Security at Quill

Last updated: August 29, 2026
Short version: We store as little as possible, encrypt everything in transit, hash everything sensitive at rest, rate-limit every endpoint, and let Stripe handle every card number. Found a hole? Email us, subject SECURITY.

1. Architecture: less to breach

Quill's security posture starts with storing less. Drafts, profile details, and send history live in your browser, not on our servers. The server-side footprint is limited to account records, hashed credentials, hashed verification codes, waitlist emails, and usage counters.

2. Transport and headers

3. Authentication

4. API protections

5. Payments

All payment processing is handled by Stripe, a PCI-DSS Level 1 provider. Card data never touches Quill infrastructure. Webhook signatures are verified server-side.

6. Reporting a vulnerability

If you find a security issue, email hello@quill.ink with the subject "SECURITY". Please give us a reasonable window to fix the issue before public disclosure, do not access other users' data, and do not run disruptive automated scans. We are grateful to good-faith researchers and will credit fixes if you want the shout-out.

HomeAboutPrivacyTermsEULAAcceptable useSecurityContact© 2026 Quill, Inc.