Loading

Quip Information Security Policy

Publiceringsdatum: Sep 11, 2026
Beskrivning

Quip's information security policy defines the organizational controls, technical safeguards, and operational practices that protect customer data and Quip's production systems. This article summarizes the key elements of the policy — suitable for use in vendor security questionnaires, compliance evaluations, or internal risk assessments when Quip is being considered or is in use as an enterprise platform.

Lösning

Security Policies

  • Two-factor authentication is required for all Quip employees for all system access
  • Personalized SSH keys are required for each employee for production server access — shared keys are not permitted
  • Production server access is restricted to engineers with a direct operational need (on-call engineers and the Production Root team)
  • All code and configuration changes are published to the engineering team and audited by the Production Root team before deployment
  • Firewall and network configurations are reviewed quarterly and on an ongoing basis
  • All network access to production servers is strictly limited to HTTP, HTTPS, and SSH ports

Laptop and Workstation Configuration Policy

  • Quip source code, production data, and configuration may only be stored on Quip-owned and managed computers
  • All employee laptops are encrypted using full-disk encryption
  • Automatic screen lock is required after a short idle period
  • Remote wipe capability is enabled on all Quip-managed devices
  • Employees must report lost or stolen devices to the security team immediately

Customer Data Handling

  • Customer data is encrypted at rest using AES-256 encryption
  • Customer data is encrypted in transit using TLS 1.2 or higher
  • Customer data is logically separated between tenants — one customer cannot access another customer's data
  • Quip employees do not access customer data except when required to resolve a support issue and with appropriate authorization
  • Customer data is never used for internal testing or development purposes

Note: Customers who require additional control over their encryption keys can purchase the Enterprise Key Management (EKM) add-on. See the Quip Enterprise Key Management Guide for details.

Vulnerability Disclosure

Quip has a responsible disclosure process for security vulnerabilities. If you discover a security issue with Quip, report it to the Quip security team through official Salesforce security disclosure channels. Quip commits to acknowledging receipt within 48 hours and working to resolve confirmed vulnerabilities within a reasonable timeframe based on severity.

Security Certifications and Audits

Quip maintains security certifications and undergoes periodic third-party security audits. For a complete list of current certifications and audit documentation, see the Trust and Compliance Documentation for Quip article.

Knowledge-artikelnummer

000388836

 
Laddar
Salesforce Help | Article