Qore Safety Logo
HomeSecurity & Trust
Security Overview

Built to Pass Your Security Review

Encryption, isolation, SSO, device revocation, and credential hashing — in one place. This is the page to send your security team.

Security Architecture

What Protects Your Data

Encryption at Rest on Every Device

Data captured in the field is encrypted on the device with AES-256, with keys held in the platform secure enclave — iOS Keychain and Android KeyStore.

Full Multi-Tenant Isolation

Built as secure multi-tenant SaaS from day one. Each customer's data is fully isolated — one customer's data is never visible to another.

Microsoft Entra ID SSO

Sign in with your existing Microsoft Entra ID (Azure AD) identity, alongside passwordless magic-link and email/password options.

Session & Device Control

Every session is tied to a device. Admins see all active devices and can revoke any of them instantly; deactivating a user signs them out automatically, everywhere.

Hashed Credentials & Tokens

Credentials and tokens are stored hashed — a database leak exposes no usable secrets.

Write-Once, Attributed Evidence

Every capture is write-once and stamped with who, what device, when, where, and which form version — a tamper-evident record for compliance and disputes.

Unblock Procurement

Put Us in Front of Your Security Team

We'll walk your IT and security reviewers through the architecture — identity, encryption, isolation, and device control — and answer the questionnaire items directly.

  • Microsoft Entra ID (Azure AD) SSO
  • AES-256 encryption at rest on devices
  • Instant device revocation

Get a Demo

See it on a populated demo environment that looks like a real, busy operation.

By submitting, you agree to Qore Safety's Privacy Policy. Your details are only used to contact you about your request.

Security FAQ

Straight answers for your IT and security reviewers.

We don't claim certifications we can't show you. The platform provides the security architecture described on this page — encryption at rest, tenant isolation, SSO, device revocation, hashed credentials — and the tooling to support your GDPR and audit obligations. Ask us for the current status of formal attestations for your review.

Revoke that device's access instantly from the admin portal. Data on the device is encrypted at rest with AES-256, and each session is tied to the specific device, so revocation is immediate and targeted.

A built-in PII erasure workflow anonymizes a person on request while preserving business-record integrity, supporting the "right to be forgotten." Tenant isolation and the attributed evidence trail support your broader accountability obligations. See our GDPR page for detail.

On Microsoft Azure — serverless functions, SQL, and blob storage — built cloud-native for scale and reliability. See Platform & Scale for more.