QIOI
Security & privacy

Designed with security and privacy controls.

Security is an operating practice, not a badge. Below is how QIOI is built — and an honest statement of what it does not yet claim.

Controls

How QIOI is built

Secure authentication

Email verification and support for multi-factor authentication, with role-based access.

Organization separation

Instances and data are isolated per organization; production and staging are separated.

Encrypted secrets

Credentials are encrypted at rest, never written to logs in plaintext, and scoped least-privilege.

Audit logging

Consequential actions are recorded as audit events with actor, metadata, and timestamp.

Backup encryption

Backups are encrypted, and restore is a first-class, tested operation.

Secure deletion

Deletion is explicit and confirmed — dangerous actions require typing the instance name.

Rate limiting & CSRF

Input validation, secure cookies, CSRF protection, and rate limiting on sensitive endpoints.

Least-privilege credentials

Provider root credentials are never exposed to application instances.

Your data

You keep control.

Isolated instances, region selection, and no forced provider lock-in.

  • Dedicated or isolated application instances
  • Choice of supported model providers
  • External API keys remain customer-controlled where possible
  • Region selection at deploy time
  • Exportable data and downloadable backups
  • Clear data-retention policies

An honest statement

What QIOI does not claim

QIOI does not claim SOC 2, ISO 27001, HIPAA, or GDPR certification. Where a certification or attestation is not formally held, this site will not imply it. Any compliance status will be stated only once it is genuinely obtained, with its scope.

Certification placeholders remain empty until earned.

Private by construction.

Run isolated AI applications, choose your region and providers, and export your data whenever you need it.