🔒 Connect agent · choose what it can do
Read metrics
Inspect ticket details
Create AI classifiers
Access conversations Off

Security that's tested on every commit

SAML SSO, enforceable two-factor authentication, granular permissions, and multi-tenant isolation that our CI verifies continuously, not once a year.

Visit our live trust center at trust.qvasa.com for current compliance reports and controls.

How Qvasa protects your support data

  • SAML 2.0 SSO with any IdP
  • Force-SAML & JIT provisioning
  • Enforceable 2FA (TOTP + SMS)
  • Configurable session timeouts
Authentication

Enterprise sign-in, enforced your way

SAML 2.0 SSO works with Okta, Azure AD, Google, or any identity provider, with force-SAML to shut down password logins and just-in-time provisioning for new users. Two-factor authentication supports TOTP and SMS and can be enforced account-wide, and session timeouts are configurable to your policy.

36 Permission bits
  • Per-dashboard permissions
  • Scope-limited agent tokens
  • Live permission intersection on every request
  • Instant revocation & full audit log
Permissions

Granular access for humans and agents alike

36 granular user permission bits plus per-dashboard permissions let you scope exactly who sees what. AI agent tokens are scope-limited, intersected with the user's live permissions on every request, revocable instantly, and covered by a full audit log. An agent can never see more than the human it acts for.

100% Commits security-tested
  • Multi-tenant isolation tests in CI
  • Route-scanning authentication tests
  • Cross-tenant access tests fail the build
Continuous testing

Isolation verified on every commit

Multi-tenant isolation and authentication enforcement are tested in CI on every single commit. Route-scanning tests verify every endpoint enforces authentication, and automated cross-tenant access tests fail the build if one account could ever see another's data. Security is a gate in our pipeline, not an annual event.

  • Conversational data redaction mode
  • Per-account data retention policies
Data controls

Your data, on your terms

A conversational data redaction mode keeps message content out of Qvasa when your policy requires it, and per-account data retention policies control how long data lives before it is purged.

Compliance is monitored continuously through Vanta. See current reports and controls at trust.qvasa.com.

Bring your security team to the demo

We're happy to walk through SSO, permissions, data controls, and our continuous security testing in detail.

Request a demo