Security

Your customer data belongs to you, not to our AI

Quack is trained on your documentation and your ticket history. That data stays isolated to your tenant and is never used to train models for any other customer.

AES-256
Encryption at rest
TLS 1.3
Encryption in transit
SOC 2
Type II audit in progress

Data handling and storage

How we store your data

  • Encryption at rest

    All customer data is encrypted at rest using AES-256. This includes ingested documentation, ticket archives, and trained model weights specific to your account.

  • Encryption in transit

    All data in transit is encrypted using TLS 1.3. API calls from your helpdesk to Quack, and from Quack back to your helpdesk, use HTTPS with certificate pinning on production endpoints.

  • Tenant isolation

    Each customer's data, including model weights, vector embeddings, and raw ticket data, lives in a logically isolated tenant environment. There is no shared data layer between accounts.

  • Data residency

    All data is stored in US-East (AWS us-east-1) by default. EU data residency (eu-west-1) is available on Scale plans upon request.

What we do not do with your data

  • No cross-tenant model training

    Your ticket data and documentation are never used to train, fine-tune, or improve the model for any other customer. The model trained on your data works only for your account.

  • No data sold or shared

    Quack does not sell, license, or share your customer data with third parties for any purpose other than operating the service you signed up for.

  • No retention after termination

    When you cancel your account, all of your data, including trained model weights, is deleted within 30 days. You can request immediate deletion at any time.

Access controls and compliance

Access controls

  • Role-based access

    Quack supports Admin, Member, and Read-only roles. Admins can manage integrations and model settings. Members can view analytics and ticket results. Read-only access is available for audit users.

  • SSO (Scale plan)

    Single Sign-On via SAML 2.0 is available on the Scale plan. SCIM provisioning for automated user lifecycle management is included with SSO.

  • Audit logging

    Scale plan accounts include full audit logs: who changed which setting, when a new doc source was connected, when Quack's confidence threshold was adjusted. Logs are exportable via API.

Compliance status

  • SOC 2 Type II

    Our SOC 2 Type II audit is in progress with an expected completion in Q4 2026. We will publish the report upon completion. A summary of controls is available on request for enterprise evaluations.

  • GDPR

    Quack acts as a data processor under GDPR. We offer a Data Processing Agreement (DPA) for all customers. EU customers can request the DPA at [email protected].

  • Vulnerability reporting

    We accept security disclosures at [email protected]. We target a 48-hour acknowledgment and 14-day remediation timeline for critical issues.

Need a security review before you sign up?

We are happy to walk your security team through our controls. Email us to request a security questionnaire response or a DPA.