Security

Security for work that has to stand behind a report.

Quotia is designed to keep client work private, limit access to the right people, and preserve the decisions behind each report.

Last updated July 26, 2026

Access follows the organization and the job.

Protected work requires an authenticated account. Quotia evaluates access using the active organization, membership, role, permissions, assignments, and the state of the record being requested.

  • Workspace owners and authorized administrators manage membership and roles.
  • Permissions control who can view, edit, review, approve, and administer work.
  • Assignment-aware checks narrow access when a role is limited to assigned work.
  • Production sessions use secure, HTTP-only cookies and password-reset links expire.

Evidence and documents stay behind private access.

The application is designed to store evidence files and report assets in private object storage. When a file is eligible for access, Quotia checks the requesting user and issues a short-lived, read-only link rather than exposing the storage container directly.

Uploaded evidence is checked against supported file signatures, content types, and size limits. It is not available to workflows, previews, or read links until the configured security check records it as clean. If scanning is unavailable, new uploads are blocked; if a scan fails or times out, the file remains quarantined and unusable until a clean result is recorded.

Workflow and report controls preserve context.

A published Playbook version stays fixed for jobs already using it, so later template changes do not silently rewrite in-progress work. Reviews, requested changes, approvals, and generated report versions remain connected to the job record.

Workflow rules and report content are validated against bounded schemas and allowlists. Quotia rejects raw HTML, event handlers, unsafe data URLs, unsafe URL forms, and unregistered document nodes rather than treating stored customer content as trusted application code.

AI-assisted editing stays under human control.

AI editing produces a reviewable suggestion. It does not change a report automatically. An authorized user chooses which suggested changes to apply, can discard the suggestion, and can undo the latest applied change set.

When an authorized user requests AI-assisted editing, Quotia sends the instruction, document title and current sections, relevant variable metadata, requested section keys, and any selected template or image context to OpenAI. Quotia sets store: false on the API request; provider processing and any service-level retention remain governed by OpenAI's applicable terms.

Application security controls.

  • Production configuration requires HTTPS and TLS-protected database connections.
  • Browser responses include content, framing, referrer, transport, and permissions protections.
  • Authentication, uploads, signed links, document actions, AI requests, invitations, and webhooks are rate-limited.
  • Application logging applies redaction to credentials, tokens, email addresses, query strings, evidence fields, request bodies, and provider errors.
  • Quotia maintains documented incident-response, deployment, access-review, and recovery procedures.

This page describes safeguards built into Quotia's application and required by its production configuration. It does not constitute an independent certification, audit assurance, regulatory certification, or customer-specific compliance outcome.

Security is a shared responsibility.

  • Choose roles and assignments that match each person's job.
  • Remove access promptly when a person no longer needs the workspace.
  • Protect account credentials and use a unique, strong password.
  • Upload only information your organization is authorized to collect and process.
  • Report suspected unauthorized access to [email protected].

Report a security concern.

Email [email protected] with “Security concern” in the subject line. Please do not include passwords, access tokens, or client evidence in the first message.