Security and trust

Clear controls for a working pilot.

qraft is building working software around operational workflows. This page describes the verified controls and boundaries for the authenticated demo, FDE pilots, and quote workflows.

No certification claim

qraft does not claim SOC 2, ISO, HIPAA, or GDPR certification. Formal compliance claims will only be published after the relevant review is complete.

Verified workspace controls.

These are the controls qraft can describe for the current FDE and demo baseline.

01

Authenticated workspace access

Dashboard and lead-workspace access require authentication. Workspace records are scoped by company, and member visibility is restricted in current lead and quote flows.

02

Structured lead context

ARCHIDEX leads preserve owner, consent, source, conversation context, and next-action fields in the authenticated workspace so the team can review the capture and handoff together.

03

Review before consequential output

AI-assisted quote and WhatsApp workflows require review or confirmation before consequential output is saved or published.

04

Request safeguards

Sensitive request paths have rate limiting and/or audit logging where implemented. These controls are applied around the request flows that need them, not presented as a blanket guarantee.

Data boundaries matter.

The demo and a client-specific deployment are different boundaries. The intended audience for shared information should stay explicit.

01

Public quote links are intentionally shareable and show only the published quote presentation.

02

Quote-view records use a per-company hashed IP signal rather than storing the raw IP for that workflow.

03

Client-specific delivery should be separated from the public demo when the data or workflow boundary requires it.

04

The pilot boundary should stay deliberate: users should avoid placing unnecessary sensitive data in a demo or quote workflow.

Policy and delivery boundary.

This page is a factual product baseline. It does not replace the legal documents or a client-specific agreement for an FDE pilot.

For privacy, cookies, terms, and data-rights details, see the privacy policy, the cookie policy, and the terms. A pilot with client-specific data should use the agreed delivery and data boundary.

Report a security concern.

Send security issues, suspected abuse, or data-access concerns to support@qrafted.co. Include the affected workspace email, quote link or quote number if relevant, and a short description of what happened.

Contact qraft