Your data stays in Europe. On hardware we control.
Qasaba does not use public cloud providers. All data is processed and stored in a private data center in Poland, within the European Union. No third-party infrastructure, no multi-tenant environments, no data leaving the continent.
Private infrastructure in Poland
No public cloud
Qasaba runs entirely on dedicated, privately owned hardware. No AWS, no Azure, no GCP. Your scan results, discovered assets, and all platform data are processed and stored on infrastructure that Qasaba directly controls.
Data center in Poland, EU
All infrastructure is located in a professional data center in Poland. Data never leaves the European Union. This eliminates cross-border transfer concerns under GDPR and satisfies data residency requirements for organizations operating under European regulation.
No multi-tenancy risks
Public cloud environments share physical infrastructure between tenants. Qasaba's private infrastructure eliminates the class of vulnerabilities associated with multi-tenant isolation — hypervisor escapes, side-channel attacks, shared resource leakage.
Full control over the stack
From network hardware through operating systems to the application layer, every component is managed by the Qasaba team. No third-party managed services handle your data at any point in the processing pipeline.
EU jurisdiction only
All data processing falls under EU law exclusively. No exposure to non-EU legal frameworks, no risk of foreign government access requests under non-European legislation.
Physical security
The data center provides 24/7 physical security, redundant power, fire suppression, and environmental monitoring. Access is restricted and logged.
What we collect, how we store it, when we delete it
What data does Qasaba collect?
Qasaba discovers and stores information about externally visible assets: domains, IP addresses, open ports, running services, software versions, SSL certificates, and publicly accessible content. This is information visible to anyone on the internet — Qasaba organizes and analyzes it for you.
Who has access to scan results?
Only authorized users within your organization and designated Qasaba personnel providing support. Access is role-based and logged. Scan results from one client are never visible to another.
How long is data retained?
Scan results are retained for the duration of the service agreement to enable historical comparison and trend analysis. Upon contract termination, all client data is deleted within 30 days. Deletion can be requested at any time during the contract.
Is data shared with third parties?
No. Scan results and client data are never shared with third parties, used for marketing, sold, or aggregated with data from other clients. Qasaba does not use third-party analytics, tracking, or advertising services on its platform.
Security tools should not introduce new risk
An ASM platform, by its nature, holds a detailed map of your external infrastructure — every asset, every service, every vulnerability. This data is extraordinarily sensitive. In the wrong hands, it is a ready-made attack plan.
Storing this data on shared public cloud infrastructure, processing it through third-party services, or allowing it to leave a controlled jurisdiction adds risk that the security tool was meant to reduce.
Qasaba's approach — private hardware, single jurisdiction, no third parties — ensures that the platform designed to protect your infrastructure does not become a liability itself.
For regulated industries
Financial services, healthcare, public sector, and critical infrastructure organizations face strict requirements on where and how security data is processed. Private EU-based infrastructure satisfies these requirements without exception requests or contractual workarounds.
For organizations with sovereignty requirements
Government agencies, defense contractors, and organizations handling classified or sensitive national data require infrastructure within controlled jurisdictions. Qasaba's Poland-based data center operates entirely under EU law with no dependencies on non-EU providers.
Questions about data handling?
We provide full transparency on how your data is processed and stored.
Contact Us