// Security & trust

Secure by design.

Quarri runs on certified enterprise infrastructure with database-per-customer isolation, end-to-end encryption, full audit logging and customer-controlled data residency. For a platform whose job is holding your numbers, this page is the contract.

1 : 1
Customer-to-database mapping, no shared tables
0
Cross-tenant access paths, enforced below the application layer
AES-256
Encryption at rest, per tenant
OAuth
Tokens bound to a single customer database
// 01 · Foundations

Built on infrastructure that's already certified.

Quarri runs on AWS cloud infrastructure and an isolated, SOC 2 Type II certified data platform, and connects to Anthropic's Claude for reasoning. We inherit their compliance and add tenant isolation on top.

// Cloud infrastructure

AWS

Multi-AZ deployment in US or EU regions. SOC 2, ISO 27001 and FedRAMP certified. You choose the region; your data never leaves it.

// Data platform

Isolated by design

A SOC 2 Type II certified data platform with database-per-customer isolation at the platform level, physically separated, OAuth-bound, encrypted at rest with AES-256.

// AI integration

Anthropic Claude

Used for reasoning over your data via Quarri's tools. Customer data is never used to train models, under Anthropic's enterprise data terms.

// 02 · Tenant isolation

Your data, in your database. Always.

Every customer gets their own isolated database at the platform layer. No shared tables. No application-level cross-tenant access. OAuth tokens are bound to a single customer database, there is no API path that could read another customer's data.

// 03 · Encryption & residency

Encrypted in transit and at rest. Hosted where you choose.

01In transit.
TLS 1.2+ on every connection· HSTS enforced· Certificate pinning where supported· No plaintext data transmission, anywhere
02At rest.
AES-256 encryption with platform-managed keys· Geo-redundant snapshots within your region· Encrypted credential storage
03Residency.
US-only hosting available· EU-only hosting available· Locked at provisioning, data does not move regions· GDPR-aligned for EU customers
// 04 · Access & audit

Least-privilege access. Every action logged.

Role-based access control with quarterly reviews, and a comprehensive audit trail accessible to customers on request.

01Authentication.
Unique credentials per user· 12+ character password complexity· Failed-login monitoring and account lockout· SSO / SAML on the roadmap
02Authorisation.
Admin and user role separation· Principle of least privilege· Access rights reviewed quarterly· Immediate revocation on offboarding
03Audit trail.
Full query history per user· Authentication events, success and failure· Configuration changes and admin actions· Customer-accessible logs on request· Immutable retention for the customer relationship
// 05 · What we won't do

Four explicit promises, enforced in the architecture.

01

No PII or PHI storage

Quarri does not store personally identifiable or protected health information. Data scope is contractual.

02

No model training

Customer data is never used to train Quarri's models, nor passed to Anthropic for training under our enterprise terms.

03

No cross-tenant access

No application or API path exists to read another customer's data. Isolation is enforced below the application layer.

04

No user-injected code

Users cannot directly inject or execute code. Pipelines are generated only by controlled agents running in subprocess isolation.

// 06 · Reliability & recovery

Continuous backup. Recovery in hours, not days.

A documented disaster recovery plan with continuous replication, regional redundancy, and a 72-hour customer-notification commitment for any incident affecting your data.

99.9%
Uptime SLA, measured monthly
4 hr
Recovery time objective (RTO)
1 hr
Recovery point objective (RPO)
30 days
Geo-redundant snapshot retention

Continuous database replication · daily integrity verification · annual full DR test · 72-hour customer notification on incidents

See it on your own data. Securely.

Live in two weeks, on the systems you already run.