QwotraBook a demo

Security and Data Handling

Your commercial data stays yours.

Qwotra separates the private information your team needs from the customer-safe information that belongs in the proposal. This page states plainly what the product does, who processes your data, and how retention and deletion work. Everything here is a current fact, not a roadmap item.

01 - Product controls

Customer-safe output by design

Two separate outputs. Every project produces a customer proposal and a private internal job record. They are built from separate layers; the internal record never ships with the proposal.

Supplier identity stays internal. Supplier and subcontractor names, vendor quote numbers, item codes, and source costs are removed from the customer layer by construction.

Markup and margin stay internal. Your pricing rules, markup, and gross margin live only in the internal record and internal views.

Leak check before export. A final scan of the exact export checks for supplier names, source costs, quote numbers, and internal codes. A failed check blocks the export.

02 - Account and access

Access is deliberate

Accounts are approved individually during early access; powerful actions (export, upload, email, download) are off by default until enabled.

Sign-in uses a password or an emailed sign-in link, with self-serve reset. Password rules are enforced on the form and the server, handled by our authentication provider; Qwotra never stores plaintext passwords.

Roles are enforced at the database: owner, admin, estimator, sales, viewer. Source-cost visibility follows role rules.

Administrative access is restricted to named individuals, and every mutating administrative API call is recorded in an append-only audit log.

03 - Encryption and hosting

The deployed infrastructure, plainly

All traffic to Qwotra is encrypted in transit (HTTPS/TLS).

The application, database, authentication, and file storage run on established commercial cloud platforms.

Every account's data is isolated with database-level row security.

Uploaded vendor quote files live in private, account-scoped storage; download links are short-lived and signed.

Credentials and API keys are held in environment configuration, never in source code.

The database is backed up daily; independent backups are pruned at 90 days.

Our providers may store or process data in the United States and other regions; we do not claim Canada-only data residency.

04 - Processing providers

Who processes your data

Qwotra uses established commercial service providers for:

Application hosting

Database, authentication, and private document storage

AI-assisted document processing, through a commercial API

Payments and billing (card numbers never touch Qwotra)

Transactional email and business communications

Documents you run through the Smart features can include supplier names, costs, and pricing, and are sent to our AI provider through its commercial API to produce your results. Under that provider's commercial terms as of our policy date, API data is not used to train its models without express permission, which we have not granted, and your data is not used to train public or third-party general-purpose models. Details are in the Privacy Policy. The current list of subprocessors is available to customers and serious evaluators through our security-review process or a data-processing agreement.

05 - Retention and deletion

The data lifecycle, by category

Raw customer data stays while your account is active; deleting a project also removes its stored vendor files.

On account closure or a verified deletion request, raw data leaves live systems within 30 days after the export window and ages out of backups; no backup copy is kept longer than 90 days.

Customer-linked records (account, billing, acceptance, audit) are kept as long as the law and the signed agreement require; protected aggregate information that cannot reasonably identify or reconstruct your business may be retained as stated in the Terms and Privacy Policy.

We never delete your data over a payment problem. A paused account keeps its data for at least 90 days so you can pay and resume or export everything, and we email you before anything further happens.

06 - Incidents and questions

Security contact and incident response

Security contact: brent@qwotra.com. It reaches the founder directly.

Found a vulnerability? Report it to the same address and we will respond, investigate, and tell you what we did.

If we ever discover a breach affecting your data, we will notify you promptly with what we know and what we are doing, consistent with Canadian breach-notification requirements, and we keep the records those requirements demand.

Reviewing Qwotra as a vendor and need documentation? Request security documentation and we will work through your checklist with you.

Clear facts beat vague reassurance.

Qwotra does not currently hold a SOC 2 or ISO certification and does not claim one. No service can promise perfect security, and we don't. What we publish here is what is actually deployed, and we keep this page current as the product evolves. The full legal detail lives in the Privacy Policy and Terms of Service.

← Back to Qwotra