How Quorum protects your files

A plain-language tour of the security around your documents: workspace isolation, encryption at rest, audited access for automated services, and offboarding guarantees.

Last updated 29 July 2026

How Quorum protects your files

Your documents power your briefings, so protecting them is the foundation of everything Quorum does. Here is what stands between your files and anyone who should not see them, in plain language.

Your workspace is an island

Every file belongs to exactly one workspace. Every request to read, change or delete a file is checked against the workspace of the signed-in user, and files are stored under workspace-specific paths, so even software bugs cannot reach across workspaces. Attempted cross-workspace access is refused and logged as a security signal.

Encryption at rest

File content is encrypted at rest with AES-256. Each workspace has its own encryption keys, and each file is sealed with its own individual key on top of that. One workspace's keys never protect another workspace's data. Extracted document text used for search is encrypted the same way.

Because Quorum reads your documents server-side to build search indexes and briefings, this is not end-to-end encryption, and we are careful to say so. What it does mean is that stored file content is unreadable without the keys, which are managed separately from the storage itself.

People sign in, services need permission

People in your workspace access files with their own signed-in account. Quorum's automated services, such as the briefing pipeline, are held to a stricter standard: they read file content in connection with work a person initiated, under a short-lived permission scoped to exactly the files involved.

Every such access is written to your workspace's security audit trail, which we retain and can provide to workspace admins on request rather than as a page in the dashboard. The trail records what was read, which automated service read it, and which user's action authorised it, and it is kept for 180 days.

Downloads are short-lived by design

Download links expire after about 15 minutes so a leaked link cannot be replayed later. For workspaces with enhanced encryption, downloads flow through Quorum's own secure endpoint that decrypts for the authorised recipient only.

When you leave

Offboarding supports a clean exit. After your data is exported, the workspace's encryption keys are destroyed, which makes all stored content permanently unreadable, including anything lingering in backups. This is deliberate and irreversible, and it is the strongest deletion guarantee available.

Questions we are often asked

Can other Quorum customers ever see our files? No. Workspace isolation is enforced on every operation and in the storage layout itself.

Can Quorum staff read our documents? The platform is designed so that automated access is scoped, logged and reviewable in your audit trail. Ask us about our operational access controls if your compliance review needs detail beyond this article.

Do you support customer-managed keys? Workspaces on our enterprise tier can hold encryption root keys in their own key-management account. Talk to your account contact about the BYOK option.

Still need help?

Ask Quincy in the chat bubble below, or write to support@quorumtech.ch and we will help you directly.