Back

Security at Quinvy

Protecting your business data is our highest priority.

1. Data Encryption

In Transit: All data sent to or from Quinvy is encrypted in transit using industry-standard Transport Layer Security (TLS/HTTPS). This ensures that your connections are secure and protected against interception.

At Rest: Our databases and storage systems employ robust at-rest encryption to protect your sensitive invoicing and client data from unauthorized access on the physical disks.

2. Payment Security

We do not store or process your credit card information directly. All subscription payments are securely processed by our Merchant of Record, Paddle. Paddle is fully PCI-DSS Level 1 compliant, which is the highest level of certification in the payment card industry.

3. Authentication and Access Control

  • Secure Login: We use secure authentication protocols (including JWT) to manage your active sessions. Passwords are cryptographically hashed and salted; we never store them in plain text.
  • Role-Based Access Control (RBAC): Our platform enforces strict role-based permissions (Owner, Admin, Member). This ensures that users within your organization only have access to the data and features necessary for their roles.
  • Verification & OTPs: Sensitive actions, such as changing your organization's primary email or deleting the organization entirely, require verification via a One-Time Password (OTP) sent to your registered email address.
  • Rate Limiting: We employ automated rate limiting and brute-force protection to prevent automated attacks on our authentication endpoints.

4. Infrastructure Reliability

Quinvy is hosted on top-tier, secure cloud infrastructure providers. We maintain regular automated backups of your data to ensure disaster recovery capabilities and high availability. Our systems are continuously monitored for unusual activity or performance degradation.

5. Reporting Security Vulnerabilities

We appreciate the efforts of security researchers and our users in keeping Quinvy secure. If you believe you have found a security vulnerability in our platform, please report it to our security team immediately. We ask that you do not publicly disclose the issue until we have had a chance to investigate and deploy a fix.