QC Blog


Strengthening Our Security Posture

At QuestionableCorp, the trust our customers and employees place in us is not something we take lightly. Over the past several months, our security organization partnered with an independent team to conduct a comprehensive internal security assessment of our public-facing and internal systems.

This effort was prompted, in part, by the incidents of 2025. We committed to our stakeholders that we would learn from those events, and we have. The assessment identified a number of legacy weaknesses that may have contributed to past compromises, and we are pleased to report that every finding has been triaged and resolved.

What Changed

Highlights of the remediation work completed this cycle include:

  • Retired legacy directory listings and endpoints that were unintentionally exposed to the public.
  • Rotated shared credentials and service passwords that had not been cycled in far too long.
  • Implemented new security protocols and monitoring tools to detect bots
  • Enhanced our internal security training program to ensure all employees are aware of the latest threats and best practices.

Our Commitment

Security is a continuous process, not a destination, and we will continue to invest in the safety and integrity of our platform. To show that we are continuing our commitment, we will regularly publish blog posts related to the innovation and improvements in our security practices. To start, we will additionally be launching our new trust center. Please visit our Trust Center for more information.

Questions about our security program can be directed to the Office of the CISO.