Trust // Security

Security Overview

This Security Overview describes, at a high level, the administrative, technical, and organizational safeguards Quiet Engine Pte. Ltd. ("Quiet Engine", "we", "us") uses to protect the Services and customer information. This page is provided for transparency and does not create contractual service levels or warranties.

§01

Security Principles

We design our Services with the following principles:

  • Least privilege: access to systems and data is limited to those who need it.
  • Data minimization: we avoid collecting and storing sensitive data where not necessary.
  • Defense in depth: layered safeguards across identity, application, network, and monitoring.
  • Secure-by-default integrations: permission-based connections and scoped access.
§02

Account Security and Access Controls

  • Authentication: access to the Platform is protected by secure authentication mechanisms.
  • Unique user access: each authorized user should have their own account credentials.
  • Role-based permissions: where supported, permissions are limited based on user roles.
  • Administrative access controls: administrative access is restricted to authorized personnel.
§03

Platform Security Monitoring

We use monitoring and logging to help detect and investigate suspicious activity and operational issues, such as abnormal sign-in behavior, API abuse, or unexpected error spikes.

§04

Data Protection Safeguards

  • Encryption in transit: data sent between your browser/app and our Services is protected using industry-standard encryption.
  • Controlled access: access to production data is restricted and monitored.
  • Segregation: we apply reasonable separation of environments and systems to reduce risk.
  • Backups and resilience: we maintain reasonable backup and recovery practices to support service continuity.
§05

Connected Accounts and Third-Party Integrations

Quiet Engine may allow customers to connect third-party services (such as email providers and professional networking platforms) through secure authorization mechanisms (e.g., OAuth) and/or authorized integration providers.

  • No credential storage: Quiet Engine does not collect or store third-party account passwords or login credentials.
  • No inbox hosting: Quiet Engine does not operate an email inbox or unified inbox and does not store full email message bodies as an inbox product.
  • Scoped permissions: access is limited to the permissions explicitly granted by the user and may be revoked at any time through the relevant third-party service.
§06

Third-Party Service Providers

We rely on reputable third-party service providers for infrastructure, analytics, integrations, and data services. We evaluate providers based on security and reliability considerations and use contractual protections where appropriate.

§07

Vulnerability Management

We maintain reasonable practices to identify and address security issues, which may include software updates, configuration reviews, and security testing appropriate for our stage.

§08

Incident Response

We maintain internal processes designed to identify, assess, and respond to security incidents. Where required by applicable law and depending on the circumstances, we may notify affected customers or individuals.

§09

Customer Responsibilities

Customers and users play a role in security:

  • Keep credentials confidential and use strong passwords.
  • Restrict access to authorized users only.
  • Promptly notify us of suspected unauthorized access or misuse.
§10

Contact

For security-related questions, please contact [email protected].