Built to be handed your customers' data.
Governance isn't a setting you switch on — it runs through every query, every share, and every scheduled send.
Encrypted & authenticated
Connection credentials sealed at rest; role-based login with revocable sessions; HTTPS, secure cookies, security headers, and login rate-limiting.
Row-level security that fails closed
Each viewer sees only the rows they're entitled to, enforced server-side inside the query. If a policy can't resolve, it shows nothing rather than leaking.
Governed AI
The assistant reads only approved data through a guarded query layer with a read-only allow-list. It can't run arbitrary commands or reach beyond what you permit.
We never train on your data
Your data is used only to answer your questions. Neither Qeries nor its model providers train models on your data, and it is never shared across organizations.
Access control that holds
Grant access by person or group at the dashboard, folder, or data-source level, with a clear deny-wins model and request-and-approve sharing. No "anyone with the link".
Isolated by organization
Every client is a separate workspace with its own users, data, connections and dashboards. Cross-workspace access is denied by default and enforced on the server, not in the browser — so a reader who goes around the interface gets the same answer.
Hosted in the EU · data residency
Your data stays in-region, hosted in the EU by default. Dedicated instances, in-country hosting, or deployment in your own cloud are available for regulated clients.
Audit & cost control
Logins, permission changes, shares, and scheduled sends are recorded per workspace, and AI usage is rate-limited with a hard spend ceiling.
Straight about where we are.
We're in private preview and won't claim certifications we don't yet hold. Here's the honest state — and where we're headed.
GDPR-aligned, EU-hosted
Data is hosted in the EU by default and handled in line with GDPR principles — data minimisation, purpose limitation, and your right to deletion.
SOC 2 readiness in progress
We're building toward SOC 2 and will publish our status transparently. In the meantime we're glad to walk security teams through our controls.
Self-hosted & your-cloud deployment
Regulated clients can run Qeries as a dedicated instance in a chosen region, or inside their own cloud account, for full control of data residency.
Shared infrastructure, bounded
Workspaces are isolated in data and access, not in compute — today they share processing, with a hard memory ceiling per query so no workspace can exhaust the platform. Dedicated instances and deployment in your own cloud are available where separation must be physical.
SSO / SAML on the roadmap
Single sign-on and SCIM provisioning are on the roadmap for enterprise identity. Role-based access and revocable sessions are available today.