Security

An honest summary of how QoreIQ is built to protect your organisation's data.

  • Per-organisation isolation

    Every table enforces row-level security in the database, strictly scoped to your organisation. There is no shared query path between tenants.

  • No provider keys in the browser

    AI provider credentials never reach the browser. Every model call is made server-side, on your organisation's behalf.

  • Encrypted credentials for connected sites

    Credentials for connected WordPress sites are encrypted at rest.

  • Drafts only, never live posts

    WordPress publishing from QoreIQ always creates a draft. Nothing is published live without a person choosing to do so in WordPress itself.

  • Audit log of administrative actions

    Administrative actions are recorded in a full audit log.

  • Configurable retention

    Conversation retention is configurable, so you can control how long chat history is kept.

  • UK GDPR posture

    People can request an export or deletion of their own chat data, in line with UK GDPR.

  • Invitation-only membership

    Nobody can join an organisation's workspace without an invitation from an administrator.

What we do not claim

QoreIQ does not currently hold SOC 2, ISO 27001, or any other formal security certification. What's described above reflects how the system is actually built today, not a certified or independently audited standard. If a formal certification matters to your organisation, please get in touch before relying on this page.