Protection that matches the weight of unfinished work.
Research can be unpublished, commercially sensitive, personally revealing, and years in the making. This page explains the safeguards Quester uses today, the boundaries around your data, and the assurance claims we do and do not make.
Last reviewed: August 29, 2026
The trust compact
Four commitments before the architecture.
Quester receives only the limited rights needed to operate the service.
We do not use Research Content to train Quester or general-purpose AI models.
We do not sell personal data or use it for targeted advertising.
Provider certifications are not presented as certifications of Quester.
Data architecture
Research stays inside a small, explicit path.
The authenticated application is the gateway to workspace data. Quester separates account identity, core workspace records, uploaded documents, requested AI processing, payments, and optional product analytics so each provider receives only what its function needs.
Controls in place
Security is enforced at several layers.
Identity and sessions
WorkOS provides identity, sign-in, organization membership, and session management. Quester stores the sealed session in an HttpOnly cookie that is Secure in production and uses SameSite=Lax. Protected API routes authenticate the session on every request, and signing out revokes the provider session.
Workspace and project authorization
Server-side checks scope access through workspace, department, and project membership. Owner, administrator, and member roles determine who can view a project and who can manage membership, settings, billing, transfers, exports, or deletion. Production API requests with browser credentials are restricted to the configured application origin.
Encryption and storage
Application traffic uses HTTPS. Render's managed database and backups use provider encryption at rest, and Cloudflare R2 automatically encrypts objects and metadata at rest. Quester accesses uploaded documents with server-held storage credentials or time-limited signed requests; user documents are not published as website assets.
Secrets, uploads, and service boundaries
Production database credentials, storage credentials, AI keys, payment secrets, and identity-provider keys are supplied to server services through hosted secret configuration rather than exposed to the browser. Document uploads are limited by file type and size before processing. Stripe webhook signatures are verified before billing events are accepted.
Recovery, logs, and deletion
The managed database provides backup and recovery capabilities. Quester records selected sign-in, role-change, activity, billing, AI-usage, and operational events for service integrity and support. Document deletion uses tracked jobs with retry and recovery logic so a temporary storage-provider failure does not silently orphan a file.
AI boundary
AI is a feature path, not a claim on your work.
Quester currently uses commercial Google Gemini API services for tasks such as document metadata extraction, embeddings, analysis, and the Advisor. When a feature requires AI, Quester sends the prompt, document text, or workspace excerpts needed for that task. It does not send every project to every request.
We use business/API offerings under terms that do not permit submitted Research Content to train the provider's general-purpose models.
Quester does not use your Research Content to train models of its own. Outputs and selected context can be stored to provide the feature and conversation continuity.
A workspace manager can turn off new AI processing for a project while keeping its structured, non-AI workspace available.
AI output can be wrong or invent citations. Researchers remain responsible for reviewing claims, sources, methods, and academic-integrity requirements.
Analytics boundary
Product analytics cannot read the research.
Quester's PostHog integration is configured differently from ordinary website analytics. It accepts only reviewed event names and a typed allowlist of internal identifiers, counts, durations, plan and role classes, formats, and coarse feature categories.
Explicitly disabled
- Autocapture and automatic page views
- Session replay and surveys
- Exception and performance capture
- Persistent analytics cookies and browser identifiers
- Person profiles, referrers, and campaign parameters
Never permitted in events
- Source, note, question, model, or prompt text
- Document names, contents, or search queries
- Advisor messages or generated answers
- Email addresses, personal names, or organization names
- Raw URLs, referrers, or arbitrary custom properties
Analytics respects Do Not Track and can be disabled under Settings → Profile → Product analytics. The complete field-level boundary is described in our Privacy Policy.
Service map
Who helps provide Quester and what each receives.
| Function | Current provider | Boundary |
|---|---|---|
| Application and database | Render | Hosts core application services, workspace records, and managed backups. |
| Document storage | Cloudflare R2 | Stores uploaded source files and related object metadata. |
| Identity and sessions | WorkOS | Receives account identity, authentication, membership, and session data. |
| AI processing | Google Gemini API | Receives context needed for an AI task when AI processing runs. |
| Payments | Stripe | Handles checkout and payment credentials; Quester does not receive full card numbers. |
| Product analytics | PostHog | Receives only sanitized, allowlisted event metadata when analytics is enabled. |
Scholarly discovery features can also send an identifier, author name, or search terms to services such as Crossref, OpenAlex, Open Library, or Firecrawl when needed to perform the request. See the Privacy Policy for the fuller disclosure.
Researcher control
Security includes a practical way out.
- Choose collaborators deliberately. Owners and administrators control invitations, roles, and membership for shared workspaces and projects.
- Export projects. Project export provides a portable copy of the structured work and associated records available through the export workflow.
- Delete what you control. Account, project, source, document, note, Advisor, and other deletion controls are available subject to workspace roles and necessary retention.
- Turn off optional processing. Product analytics is an account preference; new AI processing can be disabled per project by a workspace manager.
- Protect your side of the boundary. Keep your sign-in method and device secure, review workspace members, and report unexpected access promptly.
Current assurance status
What Quester does not claim.
Quester uses providers with mature security programs, but their reports and certifications do not automatically certify Quester. Today:
- Quester has not completed a SOC 2 examination or ISO 27001 certification.
- Quester does not claim HIPAA or FERPA compliance.
- Quester does not currently publish an independent penetration-test report.
- Quester is not intended for protected health information, student education records, government identifiers, financial-account credentials, or identifiable raw research-participant data unless the required safeguards are agreed in writing first.
We can answer architecture, data-flow, retention, provider, and control questions using the implementation described here. Institution-specific data terms and additional safeguards must be evaluated before regulated data enters Quester.
Security contact
Report a vulnerability or account concern.
Send security reports privately to support@quester.tech with “Security report” in the subject. Include the affected URL or feature, clear reproduction steps, impact, and a safe way to contact you. Do not access, alter, retain, or publicly disclose another person's data, disrupt the service, or use destructive testing.
We will triage credible reports, investigate suspected incidents, work to contain and remediate confirmed issues, and notify affected people or authorities when applicable law requires it. For details about data practices and contractual responsibilities, read the Privacy Policy and Terms of Service.