Is this your company?Buyers are checking Quickbase Inc here. Claim quickbase.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Quickbase is a powerful application platform designed for dynamic work. We make the complex simple by helping companies to see, connect, and control their projects. With Quickbase, you can empower your entire workforce to help drive your business forward by enabling problem solvers of any technical background to create custom applications. All while giving your IT team the visibility and control they need to ensure that you're following proper regulations and corporate policies.
Quickbase has published our Responsible AI White Paper, outlining our approach to building and managing AI responsibly. You can find the paper on the Resources tab of the Trust Center.
Quickbase issues SOC1 and SOC2 reportsOct 2025
Quickbase has received our most recent SOC 1 and SOC 2 Type II reports for the Quickbase platform. You can access these reports on the Resources tab of our Trust Center. At Quickbase, keeping customer and stakeholder data secure is our top priority. To validate that our systems and controls are designed and operating effectively, we engage an independent, third-party auditing firm to perform annual examinations. These reports reflect the results of that assessment.
Quickbase issues SOC1, SOC2 and SOC3 reportsAug 2024
Quickbase recently received our latest SOC1/SOC2 - Type II and SOC3 reports for the Quickbase platform. Quickbase's Project Services also received a SOC2 - Type I report. These reports can be found on the Resources tab of the Trust Center. At Quickbase, keeping customer and stakeholder data secure is our top priority. To ensure that our systems and controls have been designed appropriately to achieve that goal, we sought out third-party attestation from a qualified auditing firm. These reports are the result of their examination.
Quickbase assessment of Polyfill[.]io vulnerabilityJun 2024
Quickbase is aware of the recent supply chain attack affecting Polyfill[.]io, which has impacted over 110,000 websites. Our security team has conducted a thorough review using Software Composition Analysis (SCA) and other assessments, finding that this vulnerability impacts no dependencies in our products. We continue to monitor the situation and will reassess as new information comes to light.
In light of the recent security incident reported by Snowflake, we have taken several measures to ensure the continued safety of your data: · Indicators of Compromise: After reviewing the IOCs provided by Snowflake, we confirm there have been no matches found within our systems. · Best Practices: We have reviewed Snowflake’s recommended security practices and have confirmed that we have implemented those that align with our security framework. · Credential Management: As a precaution, we are rotating all credentials associated with our use of Snowflake. · Continuous Monitoring: We are actively working with our MSSP to monitor for any suspicious activity and have not been identified by Snowflake as an impacted entity. We are also in constant dialogue with external cybersecurity experts to adapt our response as more information becomes available. We are committed to maintaining the highest standard of data security and will keep you informed of any developments impacting Quickbase.
This listing is partial
5/11 details · 45%
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Quickbase Inc SOC 2 compliant?
Quickbase Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Quickbase Inc HIPAA compliant?
According to Quickbase Inc's public trust center, Quickbase Inc is HIPAA compliant. On SOC2C this listing is Listed.
Is Quickbase Inc CSA STAR certified?
According to Quickbase Inc's public trust center, Quickbase Inc is CSA STAR certified. On SOC2C this listing is Listed.
Is Quickbase Inc GDPR compliant?
According to Quickbase Inc's public trust center, Quickbase Inc is GDPR compliant. On SOC2C this listing is Listed.
Is Quickbase Inc SOC 2 Type I or Type II?
Quickbase Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Quickbase Inc's SOC 2 for a vendor risk assessment?
Yes. Quickbase Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Quickbase Inc penetration tested?
Quickbase Inc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Does Quickbase Inc have a SOC 3 report?
Quickbase Inc publishes a SOC 3 report, which is publicly shareable. Request access through SOC2C.
Can I get Quickbase Inc's SOC 2 report?
Quickbase Inc's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Quickbase Inc secure?
Security isn't a single yes/no, but Quickbase Inc is SOC 2 Type II compliant and holds SOC 2 Type II, HIPAA, CSA STAR, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Quickbase Inc have a bug bounty or vulnerability disclosure program?
Quickbase Inc hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@quickbase.com or via a /security page (Quickbase Inc lists a security contact).
Who are Quickbase Inc's subprocessors?
Quickbase Inc's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Quickbase Inc host or store data?
Quickbase Inc's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Quickbase Inc's trust center or security page?
Quickbase Inc's trust center is at https://trust.quickbase.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What is the Shared Responsibility Model?
Quickbase is committed to maintaining best-in-class security; however, security and privacy are a shared responsibility. Quickbase provides a secure Platform-as-a-Service (PaaS), and further provides the tools, support and training resources to enable our customers to build and maintain secure apps. Customers also have responsibilities around the security of Quickbase apps and the data held within them. Customers must understand what data they intend to collect and store in their Quickbase apps, and ensure that legal, security and compliance requirements are addressed accordingly. Customers must ensure that security is addressed in the development, implementation and maintenance of Quickbase apps, including but not limited to ensuring that apps are shared with only those who are authorized to access them. This “Shared Responsibility Model” empowers Quickbase customers to maintain greater control of their data, which in return limits the actions Quickbase might be able to take on their behalf.
How is customer data segregated?
Quickbase is a multi-tenant application PaaS with logical access segregating each customer’s data. Quickbase customers control logical access to their data via authentication and authorization at the Realm, Account and Application layer. Realms, otherwise thought of as a sub-domain, hold customer Accounts. Applications exist within each Account, and are developed, implemented and maintained by the customer. Customers further manage access and permissions at the Realm, Account and Application layer.
How is data access controlled?
Customers provision and manage access to their Quickbase apps. Quickbase supports single sign on and user provisioning/de-provisioning via Security Assertion Markup Language (SAML). Groups can also be used to provision role-based access at the app, form or field layer. Quickbase staff do not access customer apps and the data therein unless invited into the app by the customer. Quickbase developers occasionally require read-only access to systems which hold metadata, scripts and app schema in order to troubleshoot. A small team of operations personnel have administrative access to the infrastructure which hosts the Quickbase platform. All Quickbase personnel are bound by NDAs and acceptable use policies prohibiting unauthorized access and disclosure of customer data.
Do you encrypt data in transit and at rest?
Quickbase encrypts customer data in motion and at rest. All communications over non-trusted Internet networks are encrypted at up to 256 bit (SHA2) TLS certificate, TLS 1.2 and 1.3. Quickbase encrypts all customer app data and any files attached therein using an AES 256 key. For advanced data encryption needs, Quickbase supports the ability for customers to encrypt data at rest using their own encryption key, rotated on their own schedule. Realm-specific encryption keys provide an additional means to ensure the privacy and confidentiality of customer data. To set up realm-specific encryption keys for your organization, please open a support case.
Do you perform audit logging?
Extensive logging of all aspects of the Quickbase platform are ingested in near real-time into a log management system and SIEM. This supports analysis, alerting and reporting, as well as investigation capabilities for Quickbase’s operations, engineering and security teams supporting the platform. Operational logs are retained for six months. Quickbase also provides audit logs as an optional feature for customers. Application audit logs are available on Team, Business and Enterprise plans and provide Quickbase realm administrators a view of their Quickbase realm user activity, data and schema changes to their apps. Customers may choose to retain audit log data for six months, one, three or seven years.
Is vulnerability scanning and penetration testing performed?
###### Penetration Testing At least annually, Quickbase engages an independent penetration testing firm to perform a time-bound security assessment of the Quickbase platform, internet-facing systems, applicable infrastructure, and supporting policy and procedure documentation. This penetration testing firm is given application design diagrams, source code, threat models, and full administrative privileges within multiple tenants created specifically for the test. These resources give the firm the greatest advantage in identifying possible weaknesses in the Quickbase platform. This type of penetration testing is known as white-box methodology and is inclusive of testing against the OWASP Top Ten. ###### Vulnerability Scanning — Quickbase Quickbase employs a variety of tools and processes to detect, protect and respond to security vulnerabilities. This includes, but is not limited to, regular web application security scans and infrastructure scans. More details on these processes are available to current or prospective customers under obligations of confidentiality. ###### Vulnerability Scanning — Quickbase Customers Customers may run a security scan against their Quickbase realm under the following conditions. - Customers can only test using their own Quickbase application(s) with up to three (3) applications accessed during the testing. - The methodology for the test should mimic normal user activities with both normal pace and normal user volume. - This should not be a performance test or a denial-of-service test. - Customers should conduct the test during non-business hours to minimize the chance of negatively impacting their own users. Customers must open a support case with Quickbase Customer Care to test up to three apps at least five business days prior to the security scan. The following details must be provided. - The application URL(s) against which the test will be conducted. - The source IP address from which the test will be conducted. - The date and…
What is your SLA history?
Quickbase is a high reliability and availability platform. The history of our system status and availability is publicly available here.
What is your RTO and RPO?
Each component of the infrastructure which powers Quickbase — from network equipment to web, app and database servers — is highly available and redundant. If something were to drastically impact our production services, our DR capabilities are best in class. Quickbase maintains 2 geographically diverse, production-ready data centers for all core infrastructure components. Production data is replicated to the warm standby data center with up to a 15 minute delay, i.e., a recovery point objective (RPO) of 15 minutes. If an issue were to impact the production site, we only need 2 hours to bring up production at the DR site, i.e., a recovery time objective (RTO) of 2 hours. We periodically (2-4 times per year) switch between the two data centers as part of our normal disaster recovery plan validation process. Switching between data centers allows us to ensure that Quickbase’s disaster recovery plan is tested and working properly should there ever be a real disaster. Further information about our platform architecture can be found in our Platform Evaluation Guide.
Where is the Quickbase US platform hosted?
The production US Instance of the Quickbase platform (“Quickbase US”) is currently built on top of two cloud hosting providers: Amazon Web Services (AWS), and Google Cloud Platform (GCP). All platform functionality except Pipelines runs in AWS. Pipelines runs in GCP. The primary platform services running in AWS are referred to as the “Core Cluster Components” and include the Quickbase Runtime Engine and proprietary in-memory database, as well as Application Data, Application Schema, Realms, Accounts, and Users. If interested, you can read more about the Core Cluster Components in the Quickbase Platform Evaluation Guide. To ensure the availability of Quickbase US in AWS and GCP, Quickbase relies on the use of Availability Zones (AZs) for high availability. AZs utilize multiple data centers typically located within 60 miles of each other to provide protection against localized or data center specific service interruptions. Failover between AZs is exercised regularly and is typically invisible to customers. The Quickbase platform is composed of multiple software services and databases. Depending on the service or database, exercising of AZ failover occurs daily, weekly, or monthly. Quickbase US uses AZs in the AWS US-West-2 ("AWS-Oregon") region and the GCP US-Central-1 (“GCP-Iowa”) region. To further ensure the availability of the Core Cluster Components of Quickbase US in AWS, Quickbase uses two geographically diverse locations: AWS US-West-2 ("AWS-Oregon") and AWS US-East-2 ("AWS-Ohio"). The Quickbase platform Core Cluster Components can run actively in only one location at a time with the other location running in standby mode. Both locations are always identical so there is no difference in Quickbase function or performance. We periodically switch between the two AWS locations as part of our normal disaster recovery plan validation process. Switching between AWS locations allows us to ensure that Quickbase’s disaster recovery plan is tested and working properly…
Where is the Quickbase EU platform hosted?
The production EU Instance of the Quickbase platform (“Quickbase EU”) is currently built on top of two cloud hosting providers: Amazon Web Services (AWS), and Google Cloud Platform (GCP). All platform functionality except pipelines runs in AWS. Pipelines run in GCP. The primary platform services running in AWS are referred to as the “Core Cluster Components” and include the Quickbase Runtime Engine and proprietary in-memory database, as well as Application Data, Application Schema, Realms, Accounts, and Users. If interested, you can read more about the Core Cluster Components in the Quickbase Platform Evaluation Guide. To ensure the availability of Quickbase EU in AWS and GCP, Quickbase relies on the use of Availability Zones (AZ's) for high availability. AZ's utilize multiple data centers typically located within 60 miles of each other to provide protection against localized or data center specific service interruptions. Failover between AZs is exercised regularly and is typically invisible to customers. The Quickbase platform is composed of multiple software services and databases. Depending on the service or database, exercising of AZ failover occurs daily, weekly, or monthly. Quickbase EU uses AZs in the AWS EU\-Central-1 (“AWS Frankfurt-Germany”) and the GCP Europe-West-1 (“GCP St. Ghislain-Belgium”) region. To further ensure the availability of the Core Cluster Components of Quickbase EU in AWS, Quickbase uses two geographically diverse locations: AWS EU-Central-1 ("AWS-Germany") and AWS EU-West-1 ("AWS-Ireland"). The Quickbase platform Core Cluster Components can run actively in only one location at a time with the other location running in standby mode. Both locations are always identical so there is no difference in Quickbase function or performance. We periodically switch between the two AWS locations as part of our normal disaster recovery plan validation process. Switching between AWS locations allows us to ensure that Quickbase’s disaster recovery plan…
How do you protect, detect and respond to security incidents?
Quickbase employs tools and process which monitor the platform, network, server and service components which make up the Quickbase services, and has a dedicated security team and incident response processes. Quickbase commits to notifying affected customers of any suspected or confirmed unauthorized access to information via e-mail or phone. ##### Monitoring Quickbase’s operations team employs automated incident detection, escalation technologies and procedures which ensure that any infrastructure or sub-service provider issue is rapidly addressed, 24/7/365. Customers may view and subscribe to service status updates here.
How often do you perform backups, and what is your retention schedule?
Quickbase data is continuously replicated from the production to the warm standby data center. In each data center, Quickbase app and file attachment data is backed up via a daily snapshot from online storage to alternate online storage within the same data center. Quickbase maintains 14 daily snapshots and 6 months of weekly snapshots. This same procedure is done in the disaster recovery data center. The backup data is encrypted by virtue of the fact that the data is encrypted at the application layer. Removable backup media is not used, hence there is no physical transportation of media. Additionally customers may download their Quickbase application data at any time. For more information consult our help article on backups.