Back to Platform

Cookie Policy

Effective Date: October 15, 2026

Trust in cybersecurity begins at the first touchpoint. The CQWS Billing & Provisioning Portal adheres to a radical standard of digital sovereignty. If a website tracks you without your permission, it is inherently hostile. Therefore, we do not engage in surveillance capitalism.

1. Our Stance on Tracking and Profiling

As a foundational cybersecurity company, we believe that your behavior across the internet is your private property.

We explicitly do not use:

  • Third-party marketing cookies or behavioral retargeting pixels (e.g., Meta Pixel, Google Analytics).
  • Cross-site fingerprinting tools that attempt to identify your browser configuration.
  • Session replay scripts that record your mouse movements or keystrokes.

We do not track your behavior, we do not profile your usage for advertising, and we do not sell visitor data to data brokers. Period.

2. Strictly Necessary Cookies

While we reject marketing trackers, the secure operation of the CQWS Provisioning Portal mathematically requires the use of certain local storage elements to maintain encrypted state between your browser and our servers.

We utilize only the following Strictly Necessary Cookies:

A. Session Authentication Tokens

When you successfully authenticate into the CQWS dashboard, we issue a secure, HTTP-only, SameSite=Strict cookie. This token proves your identity to our API servers, ensuring no unauthorized party can access your cryptographic provisioning material or alter your node licenses. This token is destroyed when you log out or when the session naturally expires.

B. CSRF (Cross-Site Request Forgery) Protection

To prevent malicious external websites from forging requests to our API on your behalf (such as secretly revoking a node license), we utilize cryptographic CSRF tokens stored locally in your session. These tokens must match the server's expected value for any state-changing action to succeed.

C. Stripe Payment Integration

For secure subscription processing, our Tier-1 payment processor (Stripe) sets functional cookies required for PCI-DSS compliant fraud detection and transaction validation. These cookies are entirely sandboxed to the checkout flow and are governed by Stripe's stringent financial privacy policies.

3. Why There Is No "Accept All" Banner

Under the EU General Data Protection Regulation (GDPR) and the ePrivacy Directive, websites are only required to show cookie consent banners if they utilize non-essential tracking cookies.

Because CQWS utilizes zero non-essential cookies, you will not find an "Accept All" banner or a preference center on this platform. We respect your privacy by default, not by option.

4. Managing Your Browser Settings

If you wish to enforce maximum local security, you may disable all cookies via your web browser's settings. However, please be advised that because our cookies are strictly necessary for authentication and CSRF protection, disabling them will render you physically unable to log into the provisioning dashboard or securely manage your infrastructure.