Security
Security at Qualia.
This page is maintained by the Qualia team to answer common security and privacy questions about Qualia and our platform. It is not an independent audit or certification.
Contact security →Access & authentication
Read-only by default
Qualia connects to your tools with the narrowest scopes it can request for each integration. Read-only access is the default. Write access is enabled per integration and per action type, and only after you approve it. Money-touching actions always remain behind human approval, regardless of an agent's autonomy level.
Action log
Every action logged
Every action an agent takes — reads, writes, drafts, decisions — is recorded with the agent, task type, inputs, outputs, and the human who approved it (when applicable). You can review the log at any time.
Reversibility
Reversible by design
Where the underlying system supports it, agent actions are reversible: PRs can be closed, drafts can be discarded, changes can be rolled back. Where reversibility is not possible in the underlying system, the action stays behind human approval by default.
Data handling
Your data stays yours
Qualia stores the operational data required to run the agents you enable: connector metadata, agent runs, decisions, and their outputs. Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Customer data is not used to train foundation models.
Subprocessors
Who we rely on
Qualia uses a small set of infrastructure and model providers to operate. A current subprocessor list, DPA, and security questionnaire are available on request from security@thinkqualia.com.
Compliance roadmap
SOC 2 on the roadmap
Qualia is not currently SOC 2, ISO 27001, HIPAA, or PCI-DSS certified. SOC 2 Type I is on our 2026 roadmap. We share progress with prospective customers under NDA. Anyone claiming Qualia holds a certification it does not is misrepresenting us.
Report a vulnerability
Responsible disclosure
If you believe you have found a security vulnerability in Qualia, please email security@thinkqualia.com with details. We acknowledge reports within two business days and will keep you informed as we investigate.