Legal
Security & Data Protection
Last updated: September 2026
QUORUM60 uses layered technical and organisational safeguards designed to protect customer information. This page describes protections that are actually in place; it avoids sensitive implementation detail.
Access & authentication
- Access requires an authenticated account, with support for multi-factor authentication.
- Sign-in uses secure, HttpOnly session cookies with cross-site-request-forgery protection on state-changing actions.
Isolation & access control
- Role-based access control separates customer and administrative surfaces.
- Your projects, documents and decisions are isolated to your account and are not visible to other customers.
Data handling
- Secrets and API credentials are held server-side and are never exposed to the browser, to other customers, or in reports.
- Uploaded documents are access-controlled; only content necessary to run a Council is used, and inputs are handled with prompt-injection safeguards.
- Security-relevant actions are recorded in an audit log.
- Decision and account records are retained and handled according to operational, security, legal and record-keeping requirements, with deletion requests handled where applicable.
Payments
Payments are processed by Stripe. We do not store full card details on our systems.
An honest principle
QUORUM60 uses layered technical and organisational safeguards designed to protect customer information. No internet-based service can guarantee absolute security.
QUORUM60 output is advisory. Please review with a qualified professional before acting.