Designed with security and privacy controls.
Security is an operating practice, not a badge. Below is how QIOI is built — and an honest statement of what it does not yet claim.
How QIOI is built
Secure authentication
Email verification and support for multi-factor authentication, with role-based access.
Organization separation
Instances and data are isolated per organization; production and staging are separated.
Encrypted secrets
Credentials are encrypted at rest, never written to logs in plaintext, and scoped least-privilege.
Audit logging
Consequential actions are recorded as audit events with actor, metadata, and timestamp.
Backup encryption
Backups are encrypted, and restore is a first-class, tested operation.
Secure deletion
Deletion is explicit and confirmed — dangerous actions require typing the instance name.
Rate limiting & CSRF
Input validation, secure cookies, CSRF protection, and rate limiting on sensitive endpoints.
Least-privilege credentials
Provider root credentials are never exposed to application instances.
You keep control.
Isolated instances, region selection, and no forced provider lock-in.
- Dedicated or isolated application instances
- Choice of supported model providers
- External API keys remain customer-controlled where possible
- Region selection at deploy time
- Exportable data and downloadable backups
- Clear data-retention policies
An honest statement
What QIOI does not claim
QIOI does not claim SOC 2, ISO 27001, HIPAA, or GDPR certification. Where a certification or attestation is not formally held, this site will not imply it. Any compliance status will be stated only once it is genuinely obtained, with its scope.
Certification placeholders remain empty until earned.
Private by construction.
Run isolated AI applications, choose your region and providers, and export your data whenever you need it.