Security at Quill
1. Architecture: less to breach
Quill's security posture starts with storing less. Drafts, profile details, and send history live in your browser, not on our servers. The server-side footprint is limited to account records, hashed credentials, hashed verification codes, waitlist emails, and usage counters.
2. Transport and headers
- HTTPS everywhere, with HTTP Strict Transport Security (HSTS) including subdomains.
- A strict Content Security Policy restricting scripts, connections, frames, and form targets to an explicit allowlist.
- X-Content-Type-Options: nosniff, frame-ancestors denied (no clickjacking), restrictive Permissions-Policy.
3. Authentication
- Passwords are salted and hashed; we never store or log plaintext passwords.
- Email verification uses cryptographically random (CSPRNG) codes, stored hashed, with expiry and attempt limits.
- Google Sign-In is available via Google Identity Services; we receive only your basic profile, never mailbox access.
4. API protections
- All serverless endpoints enforce rate limiting.
- The AI generation endpoint proxies Anthropic's API so the API key never reaches the browser.
- Database access from the client goes through row-level-security-scoped, least-privilege paths; sensitive counts are exposed only via security-definer functions that return integers, not rows.
5. Payments
All payment processing is handled by Stripe, a PCI-DSS Level 1 provider. Card data never touches Quill infrastructure. Webhook signatures are verified server-side.
6. Reporting a vulnerability
If you find a security issue, email hello@quill.ink with the subject "SECURITY". Please give us a reasonable window to fix the issue before public disclosure, do not access other users' data, and do not run disruptive automated scans. We are grateful to good-faith researchers and will credit fixes if you want the shout-out.