Skip to main content
Security is foundational to QuivaWorks’ architecture. This guide covers platform security and helps you navigate the rest of the security documentation.

Quick Security Setup

New to QuivaWorks? Complete these steps:
1

Enable MFA

Set up multi-factor authentication after creating your accountSet up MFA →
2

Save recovery codes

Store your recovery codes in a password manager or another secure locationAbout recovery codes →
3

Review sessions

Check your active sessions and terminate any you don’t recogniseManage sessions →
4

Secure API keys

If you’re using the API, follow the key management practicesAPI security guide →

Platform Security

Compliance & Certifications

ISO 27001

Information security management system certified

SOC 2 Type II

Coming soon - Independent audit of security controls

GDPR

Compliant. We erase personal data and answer subject access requests on request — see Your data rights

PCI DSS

Self-attested compliant; card data is handled by our payment provider
Get in touch if you need to process protected health information.

Data Protection

Encryption in Transit

All connections use HTTPS. TLS 1.2 is the minimum version accepted.

Data Hosting

Choose how your data is hosted after signup. The available region is Europe.About data hosting →

Data Isolation

Multi-tenant architecture with logical separation between accounts

Redundancy

Choose 1 or 3 nodes for your account. Three nodes replicate your data — and use three times the storage.

Your data rights

Under the GDPR you can ask us to give you a copy of the personal data we hold about you, correct it, or erase it. We honour all three.
1

Make the request

Write to us through the help centre from the email address on the account, saying which right you are exercising. We may ask you to confirm your identity before we act on it.
2

We respond within one month

That is the statutory deadline. Complex requests may take longer, and we will tell you before the month is out if that applies.
3

Erasure

Deleting your account removes its data. Where a request covers data we hold outside an account, we erase that too, except where we are required to keep it — billing records, for example, have their own statutory retention period.
These requests are handled by our team rather than through a self-service screen today. We are building tooling to make export and erasure something you can run yourself; until then, the route above is the one that works, and it is the one we support.

Account Security Features

Authentication & Access Control

Multi-Factor Authentication

Protect your account with passkeys or an authenticator appPrompted at every login until enabled

Session Management

Monitor and terminate active logins across all devices24-hour session tokens, 7-day refresh tokens

API Keys

Programmatic access with user- or account-scoped keys90-day expiry by default

Role-Based Access

Seven roles, from root through to clientApply least privilege

Security Notifications

You’ll receive an email for these events:
  • Password changed or reset
  • Email address change requested, and again when it completes
  • A new passkey added
  • Recovery codes viewed
  • A new user added to the account
  • An API key about to expire, and again when it expires
If you receive a notification for something you didn’t do, work through the incident response steps immediately.

Security Best Practices

  • Use a strong, unique password
  • Enable MFA as soon as you create your account
  • Store recovery codes in a password manager
  • Review your active sessions periodically
  • Never paste a session token from Copy token anywhere it could be read by someone else
  • Keep your browser and operating system updated
Authentication guide →
  • Encourage MFA across the team — especially for root and admin users
  • Apply least privilege when assigning roles, and review them periodically
  • Offboard departing users promptly: Logout ends their live sessions, Suspend blocks future sign-ins, and their API keys need deleting separately
  • Keep the number of root and admin users small
User management guide →
  • Never hardcode API keys in source
  • Use environment variables or a secret manager
  • Prefer a restricted key when an integration only needs a few endpoints
  • Rotate keys before they expire — a warning email arrives 7 days ahead
  • Never log a key or a session token
API key best practices →

If Something Goes Wrong

Incident Response

Suspect an account is compromised? Work through the response steps to lock it down.Common indicators:
  • Sessions from locations or devices you don’t recognise
  • Security notification emails for actions nobody performed
  • Account settings or users changed unexpectedly
  • Unexplained credit consumption

Privacy

How QuivaWorks collects, uses and retains personal data is set out in the privacy policy.

Content sent to model providers

Prompts, and the arguments of external (MCP) tool calls Abbie makes while handling a conversation, are not written into QuivaWorks’ own application logs. For requests to OpenAI models, server-side storage is also turned off: Abbie resends the relevant conversation history itself with every turn, so nothing needs to be kept on the provider’s side between turns.
This is separate from Data Retention, which controls how long QuivaWorks itself keeps your conversation history and is yours to set — see Account Settings.

Privacy Policy

What we collect, how it’s used, and your rights

Terms of Service

Legal terms and service agreement
You control how long assistant conversation history is kept from Data Retention on the Account page — see account settings. Closing your account is covered in closing an account. For a privacy or data protection question, contact us through the help centre.

Reporting a Security Vulnerability

We appreciate responsible disclosure.
If you find a security issue:
  1. Do not publicly disclose or exploit it
  2. Get in touch through the help centre with a description, steps to reproduce, your assessment of the impact, and how to contact you
  3. Allow reasonable time for us to investigate before disclosing

Security Resources

Authentication Guide

MFA, passkeys and passwords

Session Management

Monitor and terminate active logins

API Key Security

Scopes, restricted keys and rotation

Incident Response

What to do if an account is compromised

User Management

Invite, suspend, log out and remove users

Roles & Permissions

What each of the seven roles can do

Security Checklist

When you set up

  • Enable MFA (passkey or authenticator app)
  • Save your recovery codes somewhere secure
  • Set a strong, unique password
  • Choose how your data is hosted

Periodically

  • Review your active sessions
  • Review the API keys on your account and delete unused ones
  • Check for users who no longer need access
  • Review user roles against what people actually do

As needed

  • Offboard departing users — Logout, Suspend, delete their keys, then delete the user
  • Investigate every security notification email you didn’t expect
  • Rotate API keys ahead of expiry

Getting Help

Help Centre

Security questions, privacy questions, vulnerability reports and general support