Isolation and privacy
Content owner: Quote Control product. Last reviewed: 29 August 2026.
Each pilot company runs in a separate Quote Control deployment with its own PostgreSQL database and private object store. Companies do not share a tenant table, bucket or sign-in workspace.
Server authority
Section titled “Server authority”The server checks account state, role, quotation ownership, company visibility and module availability on every protected route. Client navigation reflects those rules but is not the security boundary.
Independent approval remains separate from quotation ownership. A company setting cannot let an estimator approve their own higher-value work or bypass required preparation checks.
Private files and historical records
Section titled “Private files and historical records”Quotation documents and evidence stay in private object storage. The application authorises access before returning a file. Issued PDFs are retained with their revision, so later identity or policy changes do not rewrite the customer record.
Submitted revisions keep their commercial control and company-preference versions. Material actions produce audit events. Company administrators can review and export audit data or request a company export through controlled application actions.
Account names remain administrator-assigned during the pilot. Authentication exposes only session inspection, sign-in, sign-out and supported password flows; unsupported profile and raw password mutation routes are not product APIs. Administrator audit exports include a stable actor identifier as well as the display label and neutralize spreadsheet formula prefixes.
The public role and visibility matrix explains the separate ownership, approval, handover and private-feedback limits.
Pilot recovery
Section titled “Pilot recovery”Export company data is a user-controlled portability snapshot. It has no supported application import and is not a database or private-object restore. Service recovery is an operator-controlled Railway procedure, separate from the company ZIP.
Before a new pilot company enters records or files, the operator verifies scheduled PostgreSQL backups, a separate private copy of application files and a restore with synthetic data. Live and recovery resources remain within Railway. The pilot does not claim protection from a Railway-wide failure or loss of the Railway workspace owner account.
Product feedback is stored separately from company quotations and files. The collector database is backed up within Railway, but complete disaster recovery for optional feedback screenshots is not part of the current pilot gate. Do not attach customer information, prices, credentials or other sensitive material to product feedback.
AI-assisted scope
Section titled “AI-assisted scope”AI suggestions are optional, server-mediated and use the company’s configured OpenAI project. The result is an editorial draft that requires review. Quote Control does not treat it as technical approval or a compliance decision.
The integration credential is write-only in the application and encrypted at rest. Public pages and read APIs never return it.
Product feedback
Section titled “Product feedback”Quick feedback and Project research leave the company deployment through an authenticated, write-only server connection to a separate operator-owned collector. The collector derives the company from an instance credential and records the signed-in author and deployed release from server-owned metadata.
The company database retains only a content-free delivery receipt and audit event. It does not retain the feedback body or screenshot, and the company workspace has no read access to the central collector. Each user can see their own local Project-research draft and submitted summary; administrators cannot browse another user’s product feedback. Company exports also exclude Project research and product feedback.
Optional screenshots must be reviewed PNG or JPEG files no larger than 5 MB. They are normalised, stored privately by the collector and retained for up to 90 days. Submission limits are applied before screenshots are decoded, and the collector bounds concurrent image processing. JPEG remains JPEG and PNG remains PNG after normalization.
What this page does not claim
Section titled “What this page does not claim”Quote Control does not claim a certification, guaranteed uptime, regulatory compliance, SSO or a shared multi-tenant platform. Pilot companies should assess the workflow and data-processing position against their own obligations.