Security

Last updated: January 2025

1. Our Security Commitment

Security is fundamental to Quotla. We protect your business data with industry-standard security measures and continuously improve our practices.

2. Encryption

  • In transit: All data is encrypted using TLS 1.3 during transmission
  • At rest: Database encryption using AES-256
  • Passwords: Hashed using bcrypt with salt

3. Access Controls

  • Google sign-in supported (inherits any 2FA on your Google account)
  • Role-based access control for team features
  • Session management with automatic expiration
  • API rate limiting and request validation

4. Infrastructure Security

  • Hosted on Convex (SOC 2 Type II certified)
  • Application hosted on Vercel (SOC 2 Type II certified)
  • Regular automated backups
  • DDoS protection

5. Vulnerability Management

  • Regular dependency audits (Dependabot)
  • Automated security scanning
  • Responsible disclosure program

6. Incident Response

In the event of a security incident, we follow a documented incident response plan including containment, investigation, notification, and remediation. Affected users will be notified within 72 hours.

7. Report a Vulnerability

If you discover a security vulnerability, please report it responsibly to [email protected]. We will respond within 48 hours.