Security posture, stated plainly

Quordo holds the keys to your AI estate, so we're specific about what we protect and how. This page describes the controls that are live today and the ones we're still building. We won't claim a certification we don't hold.

Certifications

Quordo is not SOC 2 certified today. SOC 2 is on our roadmap and we are building our controls toward it. When we achieve a certification or complete an audit, we will say so here with the report available under NDA — and not before. If your procurement process requires a specific attestation, tell us where you are in the buying process and we'll share our current status and timeline honestly.

Protecting provider credentials

Encrypted at rest

Provider API keys are encrypted at rest. They are the most sensitive thing Quordo holds, and they're treated that way.

Never returned to the UI

Once a credential is saved, it is never exposed back to the browser. The interface shows that a connection exists and what it's attributed to — never the secret itself.

Scoped, rotatable connections

Each provider connection is assigned to a team and can be rotated or removed. Historical attribution survives rotation because cost is stored on each usage event.

Data isolation & access

Row-level isolation per organization

Tenant data is isolated at the database layer with row-level security, so one organization cannot read another's cost, missions, or trace.

Role-based access within a workspace

Members hold roles within their workspace, scoping who can connect providers, set budgets, and manage members.

SSO / SAML & SCIM provisioning (roadmap)

Single sign-on and automated user provisioning are planned for the Enterprise plan, for organizations that centralize identity. This is on the roadmap, not yet available — if it's a procurement requirement, tell us and we'll share the timeline.

Auditability

Append-only agent trace

Agent activity — runs, context writes, handoffs, conflicts, resolutions — lands in an append-only trace. Entries are never edited or deleted, so the record can be trusted in a review.

Audit log of every mutation

Connecting a provider, assigning a team, setting a budget, dispatching a threshold alert — each is recorded in an audit log so you can reconstruct who changed what, and when.

Infrastructure & deployment

Managed cloud hosting

Quordo runs on managed cloud infrastructure with encryption in transit (TLS) and at rest. We use a small, defined set of sub-processors, listed below.

VPC or self-hosted deployment

Enterprise customers can run Quordo inside their own VPC or self-host it, keeping estate data within their boundary.

SOC 2 controls program (roadmap)

We are building the policies, monitoring, and evidence collection needed to pursue a SOC 2 examination. This is in progress, not complete.

Reporting a vulnerability

If you believe you've found a security issue in Quordo, please tell us before disclosing it publicly. Email [email protected] with the details and steps to reproduce. We'll acknowledge your report, investigate, and keep you updated on the fix. We don't pursue good-faith security researchers who follow responsible disclosure.