Quillreach

Security & trust

Security you can verify. Not just claim.

How Quillreach protects your data, your LinkedIn accounts, and your customers' contact information. With specifics, not slogans.

In one sentence

Quillreach protects every workspace with row-level access controls inside the database itself, encryption in transit and at rest, and automated security checks gating every code change. We never store your LinkedIn password, and we don't use your inbox to train AI models.

Your LinkedIn accounts, paced to stay safe

Security isn't only about data, it's about the accounts you can't get back. Quillreach sends at human pace with hard per-account daily caps that respect LinkedIn's organic-behavior thresholds, randomizes timing, and stops the moment someone replies. Those limits are enforced as constraints, not toggles you have to remember, so scaling outreach never means giving LinkedIn a reason to restrict or ban an account.

Workspace isolation, enforced at the database

Every table that holds user data (campaigns, leads, conversations, settings, audit logs) has row-level access policies that scope reads and writes to members of the owning workspace. The check runs inside the database itself, not just in application code. A bug in our app layer can't override it; a leaked database key can't override it. This is the defense-in-depth posture we wanted, so we paid the up-front cost of writing the policies.

Encryption everywhere it matters

Traffic between you and Quillreach is served over TLS. Database storage is encrypted at rest with industry-standard encryption, and backups inherit the same encryption. Production secrets live in an encrypted vault scoped per environment, so preview and production never share credentials.

Your LinkedIn account, never your password

Quillreach connects to LinkedIn without ever storing your password. You authenticate once through a secure flow, and we keep a token scoped to your account that you can revoke at any time. We don't see, store, or transmit your LinkedIn password, and we never replay your LinkedIn cookies into a browser extension.

Authentication you control

Sign in with email or Google. Sessions are stored in secure cookies that rotate on a rolling basis, and you can revoke any session from your account in a single click. Every authentication event (sign-in, password change, new device) is recorded in your recent-activity panel so you can spot anything that wasn't you.

Every code change reviewed before it ships

Every change to Quillreach passes through automated security checks (secret scanning, the full test suite, a required security checklist) before it can be merged. Production releases never bypass review. The discipline shows up where it matters: bugs that get caught at review never become incidents your account sees.

Common questions

Questions we didn't answer?

Email security@quillreach.com. Real humans reply, usually within a business day.