Your data, private by default.
Quotra runs one shop's quotes, customers, and order history sealed off from every other shop — enforced at the database layer, not just the app. Here's exactly how we protect it.
Last updated: July 2026
- Per-tenant isolation
- TLS 1.2+ in transit
- Card data handled by Stripe
- Point-in-time backups
Tenant isolation
Every shop's data is separated at the database layer using Postgres row-level security, with per-tenant search indexes. One shop can never see or reach another shop's customers, pricing, or order history — it's structurally impossible, not just a permission check.
Encryption
All traffic between you, your customers, and Quotra is encrypted in transit with TLS 1.2 or higher. Backups are encrypted with AES-256 before they ever leave our servers.
Payments
PCI SAQ-A postureCard data is handled entirely by Stripe. Quotra never sees, touches, or stores your customers' card numbers, which keeps sensitive payment data out of our systems by design.
Backups & recovery
Continuous write-ahead-log archiving gives us point-in-time recovery, and our restore process is regularly tested — so a bad day means minutes of lost work, not your whole history. That's stronger backup discipline than most early-stage software.
Data ownership
Your data is yours. Export it any time, request deletion whenever you want, and know that we never sell it or share it with anyone. Full stop.
Responsible disclosure
Found a security issue? We want to hear about it — we'll respond promptly.
Reach us through our contact page →Uptime
We monitor availability continuously. A public status page is coming soon.
Compliance & enterprise
We keep compliance right-sized for a maker's shop — real protections, no expensive badges you'd be paying for and never using. When your buyers need paperwork, we have it ready.
Data Processing Agreement
Need a signed DPA for your records or your own customers? We have a standard one ready on request — just ask.
Payment compliance (PCI SAQ-A)
Because Stripe holds all card data and Quotra never touches it, we fall under the lightest tier of PCI DSS — the simplest, safest posture for a platform like ours.
Security overview on request
Evaluating Quotra for a larger operation? We'll share a plain-English security overview document to help your review.
Questions from a procurement or IT team? Reach us through our contact page →