Your Data & Security

Your data stays yours.

Every document, session, and answer is isolated to your organization, never used to train our models, and encrypted everywhere it lives.

Try for Free
Data Isolation

Who can see my data?

Documents

Strictly private to you. Storage paths are user-scoped, and the system refuses to retrieve any document that doesn't belong to the authenticated user making the request.

Sessions

Private by default. Assigning a session to a project makes the Q&A visible to that project's organization's members. Uploaded files stay private.

Projects

Organization-scoped. All members of your organization can see and access projects within it, no one outside it can.

Cross-Organization Access

Architecturally prevented. Each user belongs to exactly one organization.

Is my data used to train DPO?

Never.

Your session content is used only to generate your response in that moment. It is not retained for model training by Quantide. Quantide keeps logs of all sessions for Quality Assurance purposes only.

Security Standards

How is my data kept secure?

Encrypted everywhere

Data is encrypted in transit with TLS and at rest in storage. Nothing moves or sits in the clear, from the moment you upload a document to the moment an answer is returned.

Least-privilege access

Every request is authenticated and authorized against the specific user and organization it belongs to. Access is granted narrowly, never by default.

User-scoped retrieval

Retrieval is bound to the authenticated caller. The system refuses to return any document or session that isn't scoped to the requesting user or their organization.

Centralized secrets management

Credentials and API keys are held in centralized, managed secret storage, never hard-coded and never exposed to client sessions.

What DPO stores, and who can see it.

Data type
Where it lives
Who can see it
Uploaded documents
Encrypted, user-scoped storage paths
Only you
Sessions
Encrypted database, scoped to owner
You by default; your org if assigned to a project. Quantide keeps logs of conversations for Quality Assurance purposes only.
Projects
Encrypted database, org-scoped
Members of your organization
Account & profile
Encrypted database
You and your org admins
Prompts & responses
Processed in-session; not retained for training
You, within your session. Quantide keeps logs of conversations for Quality Assurance purposes only.
Enterprise & Compliance

Built with SOC 2 in mind.

DPO is designed with SOC 2-aligned controls: logical access control, least privilege, centralized secrets management, and encrypted transport and storage. Formal SOC 2 certification is on the roadmap as the platform matures. Enterprise customers with stricter requirements can arrange isolated, single-tenant deployments and formal SLA commitments.

Have a security question we didn't answer?

Talk directly to the team responsible for how DPO handles your data.