Zero-Trust Security Architecture
Security & SOC 2 Compliance
Engineered to meet the stringent information security and compliance requirements of modern engineering teams.
End-to-End Encryption
TLS 1.3 in transit with strict HSTS and AES-256 encryption at rest across all PostgreSQL databases and backups.
SOC 2 Type II & ISO 27001
Continuously audited controls for system availability, confidentiality, and processing integrity.
RBAC & Scoped Tokens
Project-scoped tokens prefixed with qbly_live_* with SHA-256 hashing and granular organization roles.
1. Source Code Isolation & Zero Model Training
Qably operates on the principle of least privilege. We never clone or retain complete codebases on persistent disk. When the AI agent parses pull request diffs, execution occurs in ephemeral, isolated sandboxes and memory is immediately purged upon assertion extraction.
2. Audit Logging & Access Tracking
All administrative actions in apps/web and authenticated API queries in apps/api generate immutable audit trails with timestamps, IP addresses, user identities, and affected resources.
3. Continuous Vulnerability Management
We execute automated continuous dependency auditing (pnpm audit), periodic third-party penetration tests, and static analysis scanning on every release.
4. Requesting the SOC 2 Report
Customers on Team and Enterprise tiers can request our complete SOC 2 Type II audit report under a standard mutual non-disclosure agreement (NDA) by emailing [email protected].
