AI chatbot security at Quikori

How we protect customer conversations, uploaded knowledge, integration secrets, and tenant data.

Every business gets a separate data boundary

Quikori is built for multi-tenant SaaS use: each customer account is separated so one business cannot read another business's sources, conversations, or settings.

The isolation is enforced at the database layer as well as in the application, which gives an extra line of defense beyond ordinary route checks.

Encryption

Customer data is encrypted at rest and in transit. Integration secrets and access tokens are stored with an additional encryption layer before they are written.

Quikori never asks customers to paste payment card details into the product. Billing is handled through Stripe Checkout and Customer Portal.

Authentication

Role-based access separates platform administration from customer dashboards. Team members only see the surfaces their role allows.

Audit logs

Important account, billing, and authentication events are recorded with actor and timestamp details.

Professional and Enterprise teams can review tenant-scoped audit activity from the dashboard.

Access control

Access is limited to the people and services that need it. Production access is audited and separated from day-to-day product use.

Secrets are not exposed as customer-facing settings.

Compliance

Quikori is aligned with GDPR and KVKK expectations, including customer data export and deletion workflows.

SOC 2 Type II and ISO 27001 are planned. Until certification is complete, we publish the controls customers need for vendor review.

Responsible disclosure

Report a vulnerability to [email protected]. We acknowledge within 48 hours and triage within 5 business days.

A signed security report is available under NDA on request.

This page describes current controls. A signed security report is available under NDA. Contact [email protected].