Procurement-ready
DPA, security questionnaire and custom MSA. Data-residency options are on the enterprise roadmap. We respond in days, not weeks.
Solutions · Enterprise
SSO, SCIM, audit, custom contracts and a dedicated success engineer. Same calm product, hardened for procurement.

The problem
Enterprise rollouts die slowly: security questionnaires going back and forth for months, identity systems that won't connect, access reviews nobody can produce, and a vendor that disappears after the contract signs. The platform can be right and the process can still fail.
DPA, security questionnaire and custom MSA. Data-residency options are on the enterprise roadmap. We respond in days, not weeks.
SAML SSO, SCIM provisioning, IP allow-lists and per-tenant audit log streamed to your SIEM.
Named success engineer, quarterly business reviews, custom SLA and a private Slack or Teams channel.
SOC 2 Type II in progress; GDPR-aligned controls; BAA conversations available for qualifying customers; ISO 27001 roadmap shared on request.
UAT and staging tenants included. Hands-on migration from legacy tools, with concierge data mapping.
Theme, widgets, server-side hooks and a typed API let you tailor without leaving the upgrade path.
Enterprise rollouts live or die on identity. QUE supports SAML 2.0 SSO with all major IdPs (Okta, Azure AD, Google Workspace, JumpCloud, OneLogin) and SCIM 2.0 for automated provisioning and deprovisioning. New hires get the right role on day one; offboarding revokes access in real time.
Granular RBAC, IP allow-lists, session timeout policies, MFA enforcement and device posture (on enterprise+) round out the access controls. Every login, role change and privileged action is captured in an immutable audit log streamed to your SIEM (Splunk, Datadog, Sumo, S3) over standard transports.
We support per-tenant custom claims for downstream entitlement decisions and provide a fully documented logout flow for clean session termination across federated identity.
We've been through hundreds of enterprise procurements and learned to remove the friction. Our DPA is on the website. Our security questionnaire is pre-filled (SIG, CAIQ, custom). Our subprocessor list is published with notification triggers. Our incident response playbook is shared on request.
Custom MSAs are negotiated by humans, not bots. Most edits land in a week. Per-region data residency (EU, US, APAC) is on the enterprise roadmap, and we will share documentation procurement needs as it becomes available.
Pricing is transparent and based on the dimensions your finance team can plan against — seats, locations, bookings, calls. We don't surprise you with overage charges that gate the renewal conversation.
Every enterprise customer gets a named success engineer who knows your tenancy, your integrations and your business. A private Slack or Teams channel is the default support surface — ticket portals are an option, not a requirement. Response SLAs are tier-defined and start at 15 minutes for critical incidents on premium support.
Quarterly business reviews with the product team align your roadmap requests against ours. Influence early, not at the end.
For rollouts at scale, we offer hands-on migration from your legacy tool, white-glove training for your internal trainers, and a UAT tenant that mirrors your production catalog.
The part that changes your day
What we want the internal team to feel: procurement finishes in weeks, security sees the audit trail without asking, and the rollout plan lands without heroics. Calm is the feature.
Contracted
Uptime SLA
Negotiable targets with regional pinning options
Tier-defined
Response targets
Critical, high, medium and low — agreed in the contract
Named
Support surface
Success engineer + private Slack or Teams channel
Tunable
Audit retention
Per-workspace retention policies
Use cases
Forty clinics, SCIM-provisioned identities, audit log streamed to enterprise SIEM, BAA signed on day one.
Outcome · SCIM-provisioned identities, a BAA and an audit log streamed to the enterprise SIEM from day one.
Employee booking for in-office services with SSO, IP allow-list, no public access.
Outcome · SSO, IP allow-list and no public access keep the deployment internal-only.
Counsellors across twelve campuses, FERPA-aligned controls, SAML to the university IdP.
Outcome · Counsellors across campuses share one scheduling calendar through the university IdP.
Self-service slot booking for HGV onboarding across 18 sites with custom intake forms.
Outcome · Self-service slot booking and custom intake forms run at all sites without a central scheduler.
Local-government appointment portal with WCAG 2.2 AA and an accessibility audit pack.
Outcome · WCAG 2.2 AA and an accessibility audit pack come standard for the portal.
Beauty consultations and personal-styling in 220 stores across EU, US and APAC with regional data pinning.
Outcome · Regional data pinning keeps each market's data in its designated region.
Capabilities
Okta, Azure AD, Google Workspace, JumpCloud.
Streamed to Splunk, Datadog or your SIEM.
On the enterprise roadmap for EU, US and APAC.
Uptime, response and resolution targets.
UAT and staging tenants included.
Hands-on data import from legacy tools.
Named success engineer, fast response.
Negotiated by humans, signed in a week.
How we compare
| What you need | Legacy tools | QUE |
|---|---|---|
| SSO | Add-on or absent | SAML 2.0 included on enterprise |
| SCIM provisioning | Manual user lifecycle | Automated, real-time |
| Audit log to SIEM | Export-only, lagged | Streamed, near-real-time |
| Data residency | One region | EU / US / APAC, regional pinning |
| Custom MSA | Months of legal back-and-forth | Negotiated by humans, terms you can plan against |
| Named success | Shared queue | Dedicated engineer + private channel |
Yes. Our standard DPA is published; redlines accepted and turned around in days. Subprocessor list is published and updated on a 30-day notice cadence.
Start with QUE
Configuration that adapts to the booking flow your team already runs.