SOC2C

Is this your company? Buyers are checking Quinyx here. Claim quinyx.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Quinyx logo

Quinyx

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Quinyx is SOC 2 Type II compliant. Quinyx also holds ISO 27001, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Quinyx empowers businesses globally with AI-powered workforce management solutions, optimizing scheduling and compliance, reducing labor costs, and enhancing employee engagement. By streamlining operations and providing real-time insights, Quinyx helps companies achieve higher efficiency and profitability while maintaining high customer service standards. - View our service status here: [Quinyx Status page](http://status.quinyx.com/) - See our [User Manual and FAQs](https://quinyx.helpdocs.io/l/en)

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationLimited Personal health informationCustom data fields

Documents

1

Subprocessors

7
  • A
    Amazon Web Services EMEA SARL · Webhost for all Quinyx services
    EU/EEA
  • S
    Scrive AB · Digital singing of employee agreements
    EU/EEA
  • A
    Attensi · E-learning platform
    EU/EEA
  • S
    Stream.io, Inc. · Communication facilitator
    EU/EEA & US
  • Z
    Zoined OY · Insights module
    EU/EEA
  • T
    Twoday INSIKT AB · Advanced Analytics
    EU/EEA
  • B
    Babelway · Data analytics
    EU/EEA

Compliance leadership

The person who leads Quinyx's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Quinyx's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Quinyx ISO 27001 recertificationMay 2026

We're pleased to announce that Quinyx has successfully completed its ISO 27001 recertification, reaffirming our compliance with the internationally recognised standard for information security management. This recertification demonstrates our sustained commitment to maintaining the highest standards of information security — not just as a one-time achievement, but as an ongoing practice embedded across our organisation. You can find our latest ISO Certificate in the Resources tab of our Trust Center.

Information regarding React2Shell (CVE-2025-55182)Dec 2025

Quinyx was made aware of the React2Shell (CVE-2025-55182) vulnerability as part of our threat intelligence and the notification from CERT-SE at 2025-12-04 09:30 and have assessed our posture in relation to this. Although Quinyx uses React and Next.js, after reviewing our codebase and dependencies, we confirm that Quinyx does not use any of the affected versions or packages. Therefore, our systems are not within the scope of the vulnerability We continue to monitor the situation for any additional indications of additional packages or versions being noted as affected and continue to monitor the situation as a whole.

New ISO 27001 certificatesAug 2025

Quinyx have recently upgraded from ISO 27001:2013 to ISO 27001:2022 and have therefore updated the publicly available certificate as well as the latest version of our Statement of Applicability which is available on request from the Trust Center.

Update to our list of SubprocessorsFeb 2025

If Quinyx provides custom reports to you, we will start using Babelway© by Tradeshift for providing the custom reports. Babelway© by Tradeshift is a SaaS Integration middleware and is used for building and hosting integration workflows. Quinyx is committed to keeping your sensitive and personal data safe. We want to make you feel confident about how your personal data is being collected and used by Quinyx. Therefore, we would like to inform you that Tradeshift Belgium SA, 6, Chemin du Cyclotron, B-1348 Louvain-la-Neuve, Belgium will be added as a sub-processor under the Data Processing Agreement. For clarity, the addition of this new sub-processor does not entail a transfer of your personal data to any third countries without adequate level of protection. No further action is required on your part. If you have any questions or feedback - write to us via [dataprivacy@quinyx.com](mailto:dataprivacy@quinyx.com).

Updates to our list of subprocessorsSep 2024

We are currently developing a training environment together with a partner of ours. In this environment, videos and other generic training material regarding our service will be made accessible for a limited number of select users. In order to access and use this environment that is separate from your Quinyx environment, processing of certain basic account information (contact information, title, department, region, and whether training has been completed or not, etc.) constituting personal data will be required. For this purpose, Attensi AS, Forskningsparken, Gaustadalléen 21, 0349 Oslo, Norway will be added as a sub-processor under the data processing agreement forming part of your agreement with Quinyx, effective from 1 October 2024. We also want to inform you that Intercom R&D Unlimited company is no longer used as a sub-processor under your data processing agreement (if applicable). For clarity, other than as set out above, no changes are made to the data processing agreement, and no further action is required on your part. If you have any questions or feedback, write to us via [dataprivacy@quinyx.com](mailto:dataprivacy@quinyx.com).

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Quinyx SOC 2 compliant?
Quinyx is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Quinyx ISO 27001 certified?
According to Quinyx's public trust center, Quinyx is ISO 27001 certified. On SOC2C this listing is Listed.
Is Quinyx GDPR compliant?
According to Quinyx's public trust center, Quinyx is GDPR compliant. On SOC2C this listing is Listed.
Is Quinyx SOC 2 Type I or Type II?
Quinyx is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Quinyx's SOC 2 for a vendor risk assessment?
Yes. Quinyx's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Business & Industrial peers that completed SOC 2