Security
Growth Insights Limited operates Quokka. These are the controls used for connected work data and the limits you should understand.
- Message bodies have a key for each person
- Message bodies, chat bodies and cached quote translations use application encryption tied to a person's key. OAuth tokens are also encrypted. Facts, contact details, metadata, chat titles, drafts and frozen sent copies are separate records protected by access controls and database protections; they do not share the message-body key.
- Erasure covers the live system and the restore process
- Removing a person's encryption key makes associated encrypted content unreadable in the live database. Older backups may still contain that key until they expire. Our restore procedure requires retained erasure instructions to be reapplied before access is reopened. Facts, contacts, metadata, drafts, sent copies and audit records need separate handling. We do not claim a universal deletion deadline or an unverified backup lifetime.
- Access and retention are separate decisions
- Removing a user revokes their access and stops further syncing from their connections. Existing work records can remain for the business. Managers and administrators can read authorized correspondence linked to company deals. Contact us for return or erasure of stored records; disconnecting or cancelling billing alone does not erase them.
- Access controls in the application and database
- Workspace checks and PostgreSQL row-level security restrict ordinary application access between customers. Automated regression checks cover tenant isolation and role permissions. Privileged service operations still require correctly scoped code and protected credentials; database separation is not a guarantee against every configuration or programming error.
- Mail is filtered before message bodies are opened
- Sender and subject filters exclude recognized medical, financial, job-related and personal threads before fetching new bodies. Filters can miss personal content, and a previously accepted conversation may later be excluded. Its source messages are then blocked from ordinary retrieval for viewing and AI processing. Previously derived profiles, custom fields and other records without complete source links may remain visible or be used again until separately reviewed or erased.
- Evidence helps you check results
- Extracted facts are checked against their quoted source. Human notes, corrections and imported CRM records have their own provenance. Evidence links help users review results, but they do not guarantee that a fact or AI interpretation is correct.
- Records of supported access and actions
- Quokka records supported actions, deal access, connection changes and operational results, including counts and model usage. Administrators can review product audit records. This is not a claim that every infrastructure or production access is logged by the application. Quokka does not provide an hours-worked or response-speed productivity score.
- Only the mailbox owner approves sending
- Quokka prepares drafts. The connected mailbox owner must explicitly approve the reply before it is sent. Managers and administrators cannot approve sending from a colleague's mailbox. Reading and AI processing take place before that approval; approval controls the outgoing email.
- Necessary cookies and operational records
- The app uses necessary sign-in and OAuth security cookies. We do not use advertising pixels or third-party analytics scripts. Hosting/security logs, audit events and sync counts are operational records, not an absence of all activity data. The privacy policy explains what is collected.
What we have not done yet
Quokka is in an unpaid beta. We have not completed an external penetration test or a SOC 2 audit. Do not treat this page as a security certification or evidence of completed Google verification. If your business needs an assessment, processing-location commitment or particular transfer agreement, contact info@askquokka.com before connecting that data.