Quotinc Security

S Security & data protection

You are handing us the engine
your revenue runs on.

So we will be plain about it. Here is what protects your rates, your clients and your quotations today, what we are strengthening next, and exactly which companies ever touch your data. No security theater, no claims we cannot stand behind.

Last updated 1 July 2026 · We are pre-certification and we say so.

In place today

Every item below is live in the product right now. If it is on the roadmap instead, it is in the next section, not this one.

Isolation

Your workspace is walled off from every other desk

Each customer is a separate tenant. Every record is tied to a tenant identity that our servers derive from your logged-in session. It can never be set by a browser or an API call. Our backend enforces that boundary on every read and rejects any write that would cross it.

Your edge

We never train on your rates

Your supplier rates never train a shared model, never benchmark you against another desk, and never get sold. They are your edge, not our dataset. This is a written promise, not a setting.

Encryption

Encrypted end to end in transit

All traffic runs over TLS with HTTPS forced and HSTS with preload. Your structured data lives in managed Postgres, which encrypts it at rest.

Sign-in

Passwords hashed, sessions signed

Passwords are hashed with bcrypt and never stored or logged in the clear. Sessions ride cryptographically signed, HTTP-only, Secure cookies. Operator and customer logins are separate realms with separate credentials.

Accountability

A full audit trail

We record the security-relevant actions inside your workspace, sign-ins, failed sign-ins, permission changes, record changes, with the actor, the tenant and a timestamp.

AI assistant

The assistant only sees your quote

Our AI assistant only ever reads the quotation you are actively editing and your own catalog, scoped to your tenant on the server. It cannot reach another customer's data, and it cannot write to the database. It proposes changes you approve, through the same audited path as a human edit.

Portable

You can leave whenever you want

Export every quote, rate, rooming list and total to XLSX, PDF and PPTX in one click. No export fee, no hostage data. We will delete your workspace on request. The way out is built in, so the way in is safe.

Secrets

Credentials stay out of our code

API keys and signing secrets are held as environment configuration on the server, never committed to our codebase and never shipped to the browser.

Disclosure

We tell you who touches your data

Every third party in the data path is listed on our subprocessors page, kept current. If that list changes, the page changes with it.

What we are strengthening next

We would rather show you the roadmap than pretend it is finished. These are in build or scheduled, and we are happy to talk timelines on a call.

  • Database-level tenant isolation. A second isolation layer enforced by the database itself, so that even a bug in application code cannot return another tenant's row. It is built and tested; we are scheduling the production cutover. We will only claim it here once it is live.
  • Brute-force protection on sign-in. Per-account and per-address rate limiting on all login and password-reset endpoints. Built and landing in the current release.
  • Automated, tested off-site backups. Extending scheduled backups with a rehearsed restore across both your database and your uploaded files.
  • Independent penetration test. A third-party review, with a findings-and-remediation summary we can share under NDA.
  • SOC 2 readiness. We are building toward a formal audit. In the meantime we will complete your security questionnaire honestly, line by line.
  • Higher availability. A documented path to a second application instance and redundant storage as the pilot cohort grows.

How we divide responsibility

Security is a shared job. Here is the honest split.

We own

The platform

Tenant isolation, encryption, patching, backups, audit logging, and the security roadmap on this page. We keep the walls up.

You own

Your access

Who you invite, what role you give them, and removing people when they leave. Use strong, unique passwords. Tell us fast if an account is compromised, and we will act.

Straight answers to the usual questions

Are you SOC 2 or ISO 27001 certified?

Not yet. We are a young company at design-partner stage and we will not pretend otherwise. We are building toward a formal audit, and in the meantime we will complete your vendor security questionnaire honestly and walk your security team through the architecture on a call.

Where does our data live?

Your structured data (quotations, rates, clients, catalog, audit logs) lives in managed Postgres. Uploaded files (attachments, images, receipts) are stored on our application infrastructure. Every external company that touches your data is listed on our subprocessors page.

Can another customer ever see our rates?

No. Every request is scoped to your tenant, derived from your session on our servers and never trusted from the browser. Reads are filtered to your tenant and cross-tenant writes are rejected. We are also rolling out a database-level backstop so the same rule is enforced a second time, at the database itself.

What does the AI assistant send to a third party?

To generate a suggestion, the assistant sends the quotation you are editing and your own catalog to Anthropic's Claude, our AI provider. It is used only to produce your result. It is not used to train shared models, and the assistant can only ever see your tenant's data. We can go through the specifics with your team.

Can we get our data out, or have it deleted?

Yes to both. Export every quote and rate to XLSX, PDF and PPTX yourself in one click, no fee. Ask us to delete your workspace and we will. Your data is yours.

What happens if there is a breach?

We keep an audit trail to investigate quickly, and we commit to notifying affected customers without undue delay. Reach us at sales@quotinc.com.

Will you sign our DPA?

Yes. Send it over, or ask us for ours. We will also complete your security questionnaire.

Have a question we did not answer?

Talk to us directly. At this stage you get the founders on the call, not a ticket queue, and real influence over what we build next.

Email us about security See our subprocessors