Quorify

Security

Your data belongs to you.

Quorify is built with security as a foundation, not an afterthought. Every product decision was made with data protection as a primary requirement.

100% EU data storage
Every organization fully isolated
GDPR compliant
Externally penetration tested

Hosting

Your data stays in Europe

No information leaves the European Union.

All databases, files, documents and backups are stored on servers within the European Union. There are no copies in the US or any other region. When you upload a document or save member data, it stays in Europe.

DatabasePostgreSQL servers in the EU
Files and documentsEncrypted storage in the EU
AuthenticationEU servers
Error monitoringEU, with automatic anonymization of sensitive data
Transactional emailEU provider
Data transfer outside EUNone
Quorify does not sell or transfer organization or member data to third parties for commercial or advertising purposes. Ever.

Isolation

Your organization is fully isolated

No other organization can access your data, under any circumstances.

Each organization's data is separated at the database level — not through a software rule that could be bypassed, but through the system's architecture. Even if the application had a bug, your data could not reach another organization, and theirs could not reach yours.

Each account has access strictly limited to its own organization. Admins see more than members, and the founder has full control — but no role can cross the boundaries the system enforces.

Isolation guarantees

No other organization can view or access your data
Members cannot access data outside their role and permissions
Your data is never used for advertising or commercial purposes
Quorify team access: in technical support cases, Quorify team members may access your organization's data solely for that purpose. Any such access is automatically recorded in an internal audit log and cannot be used for any other purpose.

Encryption

Everything is encrypted

Sensitive data is protected both while it travels and while it is stored.

Data in transit

All connections between your browser and Quorify servers use HTTPS. No data travels over the network in unencrypted form.

Data at rest

Infrastructure encrypts all databases and files at the disk level. Backups are encrypted too.

Sensitive field-level encryption

The national ID number (CNP) collected via Form 230 is encrypted separately with a dedicated key before it reaches the database. Even the Quorify team cannot read it.

IP addresses

IP addresses are never stored in a directly identifiable form. Before storage, they are processed through an irreversible hashing algorithm.

Account

Your account is protected by multiple layers

More than just a password stands between your account and unauthorized access.

Two-factor authentication

Available to all users and enforced on the web platform. Even if someone knows your password, they cannot sign in without the second verification.

One-time codes

At each sign-in, you receive a code by email. There are no permanent passwords that can be guessed or intercepted over time.

Recovery codes

If you lose access to your authenticator app, you can use the recovery codes generated when you set up two-factor authentication.

Protection against automated attacks

Repeated sign-in attempts are blocked automatically. There is no way to test thousands of passwords without being stopped.

Logging

Every action is recorded

As an administrator, you have full visibility into everything that happens in your organization.

Every member invitation, document change, vote or settings update is logged with the date, time and the person responsible. The log is available directly from the platform, in your organization's settings section.

Adding or removing members
Changes to documents and folders
Votes and decisions in meetings
Organization settings changes
Financial transactions and dues
Sensitive data (IBAN, national ID) is automatically excluded from the log. It never appears in the activity history.

GDPR

Your data, your rights

You have full control. You can export, correct or delete any data in your account, at any time.

We act as a data processor under GDPR. We process your information strictly in accordance with your instructions and never share it with anyone without explicit consent.

Access

You can request a copy of all your personal data we hold.

Portability

You can export your data directly from account settings, at any time.

Deletion

You can permanently delete your account, including associated documents and stored files.

Rectification

You can modify or correct your profile data directly from the platform.

Objection

You can request restriction of the processing of your data by contacting the team.

Guaranteed response

We respond to any GDPR request within one month.

GDPR requests go to contact@usequorify.com. Appointed DPO: Patriciu Rosata.

Questions

Frequently asked questions

Clear answers to the most common questions about how we handle data.

What happens to my data if I cancel my subscription?

You can export all your data before cancelling. If you delete your account, all information is permanently removed from our systems, including backups, in accordance with the DPA retention schedule. We do not keep data after deletion, except where required by law (for example, tax records).

Do you sell or share our organization's data?

No. Never. Your organization's data belongs entirely to you. We do not monetize it, share it with advertisers, or use it for anything other than providing the service you subscribed to.

Which third-party providers have access to our data?

We use infrastructure providers with servers in the EU for the database, file storage and email. No third party has access to your organization's documents or financial data. The full list of sub-processors is available in the DPA.

Do you carry out security testing?

Yes. We conduct periodic external penetration testing and fix any vulnerabilities found. If you have discovered a security issue, you can report it in the section below.

How is the national ID number (CNP) protected in Form 230?

The CNP is encrypted immediately on entry, before being stored in the database. Even the Quorify team cannot read it in clear form. It is used solely to generate the PDF form and transmit it to ANAF.

Security

Found a vulnerability?

We want to know. Report responsibly and we will protect you.

If you have identified a security issue in Quorify, please contact us directly. We will not pursue legal action against good-faith researchers who report responsibly.

Send your report to

Include: a description of the problem, reproduction steps and potential impact. We respond to every report and keep you updated through to resolution.

Safe harbor: we will not take legal action against researchers who report promptly, do not exploit the vulnerability, and do not access other people's data.
Scope: usequorify.com and subdomains, the mobile app. Out of scope: social engineering, physical attacks, denial-of-service.

Full responsible disclosure policy: /legal/security

Have a security or privacy question?

Our team answers any question related to protecting your organization's data.

Get in touch