Keep
On our side
- Conversation transcripts, so you can review them and so QUIRA has context within a conversation
- Your configuration — guardrails, tone settings, escalation rules
- The documents and policies you connect
- Usage data for billing
You're about to give a third party read access to your product catalog and your order records. You should ask hard questions about that, and you should get answers that don't hide behind badges.
QUIRA reads your product, inventory, and order data. It doesn't write to your commerce database, modify products, or change orders.
Access is limited to the tables and fields required to answer customer questions. Not your full database.
Cut access from your dashboard. No notice period, no support ticket, no negotiation.
QUIRA reads your data at the moment a question requires it. It doesn't bulk-replicate your catalog onto our servers and work from a copy.
Stored, skipped, and off-limits.
Keep
Skip
Never
All traffic between your store, our servers, and the customer's browser is encrypted.
Stored data, including transcripts, is encrypted.
Internal access to production systems is limited to team members who need it, and is logged.
Most security pages in this category lead with badges. Here is what we actually have and what we don't.
What we do today: read-only scoped access, encryption in transit and at rest, and no model training on your data.
What we don't have yet: we are not SOC 2 certified. We don't hold ISO 27001. We're a small company and those programs take time and money we're currently putting into the product.
If compliance is a hard requirement for you, talk to us before you spend time on an evaluation. We'd rather tell you on a first call that we don't meet your bar than discover it in your security review.
No. Your conversations and product data are not used to train any model, ours or our vendors'.
OpenAI. A full subprocessor list will live on /legal/subprocessors/ once the legal documents are published.
No. Access is read-only for commerce data.
Hosting region will be published here once confirmed. Until then, ask security@quira.ai and we will answer specifically.
Deletion timing will be published in the privacy policy. Until that document ships, email security@quira.ai for the current retention period.
Not yet — it is in progress. EU merchants should talk to us before an evaluation if a DPA is a hard requirement.
We follow specific practices today — data minimization, no training on customer data, deletion on request — and formal compliance work is underway. We do not claim to be GDPR compliant until that work is done.
No. If one occurs, we will disclose it.
Not a form that disappears. security@quira.ai reaches the team directly. If you've found a vulnerability, that's the address — we'll respond and we won't come after you for reporting it.