Security
Built for the standards finance lives by.
Security, privacy, and auditability are not features we added. They are how the platform is built. Here is what your audit, security, and procurement teams need.
ISO 27001
Building our information security management system toward ISO 27001 certification.
In progress
GDPR
Data protection program for EU personal data: DPA, disclosed sub-processors, and data subject rights.
In progress
SOC 2 Type II
Independent audit of our security, availability, and confidentiality controls.
In progress
We report status as it is. Target dates are shared with customers and prospects under NDA.
Enterprise-grade protection
Your financials, protected at every layer.
Six commitments built into the platform, not bolted on for the security review.
Your data never trains models
Customer data is not used to train or fine-tune any model, ours or our AI providers. Your numbers inform your answers, nothing else.
Isolated by design
Every record is scoped to your organization at the database layer. There is no path, client-side or otherwise, to another tenant.
Read-only by default
Analysis runs in read-only transactions with statement timeouts. Quivv reads your finance data; it cannot rewrite it.
Encrypted in transit and at rest
TLS 1.2+ on every connection and AES-256 in storage. Customer-managed keys are available on enterprise plans.
Access on your terms
SAML SSO, SCIM provisioning, role-based permissions, IP allow-listing, and MFA. Included as standard, not sold as add-ons.
Every action on the record
Access, approvals, permission changes, and every AI answer with the queries behind it, kept in an immutable, exportable audit trail.
FAQ
Questions security teams ask us.
Your financials are the most sensitive data your company holds. We treat protecting them as the foundation of the product, not a box to tick before a sale: every control on this page is built in, reviewed, and documented.
Need more than the answers here? We share the documents your review team will ask for.
Request security documentationIs our data used to train AI models?
No. Customer data is never used to train or fine-tune models, whether ours or those of our AI providers.
Where is our data hosted?
We use the GCP environment, and data is hosted in Europe. It does not leave the region without your explicit opt-in.
How is access to our data controlled?
Access is governed by the highest security practices: role-based permissions, IP allow-listing, MFA, SSO and SCIM.
Which AI providers process our data?
Anthropic is our primary model provider and OpenAI is the fallback.
How do you handle vulnerabilities?
Dependencies are scanned on every commit. Critical vulnerabilities are patched the same business day; medium severity within seven days.
Where are you on ISO 27001, GDPR, and SOC 2?
All three are in progress. We share target dates and our current status with customers and prospects under NDA.
Can our security team review your documentation?
Yes. Request documentation and it will be provided under an NDA.