> ## Documentation Index
> Fetch the complete documentation index at: https://docs.quivly.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and Compliance

> Quivly is SOC 2 Type II compliant and applies security, privacy, and access controls to protect customer data.

## Compliance

| Framework     | Status      |
| ------------- | ----------- |
| SOC 2 Type II | Compliant   |
| ISO 27001     | In progress |
| GDPR          | In progress |
| HIPAA         | In progress |

The [Quivly Trust Center](https://trust.mycroft.io/quivly) has the latest compliance status, SOC 2 Type II report, security policies, controls, and subprocessors.

<Warning>
  Contact Quivly at [privacy@quivly.ai](mailto:privacy@quivly.ai) before processing protected health information or other specially regulated data.
</Warning>

## How Quivly protects your data

Quivly's security program covers encryption, vulnerability management, network boundaries, segregated environments, secure software development, vendor risk management, incident response, business continuity, and disaster recovery. The [Trust Center](https://trust.mycroft.io/quivly) lists the current policies and controls.

Customer data is scoped to your Quivly organization. The app, [Slack bot](/product/ask-quivly-slack), [Ask Quivly](/product/ask-quivly), and [MCP server](/developers/mcp-server) only return data from the signed-in user's organization.

[Admins](/settings/organization-settings) manage integrations, settings, and team access. Deactivating a member removes access immediately.

## Connected systems and AI actions

[Data-source integrations](/integrations/introduction) are read-only. Quivly never writes back to your CRM, billing, support, or warehouse systems on its own.

Outbound actions — such as sending an [email](/integrations/communication/gmail), posting a [Slack](/integrations/communication/slack) message, or creating a [calendar](/integrations/communication/google-calendar) event — only happen through [workflows](/product/agents) your team configures.

[Agents](/product/agents) support Review steps that pause a workflow for human approval. Recommendations generated by [signal rules](/product/signal-rules) are always drafts in [Actions](/product/actions).

[AI-generated answers](/product/ask-quivly) should be verified before they're used for customer or revenue decisions.

## Privacy

The [Quivly Privacy Policy](https://www.quivly.ai/privacy-policy) explains how personal information is collected, used, transferred, and disclosed.

Current subprocessors and security documents are available through the [Trust Center](https://trust.mycroft.io/quivly).

For security or privacy questions, contact [privacy@quivly.ai](mailto:privacy@quivly.ai).
