SOC2C

Is this your company? Buyers are checking Quickbase Inc here. Claim quickbase.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Quickbase Inc logo

Quickbase Inc

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Quickbase Inc is SOC 2 Type II compliant. Quickbase Inc also holds HIPAA, CSA STAR, and GDPR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Quickbase is a powerful application platform designed for dynamic work. We make the complex simple by helping companies to see, connect, and control their projects. With Quickbase, you can empower your entire workforce to help drive your business forward by enabling problem solvers of any technical background to create custom applications. All while giving your IT team the visibility and control they need to ensure that you're following proper regulations and corporate policies.

Compliance & infrastructure

Documents

25

Compliance leadership

The person who leads Quickbase Inc's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Quickbase Inc's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Responsible AI white paperOct 2025

Quickbase has published our Responsible AI White Paper, outlining our approach to building and managing AI responsibly. You can find the paper on the Resources tab of the Trust Center.

Quickbase issues SOC1 and SOC2 reportsOct 2025

Quickbase has received our most recent SOC 1 and SOC 2 Type II reports for the Quickbase platform. You can access these reports on the Resources tab of our Trust Center. At Quickbase, keeping customer and stakeholder data secure is our top priority. To validate that our systems and controls are designed and operating effectively, we engage an independent, third-party auditing firm to perform annual examinations. These reports reflect the results of that assessment.

Quickbase issues SOC1, SOC2 and SOC3 reportsAug 2024

Quickbase recently received our latest SOC1/SOC2 - Type II and SOC3 reports for the Quickbase platform. Quickbase's Project Services also received a SOC2 - Type I report. These reports can be found on the Resources tab of the Trust Center. At Quickbase, keeping customer and stakeholder data secure is our top priority. To ensure that our systems and controls have been designed appropriately to achieve that goal, we sought out third-party attestation from a qualified auditing firm. These reports are the result of their examination.

Quickbase assessment of Polyfill[.]io vulnerabilityJun 2024

Quickbase is aware of the recent supply chain attack affecting Polyfill[.]io, which has impacted over 110,000 websites. Our security team has conducted a thorough review using Software Composition Analysis (SCA) and other assessments, finding that this vulnerability impacts no dependencies in our products. We continue to monitor the situation and will reassess as new information comes to light.

Quickbase Closely Monitoring & Assessing Snowflake AttacksJun 2024

In light of the recent security incident reported by Snowflake, we have taken several measures to ensure the continued safety of your data: · Indicators of Compromise: After reviewing the IOCs provided by Snowflake, we confirm there have been no matches found within our systems. · Best Practices: We have reviewed Snowflake’s recommended security practices and have confirmed that we have implemented those that align with our security framework. · Credential Management: As a precaution, we are rotating all credentials associated with our use of Snowflake. · Continuous Monitoring: We are actively working with our MSSP to monitor for any suspicious activity and have not been identified by Snowflake as an impacted entity. We are also in constant dialogue with external cybersecurity experts to adapt our response as more information becomes available. We are committed to maintaining the highest standard of data security and will keep you informed of any developments impacting Quickbase.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Quickbase Inc SOC 2 compliant?
Quickbase Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Quickbase Inc HIPAA compliant?
According to Quickbase Inc's public trust center, Quickbase Inc is HIPAA compliant. On SOC2C this listing is Listed.
Is Quickbase Inc CSA STAR certified?
According to Quickbase Inc's public trust center, Quickbase Inc is CSA STAR certified. On SOC2C this listing is Listed.
Is Quickbase Inc GDPR compliant?
According to Quickbase Inc's public trust center, Quickbase Inc is GDPR compliant. On SOC2C this listing is Listed.
Is Quickbase Inc SOC 2 Type I or Type II?
Quickbase Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Quickbase Inc

Reproduced from Quickbase Inc's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What is the Shared Responsibility Model?
Quickbase is committed to maintaining best-in-class security; however, security and privacy are a shared responsibility. Quickbase provides a secure Platform-as-a-Service (PaaS), and further provides the tools, support and training resources to enable our customers to build and maintain secure apps. Customers also have responsibilities around the security of Quickbase apps and the data held within them. Customers must understand what data they intend to collect and store in their Quickbase apps, and ensure that legal, security and compliance requirements are addressed accordingly. Customers must ensure that security is addressed in the development, implementation and maintenance of Quickbase apps, including but not limited to ensuring that apps are shared with only those who are authorized to access them. This “Shared Responsibility Model” empowers Quickbase customers to maintain greater control of their data, which in return limits the actions Quickbase might be able to take on their behalf.
How is customer data segregated?
Quickbase is a multi-tenant application PaaS with logical access segregating each customer’s data. Quickbase customers control logical access to their data via authentication and authorization at the Realm, Account and Application layer. Realms, otherwise thought of as a sub-domain, hold customer Accounts. Applications exist within each Account, and are developed, implemented and maintained by the customer. Customers further manage access and permissions at the Realm, Account and Application layer.
How is data access controlled?
Customers provision and manage access to their Quickbase apps. Quickbase supports single sign on and user provisioning/de-provisioning via Security Assertion Markup Language (SAML). Groups can also be used to provision role-based access at the app, form or field layer. Quickbase staff do not access customer apps and the data therein unless invited into the app by the customer. Quickbase developers occasionally require read-only access to systems which hold metadata, scripts and app schema in order to troubleshoot. A small team of operations personnel have administrative access to the infrastructure which hosts the Quickbase platform. All Quickbase personnel are bound by NDAs and acceptable use policies prohibiting unauthorized access and disclosure of customer data.
Do you encrypt data in transit and at rest?
Quickbase encrypts customer data in motion and at rest. All communications over non-trusted Internet networks are encrypted at up to 256 bit (SHA2) TLS certificate, TLS 1.2 and 1.3. Quickbase encrypts all customer app data and any files attached therein using an AES 256 key. For advanced data encryption needs, Quickbase supports the ability for customers to encrypt data at rest using their own encryption key, rotated on their own schedule. Realm-specific encryption keys provide an additional means to ensure the privacy and confidentiality of customer data. To set up realm-specific encryption keys for your organization, please open a support case.
Do you perform audit logging?
Extensive logging of all aspects of the Quickbase platform are ingested in near real-time into a log management system and SIEM. This supports analysis, alerting and reporting, as well as investigation capabilities for Quickbase’s operations, engineering and security teams supporting the platform. Operational logs are retained for six months. Quickbase also provides audit logs as an optional feature for customers. Application audit logs are available on Team, Business and Enterprise plans and provide Quickbase realm administrators a view of their Quickbase realm user activity, data and schema changes to their apps. Customers may choose to retain audit log data for six months, one, three or seven years.

Business & Industrial peers that completed SOC 2