by management at least annually.

Risk Assessment

Vendor Due Diligence Review
Vendor SOC 2 reports (or equivalent) are collected and reviewed on at least an annual basis.
Risk Register
A risk register is maintained, which records the risk mitigation strategies for identified risks, and the development or modification of controls consistent with the risk mitigation strategy.

Access Security

Unique Access IDs
Personnel are assigned unique IDs to access sensitive systems, networks, and information
Access to Product is Restricted
Non-console access to production infrastructure is restricted to users with a unique SSH key or access key