How Quelvio protects your knowledge.
Your knowledge is among the most sensitive corpus your company holds — every memo, every decision, every internal discussion. Quelvio's architecture is designed so that data stays isolated to your tenant, authenticated against every request, audited end-to-end, and recoverable when a person or a source needs to be removed. This page documents the controls in place today, the controls in active development, and the certifications we have and have not yet completed.
Eight headline controls that operate across every Quelvio tenant. Each links to the architectural detail below.
Per-tenant Qdrant collections, payload-level filters on every retrieval, cross-tenant leakage tests in CI.
OAuth 2.1 for humans, Personal Access Tokens for headless, Service Accounts for CI — all hashed, never logged.
Admin-configured session age, idle limits, IP allowlists, PAT and Service Account caps — fail-closed on violation.
HRIS-driven revocation of every session and credential in a single transaction. Idempotent, rolled back on failure.
Append-only audit trail of every authentication, configuration change, query, and revocation — surfaced to admins.
Fernet at rest with tenant-derived KEKs; TLS 1.3 in transit; TLS to RDS for every database connection.
Region selection at tenant creation — Global, Europe, or Americas. EU tenant data never leaves EU infrastructure.
Soft-delete at the source masks chunks immediately; full Postgres + Qdrant purge runs within 24 hours.
Vendor security questionnaires, DPAs, and the customer information packet are available to enterprise prospects under NDA.
Get Quelvio updates delivered to your inbox. No spam, unsubscribe anytime.