Security
How we protect your data.
No badges to wave — just a plain account of what QuoteHQ actually does to keep your business data safe.
Credentials and API keys are encrypted at rest
Anything sensitive you connect to QuoteHQ — your QuickBooks Online connection, an AI provider API key, a bank account number you add for remittance instructions — is encrypted before it's stored, using authenticated encryption (AES-256-GCM). We don't store these values as plain text.
Your organization's data is isolated
QuoteHQ is multi-tenant: every business record — leads, clients, proposals, invoices, payments — belongs to exactly one organization, and every read and write is scoped to that organization. One customer's data is never visible to another, and that isolation is verified by automated tests, not left to convention.
Your database is backed up before every change
QuoteHQ's database runs on Neon, which supports point-in-time recovery. On top of that, we take a snapshot of the production database immediately before every schema change we deploy, so a bad change can be rolled back to the moment before it happened.
Your data is yours
You are the controller of the leads, clients, proposals, and invoices you put into QuoteHQ — we process it on your behalf, isolated from every other organization on the platform. Anything you sync to QuickBooks Online also lives in your QuickBooks file, not only in QuoteHQ. We keep your data while your account is active and only as long as required after that.
We don't sell your data
We don't sell your personal information, and we don't use your data to train general-purpose AI models. See our Privacy Policy for the full detail on what we collect, who we share it with, and your rights.
For the full legal detail — subprocessors, data retention, your rights — read our Privacy Policy. Found a security issue? Email support@myquotehq.com and we’ll get back to you.