Secure by design.
Quarri runs on certified enterprise infrastructure with database-per-customer isolation, end-to-end encryption, full audit logging and customer-controlled data residency. For a platform whose job is holding your numbers, this page is the contract.
Built on infrastructure that's already certified.
Quarri runs on AWS cloud infrastructure and an isolated, SOC 2 Type II certified data platform, and connects to Anthropic's Claude for reasoning. We inherit their compliance and add tenant isolation on top.
AWS
Multi-AZ deployment in US or EU regions. SOC 2, ISO 27001 and FedRAMP certified. You choose the region; your data never leaves it.
Isolated by design
A SOC 2 Type II certified data platform with database-per-customer isolation at the platform level, physically separated, OAuth-bound, encrypted at rest with AES-256.
Anthropic Claude
Used for reasoning over your data via Quarri's tools. Customer data is never used to train models, under Anthropic's enterprise data terms.
Your data, in your database. Always.
Every customer gets their own isolated database at the platform layer. No shared tables. No application-level cross-tenant access. OAuth tokens are bound to a single customer database, there is no API path that could read another customer's data.
Encrypted in transit and at rest. Hosted where you choose.
Least-privilege access. Every action logged.
Role-based access control with quarterly reviews, and a comprehensive audit trail accessible to customers on request.
Four explicit promises, enforced in the architecture.
No PII or PHI storage
Quarri does not store personally identifiable or protected health information. Data scope is contractual.
No model training
Customer data is never used to train Quarri's models, nor passed to Anthropic for training under our enterprise terms.
No cross-tenant access
No application or API path exists to read another customer's data. Isolation is enforced below the application layer.
No user-injected code
Users cannot directly inject or execute code. Pipelines are generated only by controlled agents running in subprocess isolation.
Continuous backup. Recovery in hours, not days.
A documented disaster recovery plan with continuous replication, regional redundancy, and a 72-hour customer-notification commitment for any incident affecting your data.
Continuous database replication · daily integrity verification · annual full DR test · 72-hour customer notification on incidents
See it on your own data. Securely.
Live in two weeks, on the systems you already run.