Quorum reads sensitive systems, so we keep the access narrow, the data short-lived and every decision logged. Here is exactly how.
Access we ask for
Read-only everywhere, apart from opening pull requests in your code host.
What we store, and for how long
Everything runs in AWS us-west-2 unless you run the scanner in your own account.
Audits and controls
SOC 2 Type II
Report covering security and availability, shared under NDA.
Yearly penetration test
By an outside firm. The summary letter is available on request.
Encryption
TLS 1.2 or later in transit, AES-256 at rest, keys rotated yearly.
SSO and SCIM
SAML with Okta, Google or Microsoft Entra on Business.
Subprocessors
We tell customers 30 days before adding one.
Report a vulnerability
Email security@quorumscan.dev with the steps to reproduce. We reply within one business day, keep you updated until it is fixed and will not take action against good-faith research.
Rewards run from $200 to $5,000 depending on impact. Please give us 90 days before publishing.
Run a free scan on one repo
Connect one repo and one cloud account with read-only access. You get the findings and the first fix pull requests within a day, and you keep them either way.