Skip to main content

Security & SOC 2 Compliance — Qably

Zero-Trust Security Architecture

Security & SOC 2 Compliance

Engineered to meet the stringent information security and compliance requirements of modern engineering teams.

End-to-End Encryption

TLS 1.3 in transit with strict HSTS and AES-256 encryption at rest across all PostgreSQL databases and backups.

SOC 2 Type II & ISO 27001

Continuously audited controls for system availability, confidentiality, and processing integrity.

RBAC & Scoped Tokens

Project-scoped tokens prefixed with qbly_live_* with SHA-256 hashing and granular organization roles.

1. Source Code Isolation & Zero Model Training

Qably operates on the principle of least privilege. We never clone or retain complete codebases on persistent disk. When the AI agent parses pull request diffs, execution occurs in ephemeral, isolated sandboxes and memory is immediately purged upon assertion extraction.

2. Audit Logging & Access Tracking

All administrative actions in apps/web and authenticated API queries in apps/api generate immutable audit trails with timestamps, IP addresses, user identities, and affected resources.

3. Continuous Vulnerability Management

We execute automated continuous dependency auditing (pnpm audit), periodic third-party penetration tests, and static analysis scanning on every release.

4. Requesting the SOC 2 Report

Customers on Team and Enterprise tiers can request our complete SOC 2 Type II audit report under a standard mutual non-disclosure agreement (NDA) by emailing [email protected].