Security & Data Handling

Quaestor stores operational knowledge: roles, processes, systems, handoffs, decision criteria, SOPs, and internal workflows. That means security is not decoration. It is part of the product.

Last updated May 2026 This page states the current product posture without pretending to be a formal compliance report.
01

Data ownership

Your workspace data belongs to you. Quaestor does not claim ownership over your business processes, documents, org structure, internal workflows, or operational records.

02

AI and customer data

Customer data is not used to train public AI models. Where AI features are used, they are used to help structure, retrieve, or assemble customer-provided operational knowledge inside the customer workspace.

If an AI feature cannot meet that rule, the policy changes before the feature ships.

03

Encryption

Production traffic uses HTTPS/TLS in transit.

Production application infrastructure is hosted on AWS. The current product stack uses an Angular client, AWS API Gateway, AWS Lambda APIs, Drizzle, PostgreSQL on Amazon RDS, Amazon S3-backed uploads, Cognito authentication, and AWS Secrets Manager for database credentials.

At-rest encryption is confirmed for S3-backed uploads in the infrastructure code. We are verifying the live production database encryption setting before making a broader at-rest encryption claim.

04

Access controls

Workspace access is permissioned. Customers control who can view, edit, and administer their atlas.

Fine-grained role-based permissions are on the roadmap. Do not read this as a mature enterprise RBAC claim.

05

Backups and recovery

Production data is backed up on a recurring schedule through the managed database layer.

Formal recovery procedures are maintained and tested as the platform matures. Quaestor does not currently claim SOC 2-tested recovery controls, RTO, or RPO commitments on this page.

06

Data retention

Customer workspace data is retained while the account is active. After cancellation or written deletion request, data is deleted according to our retention schedule, except where retention is required for legal, billing, security, or backup purposes.

07

SOC 2 roadmap

Quaestor is not currently SOC 2 certified. We are building toward a formal compliance program as customer requirements demand it.

Subprocessors

Quaestor uses a limited set of infrastructure and service providers to operate the product and public trust-signal flows.

Amazon Web Services

Core product infrastructure, including AWS Lambda, API Gateway, Amazon RDS for PostgreSQL, Amazon S3, Cognito, Secrets Manager, SES, and CloudWatch.

Stripe

Payments, checkout, subscriptions, billing portal, and billing records.

Cloudflare

Public marketing site hosting, CDN, Pages previews, and edge functions.

Anthropic

AI-assisted scoring and structuring where AI features are enabled, including AI Score flows.

Supabase

AI Score intake persistence where configured during the public-site migration period.

Resend

Email delivery for public-site intake and AI Score review flows where configured.

Plausible Analytics and Google Analytics

Public-site analytics. Workspace content should not be sent to analytics providers.

Need the details?

Bring the question. We will answer what is true, mark what is in progress, and skip the theater.