SECURITY OVERVIEW
Security built around business boundaries
Launch-review draft ยท 7 September 2026
Pre-launch notice: these documents remain subject to final solicitor review and public paid subscriptions are not yet open.
This page describes controls implemented in the current product and the production checks required before public paid launch. It is not a claim of certification.
Identity and access
- Server-side sessions use secure, HTTP-only cookies and durable user identities.
- Workspace access is resolved from server-side business membership on every protected request.
- Administrative access is separately allowlisted and role checked.
- Production identity is prepared for OpenID Connect with verified email, password recovery and optional MFA managed by the identity provider.
Tenant separation and data controls
- Business records, saved state, assets, backups, analytics and feedback are scoped to the authenticated business ID.
- Owners can export structured workspace data, create restore points and initiate permanent account deletion.
- Uploads are type and size constrained. Sensitive workspace data is not placed in client-visible credentials.
Application and operational safeguards
- Origin checks protect state-changing forms and APIs; billing webhooks require provider signatures.
- Production builds run calculation, authentication, access-control, tenant-boundary, legal, billing, mobile and rendered-output tests.
- Launch gates keep public signup and billing off until legal, hosting, identity, domain and payment prerequisites all pass.
- Security incidents follow the written triage, containment, evidence, notification and recovery runbook.
Shared responsibility
Customers must control authorised users, protect devices and credentials, avoid unnecessary special-category data, verify estimates before sending them, and promptly report suspected compromise to security@quercusquote.app.