Version 2026.09.03 · effective 2026-09-03
Security overview
How Quantifiable isolates firms and protects data in transit and at rest.
Acess Limited, trading as Quantifiable · company number 16890479 · 1a Pickford Road, Bexleyheath, England, DA7 4AT
Acess Limited, trading as Quantifiable runs Quantifiable as a multi-tenant service for RICS-regulated firms. Isolation is enforced in Postgres, not only in application filters.
Tenant isolation
Every tenant-scoped table has a tenant_id and a row-level security policy. Application queries run inside a transaction that sets the current tenant. A missing where-clause cannot leak another firm's rows. The tenant app and the client portal use two separate Clerk applications and never share a session.
Encryption
TLS in transit. Encryption at rest at Neon, Vercel Blob and Cloudflare R2. OAuth refresh tokens are stored with AES-256-GCM.
Access and audit
Workspace roles (owner, admin, member, viewer) gate writes. Security-significant events are written to an immutable audit log. Soft delete is the default; hard delete is reserved for the UK GDPR erasure pipeline after the grace period.
AI
Model calls are suggestions a human accepts. Linking prompts are price-free and do not include the firm or project name. Web research queries are checked for tenant identifiers before they leave the platform.
Questions: support@quantifiable.co.uk.