Version: v1.3 Streamlined
Operator: Bobby Built Ventures LLC d/b/a QuillCaddie
Applies to: All users, business customers, security researchers, workspace administrators, and procurement/security reviewers.
Quick summary
QuillCaddie treats captures, transcripts, audio, screenshots, AI outputs, connector data, and exports as sensitive. We use reasonable safeguards, avoid logging sensitive content, keep provider keys server-side, and welcome responsible vulnerability reports. We do not claim SOC 2, ISO, HIPAA, FedRAMP, or other certifications unless separately stated in writing.
1. Security commitments
QuillCaddie is designed around the following security commitments:
- workspace-scoped access controls;
- private storage for sensitive assets;
- signed upload/download URLs where appropriate;
- encryption in transit;
- protected provider keys and secrets;
- OAuth token protection and revocation support for integrations;
- row-level security or equivalent access boundaries for workspace data;
- audit logs for security-relevant workspace actions where available;
- raw audio deletion according to retention settings;
- no intentional logging of raw audio, raw transcripts, full AI outputs, signed URLs, provider keys, OAuth tokens, secrets, or sensitive provider payloads; and
- sanitized provider and integration errors.
No system is completely secure. Customers remain responsible for user access, device security, identity provider settings, browser storage, connector authorization, public links, exports, and internal policies.
2. Sensitive content boundaries
Sensitive content includes captures, raw audio, transcripts, source text, screenshots, images, files, links, prompts, AI outputs, product/project context, vocabulary, connector data, exports, provider errors that include snippets, signed URLs, OAuth tokens, API keys, and secrets.
Support personnel should not access sensitive content unless needed to provide support, investigate abuse, comply with law, or resolve a security issue, and where practical only with user/admin permission.
3. Vulnerability reporting
Please report suspected vulnerabilities to security@quillcaddie.com. Include:
- a description of the vulnerability;
- steps to reproduce;
- affected routes, APIs, domains, or features;
- impact assessment;
- screenshots or proof-of-concept details that avoid exposing other users’ data; and
- your contact information.
4. Safe harbor expectations
We welcome good-faith security research that:
- avoids accessing, modifying, deleting, exfiltrating, or disclosing other users’ data;
- avoids privacy violations, social engineering, spam, phishing, denial-of-service, malware, credential attacks, or physical attacks;
- stops testing and reports promptly if sensitive data is encountered;
- gives us reasonable time to investigate before public disclosure; and
- complies with applicable law.
5. Prohibited testing
Do not perform destructive tests, automated high-volume scans, credential stuffing, account takeover attempts, social engineering, phishing, malware, physical attacks, extortion, or attacks against third-party providers.
6. Our response
We may acknowledge reports, request more information, investigate, remediate, and notify affected users or authorities where required. We do not guarantee a bounty or reward unless a formal bounty program is announced.
7. Security incidents
If we confirm a security incident requiring notice, we will notify affected users or customers according to applicable law and any signed agreements. Incident communications may include the nature of the incident, affected data categories where known, mitigation steps, and recommended actions.
Contact
Support: support@quillcaddie.com
Privacy requests: privacy@quillcaddie.com
Security reports: security@quillcaddie.com
Legal notices: legal@quillcaddie.com
DMCA notices: dmca@quillcaddie.com
Mail: Bobby Built Ventures LLC d/b/a QuillCaddie, 1500 N Grand St, STE R, Denver, CO 80203