Security
An honest summary of how QoreIQ is built to protect your organisation's data.
Per-organisation isolation
Every table enforces row-level security in the database, strictly scoped to your organisation. There is no shared query path between tenants.
No provider keys in the browser
AI provider credentials never reach the browser. Every model call is made server-side, on your organisation's behalf.
Encrypted credentials for connected sites
Credentials for connected WordPress sites are encrypted at rest.
Drafts only, never live posts
WordPress publishing from QoreIQ always creates a draft. Nothing is published live without a person choosing to do so in WordPress itself.
Audit log of administrative actions
Administrative actions are recorded in a full audit log.
Configurable retention
Conversation retention is configurable, so you can control how long chat history is kept.
UK GDPR posture
People can request an export or deletion of their own chat data, in line with UK GDPR.
Invitation-only membership
Nobody can join an organisation's workspace without an invitation from an administrator.
What we do not claim
QoreIQ does not currently hold SOC 2, ISO 27001, or any other formal security certification. What's described above reflects how the system is actually built today, not a certified or independently audited standard. If a formal certification matters to your organisation, please get in touch before relying on this page.