Trust
Trust, in plain terms
Quarria is built for teams that cannot afford to leak strategy. Here is exactly what protects your data today, and what is still on our roadmap. No hand-waving.
In place today
Controls that protect your data now
Per-account data isolation
Every lens, signal, report, and business note is stored against your account and read back only for you. Queries are scoped by account, with no path to another customer's data.
Encrypted connections and secrets
All traffic runs over TLS. Any third-party credentials you connect are encrypted at rest with AES-256-GCM; the raw token never touches the database.
Hashed secrets
Passwords are hashed with bcrypt. Password-reset, email-verification, and team-invite tokens are stored only as SHA-256 hashes, never in the clear.
An audit trail for every result
Every report keeps an immutable snapshot of the exact prompt and the cited sources that produced it. You can export the full prompt-and-source trail for any run.
Session control
Sign-in uses signed, HTTPS-only sessions. Changing your password or suspending an account invalidates existing sessions immediately.
Hardened deployment
Quarria runs on managed cloud infrastructure with a dedicated PostgreSQL database. Credentials live in environment variables, and every deploy is scanned for known vulnerabilities before it ships.
Who else touches your data
Quarria uses a small set of third-party services to work: an AI model, web search, email, billing, and hosting. We list every one, and what it receives.
On the roadmap
What we are still building
We would rather under-promise. These are in progress and not available yet: enterprise SSO and SCIM, customer-managed AI keys, a formal signed DPA with subprocessor agreements, and a SOC 2 program. Tell us if any of these gate a purchase and we will share where they stand.
Questions from your security team?
We're glad to answer detailed questions in writing.