Trust & Security

Security for sensitive documents and data.

Quantiva handles confidential documents and structured analysis, so protection is foundational — not an afterthought. This page summarizes the safeguards in place across our application, processing, storage, and operating process.

Last updated: 19 June 2026
Isolation

Strict multi-tenant isolation

Every organization's data — submissions, documents, knowledge base, and users — is segregated and accessed only within that organization. Cross-organization access is structurally prevented and covered by a dedicated test suite.

Encryption

Encrypted in transit & at rest

All traffic is served over HTTPS with HSTS, and session cookies are secure and HTTP-only. Data is stored on managed infrastructure with encryption at rest.

Documents

Private document storage

Uploaded documents are kept in private, access-controlled object storage — never publicly addressable — and namespaced per organization. Every file is validated and screened according to the deployment security configuration before it is stored or processed.

Database

Managed database with backups

Application data lives in a managed database with backups and point-in-time recovery configured for production operations, so data can be restored if needed.

Authentication

Strong authentication

Passwords are hashed with bcrypt and protected by brute-force throttling. Self-service password recovery uses single-use, time-limited links. Additional account safeguards, including two-factor authentication where enabled, active-session review, and session revocation, are supported.

Access control

Least-privilege roles

Role-based access (submitter, approver, admin) is enforced on every request, so disabled accounts and revoked permissions lose access immediately.

Auditability

Tamper-resistant audit trail

Security-relevant actions are recorded in an append-only audit log that cannot be edited or deleted, and administrators can review a content-free activity dashboard for their organization.

Your data

Retention & deletion you control

Administrators can set how long original documents are retained, request deletion of stored documents, and request a data export or account deletion where available. Document deletions are logged as evidence.

Processing

Protected processing commitments

Workspace documents are processed to deliver the requested output and are not used to train public models. Processing providers are bound by commercial, confidentiality, and data-use commitments.

Review

Human judgment stays final

Quantiva prepares structured outputs for review. Outputs may be incomplete or require correction, so qualified users remain responsible for decisions, approvals, and professional reliance.

How your data is retained — and what isn't

You control the lifecycle of your data, and we keep only what's necessary to deliver the service.

DataRetention
Uploaded documentsKept only for the retention period you configure, then deleted automatically. You can request deletion at any time, and every deletion is recorded as evidence.
Data processingDocument content is processed solely to provide the requested workspace output. Customer workspace documents are not used to train public models.
Analyses & recordsRetained in your account so your team can review history — exportable or deletable on request.
BackupsEncrypted backups are retained for disaster recovery and rotated on a schedule; deleted data ages out as backups rotate.
On account closureYour organization's data is deleted on request, with nothing retained beyond what law requires.

Infrastructure assurance

Quantiva uses infrastructure and subprocessors selected for security, reliability, and independently audited controls. We avoid naming vendors publicly, but can share relevant subprocessor and assurance materials with customers and qualified prospects under NDA.

LayerProvider-held assurance materials available where applicable
Application hosting, database, and private storageSOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018PCI DSSCSA STAR
Document processingSOC 2 Type IIISO/IEC 27001ISO/IEC 27018Data Processing AgreementSubprocessor controls
Privacy and cross-border safeguardsData Processing AgreementStandard Contractual ClausesPrivacy program documentationTransparency reporting

These are provider-held certifications, attestations, and contractual safeguards where applicable; they are not a claim that Quantiva itself currently holds those certifications. Subprocessor details, assurance materials, and a Data Processing Agreement are available to customers and qualified prospects on request, under NDA.

Responsible disclosure

Found a potential security issue? We appreciate responsible disclosure. Please contact us at security@getquantiva.com and we'll respond promptly.

This page describes current security practices for informational purposes and is not a standalone contractual commitment. Practices evolve; contact us for the latest details, a Data Processing Agreement, or a security questionnaire.