QPG WORKSPACE / SECURITY

Security, with clear boundaries.

Production controls and the boundaries of the current integration. Updated 9 October 2026.

Encrypted credentials

AES-256-GCM with separate key configuration. Passwords are stored as one-way hashes.

Scoped permissions

Administrator, operator and read-only roles; store scopes checked by the API.

Accountability

Login, ledger access, credential changes and imports are recorded without raw credential values.

Session controls

HttpOnly sessions expire after eight hours. Disabling a staff account invalidates its sessions.

Production operations

HTTPS requires TLS 1.2 or higher. The application is hosted on AWS in Oregon, United States. API responses use no-store caching and authenticated access; cross-origin writes require the allowed workspace origin. The environment key file is readable only by its service owner.

Encrypted database backups run daily and are retained for seven days. Backup verification restores records into temporary database tables without replacing production records. Expired sessions and old login-attempt and audit records are cleared under the published retention policy. A separate encrypted recovery snapshot is held on the administrator workstation; automatic off-server backup delivery is not yet configured.

Incident response

Staff report suspected incidents to the company administrator via the security contact below. The administrator contains the issue, preserves relevant evidence, assesses affected data, coordinates required notifications to Temu and competent authorities, and records remediation and follow-up.

Integration boundaries

Live Temu synchronization is not yet active. Current encryption protects credentials and backups; buyer names, addresses, phone numbers and shipping-label files are not currently collected. Additional personal-data functions require corresponding permissions and protection controls before activation.

Security contact

For security concerns about QPG Workspace, contact Zhongfu Intl Co., Limited at 3526861@gmail.com. Please do not email passwords, application secrets or access tokens.

Scope of this statement

This page describes the current software and production controls. It does not imply Temu approval, a completed security assessment or ISO/SOC certification.