The access Quorum asks for, and what it does with it

The access Quorum asks for, and what it does with it

Quorum reads sensitive systems, so we keep the access narrow, the data short-lived and every decision logged. Here is exactly how.

Access we ask for

Read-only everywhere, apart from opening pull requests in your code host.

System

Quorum can

Quorum cannot

GitHub, GitLab, Bitbucket

GitHub, GitLab, Bitbucket

Read code and metadata, open pull requests, comment on them

Read code and metadata, open pull requests, comment on them

Push to your default branch, change settings or merge

Push to your default branch, change settings or merge

AWS, Google Cloud, Azure

AWS, Google Cloud, Azure

Read configuration through a read-only role

Read configuration through a read-only role

Create, change or delete any resource

Create, change or delete any resource

Cloudflare

Cloudflare

Read zones, DNS records and certificates

Read zones, DNS records and certificates

Change records, rules or settings

Change records, rules or settings

Slack and Linear

Slack and Linear

Post in the channels and teams you choose

Post in the channels and teams you choose

Read other channels, messages or issues

Read other channels, messages or issues

What we store, and for how long

Everything runs in AWS us-west-2 unless you run the scanner in your own account.

Data

Kept for

Where

Source code

Source code

Not stored after a scan ends

Not stored after a scan ends

Your runner, or us-west-2 during the scan

Your runner, or us-west-2 during the scan

Findings metadata

Findings metadata

13 months, deletable at any time

13 months, deletable at any time

us-west-2

us-west-2

Approvals and merges

Approvals and merges

3 years on Business, 13 months on Team

3 years on Business, 13 months on Team

us-west-2

us-west-2

Application logs

Application logs

30 days

30 days

us-west-2

us-west-2

Audits and controls

SOC 2 Type II

Report covering security and availability, shared under NDA.

Yearly penetration test

By an outside firm. The summary letter is available on request.

Encryption

TLS 1.2 or later in transit, AES-256 at rest, keys rotated yearly.

SSO and SCIM

SAML with Okta, Google or Microsoft Entra on Business.

Subprocessors

We tell customers 30 days before adding one.

Company

What for

Location

Amazon Web Services

Amazon Web Services

Hosting, storage and the scan runners

Hosting, storage and the scan runners

United States

United States

Cloudflare

Cloudflare

DNS and edge protection for the web app

DNS and edge protection for the web app

Global

Global

Postmark

Postmark

Transactional email

Transactional email

United States

United States

Sentry

Sentry

Error tracking, with no source code attached

Error tracking, with no source code attached

United States

United States

Report a vulnerability

Email security@quorumscan.dev with the steps to reproduce. We reply within one business day, keep you updated until it is fixed and will not take action against good-faith research.

Rewards run from $200 to $5,000 depending on impact. Please give us 90 days before publishing.

Run a free scan on one repo

Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.