Quantiva handles confidential documents and structured analysis, so protection is foundational — not an afterthought. This page summarizes the safeguards in place across our application, processing, storage, and operating process.
Every organization's data — submissions, documents, knowledge base, and users — is segregated and accessed only within that organization. Cross-organization access is structurally prevented and covered by a dedicated test suite.
All traffic is served over HTTPS with HSTS, and session cookies are secure and HTTP-only. Data is stored on managed infrastructure with encryption at rest.
Uploaded documents are kept in private, access-controlled object storage — never publicly addressable — and namespaced per organization. Every file is validated and screened according to the deployment security configuration before it is stored or processed.
Application data lives in a managed database with backups and point-in-time recovery configured for production operations, so data can be restored if needed.
Passwords are hashed with bcrypt and protected by brute-force throttling. Self-service password recovery uses single-use, time-limited links. Additional account safeguards, including two-factor authentication where enabled, active-session review, and session revocation, are supported.
Role-based access (submitter, approver, admin) is enforced on every request, so disabled accounts and revoked permissions lose access immediately.
Security-relevant actions are recorded in an append-only audit log that cannot be edited or deleted, and administrators can review a content-free activity dashboard for their organization.
Administrators can set how long original documents are retained, request deletion of stored documents, and request a data export or account deletion where available. Document deletions are logged as evidence.
Workspace documents are processed to deliver the requested output and are not used to train public models. Processing providers are bound by commercial, confidentiality, and data-use commitments.
Quantiva prepares structured outputs for review. Outputs may be incomplete or require correction, so qualified users remain responsible for decisions, approvals, and professional reliance.
You control the lifecycle of your data, and we keep only what's necessary to deliver the service.
| Data | Retention |
|---|---|
| Uploaded documents | Kept only for the retention period you configure, then deleted automatically. You can request deletion at any time, and every deletion is recorded as evidence. |
| Data processing | Document content is processed solely to provide the requested workspace output. Customer workspace documents are not used to train public models. |
| Analyses & records | Retained in your account so your team can review history — exportable or deletable on request. |
| Backups | Encrypted backups are retained for disaster recovery and rotated on a schedule; deleted data ages out as backups rotate. |
| On account closure | Your organization's data is deleted on request, with nothing retained beyond what law requires. |
Quantiva uses infrastructure and subprocessors selected for security, reliability, and independently audited controls. We avoid naming vendors publicly, but can share relevant subprocessor and assurance materials with customers and qualified prospects under NDA.
| Layer | Provider-held assurance materials available where applicable |
|---|---|
| Application hosting, database, and private storage | SOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018PCI DSSCSA STAR |
| Document processing | SOC 2 Type IIISO/IEC 27001ISO/IEC 27018Data Processing AgreementSubprocessor controls |
| Privacy and cross-border safeguards | Data Processing AgreementStandard Contractual ClausesPrivacy program documentationTransparency reporting |
These are provider-held certifications, attestations, and contractual safeguards where applicable; they are not a claim that Quantiva itself currently holds those certifications. Subprocessor details, assurance materials, and a Data Processing Agreement are available to customers and qualified prospects on request, under NDA.
Found a potential security issue? We appreciate responsible disclosure. Please contact us at security@getquantiva.com and we'll respond promptly.
This page describes current security practices for informational purposes and is not a standalone contractual commitment. Practices evolve; contact us for the latest details, a Data Processing Agreement, or a security questionnaire.