Quick Security Setup
New to QuivaWorks? Complete these steps:1
Enable MFA
Set up multi-factor authentication after creating your accountSet up MFA →
2
Save recovery codes
Store your recovery codes in a password manager or another secure locationAbout recovery codes →
3
Review sessions
Check your active sessions and terminate any you don’t recogniseManage sessions →
4
Secure API keys
If you’re using the API, follow the key management practicesAPI security guide →
Platform Security
Compliance & Certifications
ISO 27001
Information security management system certified
SOC 2 Type II
Coming soon - Independent audit of security controls
GDPR
Compliant. We erase personal data and answer subject access requests on request — see
Your data rights
PCI DSS
Self-attested compliant; card data is handled by our payment provider
Get in touch if you need to process protected health information.
Data Protection
Encryption in Transit
All connections use HTTPS. TLS 1.2 is the minimum version accepted.
Data Hosting
Choose how your data is hosted after signup. The available region is Europe.About data hosting →
Data Isolation
Multi-tenant architecture with logical separation between accounts
Redundancy
Choose 1 or 3 nodes for your account. Three nodes replicate your data — and use three times the storage.
Your data rights
Under the GDPR you can ask us to give you a copy of the personal data we hold about you, correct it, or erase it. We honour all three.1
Make the request
Write to us through the help centre from the email address on
the account, saying which right you are exercising. We may ask you to confirm your identity
before we act on it.
2
We respond within one month
That is the statutory deadline. Complex requests may take longer, and we will tell you before
the month is out if that applies.
3
Erasure
Deleting your account removes its data. Where a request covers data we hold outside an
account, we erase that too, except where we are required to keep it — billing records, for
example, have their own statutory retention period.
These requests are handled by our team rather than through a self-service screen today. We are
building tooling to make export and erasure something you can run yourself; until then, the route
above is the one that works, and it is the one we support.
Account Security Features
Authentication & Access Control
Multi-Factor Authentication
Protect your account with passkeys or an authenticator appPrompted at every login until enabled
Session Management
Monitor and terminate active logins across all devices24-hour session tokens, 7-day refresh tokens
API Keys
Programmatic access with user- or account-scoped keys90-day expiry by default
Role-Based Access
Seven roles, from root through to clientApply least privilege
Security Notifications
You’ll receive an email for these events:- Password changed or reset
- Email address change requested, and again when it completes
- A new passkey added
- Recovery codes viewed
- A new user added to the account
- An API key about to expire, and again when it expires
Security Best Practices
For all users
For all users
- Use a strong, unique password
- Enable MFA as soon as you create your account
- Store recovery codes in a password manager
- Review your active sessions periodically
- Never paste a session token from Copy token anywhere it could be read by someone else
- Keep your browser and operating system updated
For administrators
For administrators
- Encourage MFA across the team — especially for root and admin users
- Apply least privilege when assigning roles, and review them periodically
- Offboard departing users promptly: Logout ends their live sessions, Suspend blocks future sign-ins, and their API keys need deleting separately
- Keep the number of root and admin users small
For developers
For developers
- Never hardcode API keys in source
- Use environment variables or a secret manager
- Prefer a restricted key when an integration only needs a few endpoints
- Rotate keys before they expire — a warning email arrives 7 days ahead
- Never log a key or a session token
If Something Goes Wrong
Incident Response
Suspect an account is compromised? Work through the response steps to lock it down.Common indicators:
- Sessions from locations or devices you don’t recognise
- Security notification emails for actions nobody performed
- Account settings or users changed unexpectedly
- Unexplained credit consumption
Privacy
How QuivaWorks collects, uses and retains personal data is set out in the privacy policy.Content sent to model providers
Prompts, and the arguments of external (MCP) tool calls Abbie makes while handling a conversation, are not written into QuivaWorks’ own application logs. For requests to OpenAI models, server-side storage is also turned off: Abbie resends the relevant conversation history itself with every turn, so nothing needs to be kept on the provider’s side between turns.This is separate from Data Retention, which controls how long QuivaWorks itself keeps your
conversation history and is yours to set — see Account Settings.
Privacy Policy
What we collect, how it’s used, and your rights
Terms of Service
Legal terms and service agreement
Reporting a Security Vulnerability
We appreciate responsible disclosure.
- Do not publicly disclose or exploit it
- Get in touch through the help centre with a description, steps to reproduce, your assessment of the impact, and how to contact you
- Allow reasonable time for us to investigate before disclosing
Security Resources
Authentication Guide
MFA, passkeys and passwords
Session Management
Monitor and terminate active logins
API Key Security
Scopes, restricted keys and rotation
Incident Response
What to do if an account is compromised
User Management
Invite, suspend, log out and remove users
Roles & Permissions
What each of the seven roles can do
Security Checklist
When you set up
- Enable MFA (passkey or authenticator app)
- Save your recovery codes somewhere secure
- Set a strong, unique password
- Choose how your data is hosted
Periodically
- Review your active sessions
- Review the API keys on your account and delete unused ones
- Check for users who no longer need access
- Review user roles against what people actually do
As needed
- Offboard departing users — Logout, Suspend, delete their keys, then delete the user
- Investigate every security notification email you didn’t expect
- Rotate API keys ahead of expiry
Getting Help
Help Centre
Security questions, privacy questions, vulnerability reports and general support