Trust
Protecting board material is the product, not a feature.
Board papers are among the most sensitive documents any organisation produces, and they are usually the least well protected. They sit in email attachments, in shared drives, in unencrypted PDFs on personal laptops. Quorums exists to replace that, so the standard we hold ourselves to is not “better than a folder.” It is a standard we can show you.
Below is what we do, how it is enforced, and how we test it. Where something is not in place, we say so.
Where your data lives
Your board documents and the intelligence extracted from them are stored and processed in the United Kingdom.
Quorums runs on managed PostgreSQL in London (AWS eu-west-2), with application processing pinned to London. Data is encrypted at rest using AES-256, including backups, with keys held in FIPS 140-2 compliant hardware security modules, and encrypted in transit using TLS.
Region is a contractual commitment, not a configuration preference. Our database provider is obliged to store and process data in the region we direct.
How your board is kept separate from every other
Every request that touches board content is checked against your membership of that board before anything is read. That check runs on every path in the system without exception: the archive, the Ask feature, document ingestion, exports, and the cross-board portfolio view.
Underneath it, the database enforces row-level security policies that no anonymous or unauthenticated connection can satisfy.
We maintain an automated test suite whose purpose is to attempt cross-board access on every one of those paths and assert that it fails. It runs at three layers: directly against the database, against each API route, and end to end through Ask, where it confirms that a question about one board cannot assemble material from another. The tests are themselves verified by deliberately inverting each guard and confirming the suite fails when it should.
We would rather describe a test than assert an impossibility. The honest position is that the risk of one customer’s material reaching another lies in a defect in our isolation layer, and the above is how we look for one.
How the AI handles your documents
Quorums uses Anthropic’s Claude API to extract structured intelligence from board documents and to answer questions about them. Three things follow from that, and the third is the one most vendors leave out.
Your content is never used to train models. This is a contractual prohibition in our agreement with Anthropic, not a setting we have chosen or a default that could change. Anthropic may not train on customer content.
The model holds no memory between requests. Each request is processed independently. There is no cross-customer knowledge store, and the model cannot be prompted to reveal another organisation’s board material because it holds no record of it.
Content is retained by our AI provider for 30 days. During that window it is accessible to Anthropic only for safety and security purposes, under a data processing agreement with confidentiality obligations, least-privilege access and audit logging. After 30 days it is deleted. We asked Anthropic for a zero-retention arrangement and were told it is available only to organisations meeting enterprise volume criteria. We will pursue it when we qualify. We would rather tell you the number than imply there isn’t one.
Anthropic Ireland Limited is our contracting entity, under a data processing agreement incorporating UK international transfer terms. Anthropic holds ISO 27001, ISO 42001 (the AI management systems standard), SOC 2 Type 2 and CSA STAR certifications, and UK Cyber Essentials.
Who else processes your data
We use four sub-processors and no more:
| Provider | What it handles | Where |
|---|---|---|
| Anthropic | Document extraction and Ask | Ireland (contracting), under UK transfer terms |
| Supabase | Database and file storage | London, UK (AWS eu-west-2) |
| Vercel | Application hosting | London, UK |
| Clerk | Authentication and identity | United States, under approved transfer terms |
Only Anthropic and Supabase handle board documents. Authentication involves a US provider under approved international transfer mechanisms, and it holds no board content.
Quorums sends no transactional email of its own. The only email associated with the service is sign-in and verification mail from our authentication provider, which carries the recipient’s address and nothing else. No board name, session title or document content can leave the system by email, because no such path exists.
Each of our providers uses sub-processors of its own. We publish ours and link to theirs rather than attempting to enumerate every party in the chain, because a list we cannot keep accurate is worse than one we can. We subscribe to change notifications from our providers and will tell you of material changes to this list.
Retention, export and deletion
Your data is retained for as long as your subscription runs. You can export it at any time in a machine-readable format.
On account closure, board data is deleted within 30 days. That figure is not arbitrary: it matches the deletion commitments we hold from both our AI provider and our database provider, so the whole chain resolves on the same timetable.
What Quorums does not do
Some of these are technical limits. Some are choices. All of them are deliberate.
Quorums does not take your minutes. It reads what has already been recorded. It is not present in the meeting, it does not listen, and it does not produce the record.
Quorums does not produce the statutory record. Your minutes remain your minutes. Nothing Quorums generates is a company record, and nothing it produces should be filed as one.
Quorums does not assess individuals. It does not score directors, rank contributions, or build profiles of people. It tracks commitments and decisions, not the people who made them.
Quorums does not set the agenda or reach conclusions. It surfaces what the record contains. Judgement stays in the room.
Quorums is not a window for investors. Access is controlled by the board, not granted by us.
We do not hold enterprise certifications of our own. We rely on our providers’ independently audited compliance programmes, and we can provide their reports on request. We are a small company and we would rather tell you that than imply otherwise.
Ask us anything
If you are evaluating Quorums on behalf of a board and need detail beyond this page, including our sub-processor terms, our providers’ audit reports, or a completed security questionnaire, ask. We will answer specifically.
Ask us about data handling