Security & governance
Intelligence you can show your board
Governance is a first-class feature here, not an afterthought. Every design decision in Quarria starts with one question: "Could we defend this to a security team?"
Per-tenant data isolation
All your data (lenses, signals, reports, and business context) is partitioned by tenant at the database level. There are no cross-tenant queries, ever. No other customer can reach your competitor research.
No cross-tenant model training
Your context, prompts, and outcomes never train or fine-tune a shared AI model. Quarria uses your data to tune relevance for you, not to improve the product for anyone else.
Cited sources on every signal
Every signal carries the source URL, the publication date, and the exact text that triggered it. You get a complete, readable audit trail for every insight. No black-box summaries.
Secure credential handling
Passwords are hashed with bcrypt. Sessions use signed, HTTPS-only JWT tokens. Google OAuth is there for teams that would rather not manage passwords at all.
Exportable and deletable data
Export your signals, reports, lenses, and business context whenever you want. Ask us to delete your account and data, and we will. Quarria is built with GDPR principles in mind. Your data is yours, and you stay in control.
Role-aware signal ranking
Signals are tuned to your role and business context, not a generic market view. A pricing move lands differently for a product manager than for a CFO, and Quarria understands that.
Data privacy
Your data stays yours
Quarria is built for teams that can't afford to leak strategy. What you put in (your context, your questions, your results) never trains AI, never gets shared, and always stays under your control.
We never train AI on your data
We never use what you put into Quarria to train or fine-tune AI models. Your strategy is an input to your intelligence, not to anyone's training data.
Encrypted in transit, secrets encrypted at rest
All traffic runs over TLS. Any third-party credentials you connect are encrypted at rest, and raw tokens are never stored in plain text.
Isolated per customer
Your data lives in its own space, never mixed with or visible to any other customer.
Only what's needed
We send the minimum needed to generate your briefing, and nothing more. We don't sell data, and there are no ads.
Yours to export, yours to delete
Export your data whenever you want, and ask us to delete your account and data whenever you want. What you build in Quarria, you own.
Traceable and governed
Every result records the exact prompt and sources that produced it, so your intelligence is something you can stand behind and defend.
Enterprise
Built for security reviews
Bringing Quarria to a security review? Talk to us about how your data is handled today, deployment options, and roadmap items such as customer-managed keys and SSO.
Hosted infrastructure
Quarria runs on Railway (cloud infrastructure) with a dedicated PostgreSQL database per environment. All traffic is TLS-encrypted. Database credentials live in environment variables, never in source control. The deployment pipeline scans dependencies for CVEs automatically, and any build that fails a security check is blocked before it reaches production.
Questions about security?
We're glad to answer detailed questions from your security team.