Q-Cal: Network and Security Requirements
For Q-Cal, the following IP whitelist and port security requirements apply in the current setup:
Web Services
- app.q-cal.net
IP: 116.203.85.242
Port: 443 (SSL) - controller.q-cal.net
IP: 116.203.23.160
Port: 11812 (SSL)
AD/O365 Synchronization
If access needs to be restricted, ensure the following IPs can communicate:
- sync.q-cal.net →
142.132.160.124 - app.q-cal.net →
116.203.85.242
Notes
Q-Play system architecture
Account Separation Method
Q-Play V2 is build on the Laravel framwork, tenant scoping is implemented with global scopes, which is recommended for implementing multi-tenancy on a one database setup.
Q-Play stores all integration login credentials encrypted with AES-256. NordicScreen employees do not have access to this information. The data is stored exclusively on the specific integration server managing the customer's integrations and is not saved anywhere else.
Our servers are hosted in Germany with Hetzner: https://www.hetzner.com/legal/legal-notice/.
Private Network
NordicScreen operates its own private network with a static IP address. This network is the gateway to critical systems, ensuring a controlled and secure environment.
Internet Security
There is no direct internet access to the server. Access is highly restricted and limited to select trusted employees with management responsibilities. Support and commercial personnel do not have access to these systems.
Access Protection
Multi-Factor Authentication (MFA) is effectively implemented through the combined use of these methods, ensuring robust protection against unauthorized access. Access to critical systems is secured with the highest standards, incorporating Multi-Factor Authentication (MFA), IP whitelisting, and SSH certificates for unparalleled protection.
This layered security approach ensures the highest levels of protection for all hosted systems and data.