Qwilr trust and security

Security, privacy and compliance

We empower over 5,000 organisations around the world to win more business. Learn how Qwilr protects customer data, manages access, tests its platform and supports security and compliance reviews.

Qwilr security at a glance

Last reviewed by Qwilr Security: 10 September 2026

SOC 2 Type 2

Qwilr completes an audit each year.

Data location

Customer data is stored and processed in Sydney, Australia.

Encryption

Customer data is encrypted in transit and at rest.

Account access

OAuth SSO is available on all plans and SAML SSO is available on Scale.

Penetration testing

Testing takes place annually and after significant platform changes.

Data retention

Customer data is deleted within 30 days after cancellation.

AI model training

Customer content and personal data are not used to train AI models.

Incident notification

Qwilr contacts administrators of accounts suspected of being involved in an incident.

Secure

Security operations and industry best practices

We protect your data with encryption in transit and at rest and provide enhanced security features such as SSO and role-based permissions. We provide SSO, email verification and password support for limiting buyer page access.

We follow industry best practices for security in our operations, with strict policies and controls for production-system access, proactive monitoring and infrastructure maintenance, and a commitment to rapid incident response and resolution

Data security

Security testing

Penetration tests take place annually and when significant platform changes are introduced.

Vulnerability monitoring

Qwilr continuously monitors for new vulnerabilities and maintains a Vulnerability Disclosure Program.

Account access

OAuth SSO is available on all plans. SAML SSO is available on Scale, and Qwilr honours MFA set by the identity provider.

Reliant

Performance and reliability

Qwilr is designed for performance and availability using infrastructure such as AWS.

We have standard data backup and retention practices. We actively monitor system availability and publicly share our system status.

View system status
Qwilr system status
Compliant

Quality and compliance

Qwilr is PCI-DSS compliant and has successfully completed a SOC 2 Type 2 audit.

We have controls in place for quality, security and data management, and seek excellence in practice with our engineering and operations.

We openly respond to questions from customers regarding our security and operational practices.

Visit the Qwilr Trust Dashboard
Security compliance
Private

Data handled with care

We are committed to protecting the privacy of your data and your customers’ data.

We seek to segregate data of different classes wherever possible, and our team only accesses identifiable data to troubleshoot particular issues in communication with you, our customer.

At all times we process your data with care and respect so you can use Qwilr with confidence.

View privacy policy
Data privacy

Certifications and compliance

Review Qwilr’s security audits, compliance standards and supporting reports to understand how your data is protected.

SOC2 certification badge

SOC 2

Qwilr completes a SOC 2 Type 2 audit each year, with ongoing automated monitoring of controls, policies and infrastructure powered by Drata.

PCI-DSS certification badge

PCI-DSS

Qwilr uses Stripe to process payments. Stripe has been audited by a PCI-certified auditor and is certified to PCI Service Provider Level 1.

GDPR compliance

GDPR

Qwilr is compliant with GDPR requirements. We have established and closely follow internal controls and policies that address the requirements of that regulation insofar as they apply to Qwilr.

Legally binding e-signatures

Qwilr esignatures are a secure way to get deals signed and closed, ensuring your customers have a secure way to sign and pay in one place. Our esignatures meet global laws for enforceability and security.

UETA

Qwilr is compliant with UETA requirements. Users in more than 50 countries trust Qwilr to sign contracts, legal documents, MSA’s and more.

eIDAS compliance

eIDAS

Qwilr is compliant with the requirements for Electronic Signatures. Users in more than 50 countries trust Qwilr to sign contracts, legal documents, MSA’s and more.

E-SIGN

Qwilr is compliant with the E-SIGN Act requirements. Users in more than 50 countries trust Qwilr to sign contracts, legal documents, MSA’s and more.

Security and compliance FAQs

Qwilr and the LLM models we use do not use customer content or personal data to train AI models.

Qwilr supports SSO through Oauth providers, including Google Workspace and Microsoft, as well as Hubspot and Salesforce CRM SSO for all subscription levels.

SAML SSO is supported for customers with a Scale subscription by contacting customer support. SAML does not support SCIM provisioning at this time.

Qwilr honors the MFA configuration as configured by a customer’s SSO Identity Provider.

All customer data is deleted within 30 days of a subscription being cancelled.

Qwilr undertakes annual penetration tests as well as when significant changes to the Platform are being introduced. Additionally Qwilr has a vulnerability management program that continuously monitors for new vulnerabilities as well as a Vulnerability Disclosure Program that allows security researchers to test for and submit any vulnerabilities they find.

Qwilr maintains incident-response controls and continuously monitors its infrastructure and security posture. Qwilr will contact the Admins of any accounts that are suspected or involved in a data breach or security incident. Additional information on any system outages can be found at https://status.qwilr.com.

Yes. Qwilr can provide a Data Processing Addendum to support customers with their GDPR obligations by contacting support. Qwilr stores and processes customer data in Sydney, Australia.

Qwilr undertakes an annual SOC 2 Type 2 Audit, a copy of the report can be found on the Qwilr Trust Dashboard. Qwilr meets the requirements for global e-signing programs including E-SIGN, UETA and eIDAS.