How Quelvio protects your knowledge.
Your knowledge is among the most sensitive corpus your company holds — every memo, every decision, every internal discussion. Quelvio is built so your data stays separated and yours, people see only what they're already allowed to see, everything is encrypted and audited, and you stay in control of access and removal. This page documents the protections in place today.
Eight headline controls that operate across every Quelvio tenant. Each links to the architectural detail below.
Your knowledge is fully separated from every other customer's, at every layer — database row-level security on your data, per-customer retrieval, partitioned storage — and continuously verified.
OAuth 2.1 for humans, Personal Access Tokens for headless, Service Accounts for CI — all hashed, never logged.
Admin-configured session age, idle limits, IP allowlists, PAT and Service Account caps — fail-closed on violation.
HRIS-driven revocation of every session and credential in a single transaction. Idempotent, rolled back on failure.
Every sign-in, change, and query captured in a hash-chained, exportable audit trail admins can review — and it can't be quietly altered.
Per-customer AES-256-GCM encryption (AWS KMS) at rest, TLS 1.2+ in transit, and customer-managed keys (BYOK) for Enterprise.
Region selection at tenant creation — Global, Europe, or Americas. EU tenant data never leaves EU infrastructure.
Key-destruction erasure across all backup copies — when you erase, we destroy the key and every copy becomes permanently unreadable. Anyone can pause or erase what's remembered about them, anytime.
Vendor security questionnaires, DPAs, and the customer information packet are available to enterprise prospects under NDA.
Get Quelvio updates delivered to your inbox. No spam, unsubscribe anytime.