Built so you can prove it.
Agencies hold the most sensitive parts of an author's life: SSNs, bank details, contracts, earnings. Quillaris treats that as the default, not a premium add-on: access is scoped at the server, every change is logged, sensitive fields are encrypted, and GDPR responses are two clicks.
Roles scoped at the server, not hidden in the UI.
Five roles map to how an agency actually runs. Agents see their own roster; power users see the whole roster without touching the controls; bookkeepers run the money; principals see everything. Scoping is enforced on the server, so manipulating the interface can't widen what a role returns.
- Admin, Power User, Agent, Bookkeeper, Read-only. Each with a precise, documented set of capabilities.
- Power User sees the business, not the controls. The full client roster and every deal, but no team and settings, and no other client's money. Viewing all submissions is a per-user switch.
- Tier-aware sidebar. Features a subscription doesn't include are hidden entirely, not just disabled.
| Capability | Admin | Power | Agent | Bkpr | R-O |
|---|---|---|---|---|---|
| Client roster | All | All | Own | All | All |
| Deals | All | All | Own | All | All |
| Submissions | All | Optional | Own | All | All |
| Process money | ✓ | Own | · | ✓ | · |
| Manage Payees | ✓ | ✓ | · | ✓ | · |
| Reports | ✓ | ✓ | · | ✓ | · |
| Team & settings | ✓ | · | · | · | · |
| Audit log | ✓ | · | · | · | · |
A field-level record of who changed what.
Every create, edit, payment, deletion, sensitive-field view, and login is captured with the actor, timestamp, and IP. Expand any entry to see exactly which fields changed.
- Color-coded diffs. Old values in red strike-through, new values in green; unchanged fields stay hidden behind a toggle.
- Filter & export. By date, action, entity, or actor, then export the entire filtered log to CSV for compliance handover.
- Article 30 ready. The trail satisfies GDPR record-keeping out of the box.
Tax identifiers, encrypted and accounted for.
SSNs and foreign TINs are stored encrypted and visible only to Admins and Bookkeepers. Revealing one is a deliberate, logged act, and the plaintext never lands in the audit trail.
- AES-256-GCM authenticated encryption. All traffic runs over TLS, and SSNs, TINs, bank routing and account numbers, OAuth tokens, and document share tokens are stored encrypted.
- Reveal is recorded. Clicking the eye writes a Viewed Sensitive Field event tied to a specific user.
- Redacted everywhere else. Diffs and exports replace the value with [redacted], recording that it happened, not what it was.
Data-subject requests, handled in two buttons.
Quillaris ships the building blocks for Articles 15, 17, and 20, not as a consulting project but as buttons on the client and contact pages. And nothing is lost to a misclick: deletions are recoverable.
- Export & portability. A ZIP of every linked record and file with a manifest, for Article 15 / 20 requests.
- Scrub-not-delete erasure. Personal fields are anonymized while tax source records keep their links, per Article 17(3)(b).
- A recycle bin & verified email. Deleted records are recoverable, and outbound mail sends from your own DKIM-verified domain.
Quillaris provides tooling that supports GDPR workflows; it is not a compliance program. Your agency remains responsible for its own regulatory compliance.
Defense in depth, from the edge to the row.
Before a request ever reaches agency data it clears an AWS Web Application Firewall (WAF), a server-side session check, role and scope checks, and tenant isolation enforced by the database itself. No single layer is the security model.
- AWS WAF at the edge. Managed rules block known-bad IPs, anonymous proxies, SQL injection, XSS, and emerging attack patterns, with bot control and per-IP rate limiting.
- Sessions live on the server. Sign in with email and password or Google SSO; the browser holds only an opaque secure cookie. One active session per user, revocable instantly.
- Isolation enforced by the database. Row-Level Security scopes every query to your agency before application code runs.
AI that never learns from your clients.
Quillaris runs every AI feature on Amazon Bedrock. Prompts and documents are processed inside our own AWS region and are never used to train any foundation model: not ours, and not the model providers'.
- No training on your data, ever. Bedrock doesn't store prompts or completions, and doesn't use them to improve any base model or share them with third-party providers.
- Bedrock Guardrails on every request. Sensitive-information filters redact PII, content filters and denied topics block unsafe output, and contextual grounding checks catch hallucinations.
- Private and encrypted end to end. Traffic stays inside AWS over PrivateLink, encrypted in transit and at rest with KMS. Nothing crosses the public internet.
Built to stay up, and to come back.
Quillaris runs in AWS's us-east-1 (Northern Virginia) region with high availability across multiple Availability Zones: EC2 application servers span zones, and Amazon RDS keeps a synchronized standby that takes over automatically if a data center fails.
- Multi-AZ across the stack. EC2 application servers run in separate Availability Zones, and the database replicates synchronously to a standby in another zone, so a zone outage doesn't take the agency down.
- Multiple backups per day. EBS snapshots run several times daily, with air-gapped copies kept isolated from the production environment so even a compromised account can't reach them.
- Encrypted everywhere it rests. Every drive and volume, every database, every snapshot, and every machine image is encrypted, not just the sensitive fields.
Run the work, not just record it.
Tasks, projects, a shared agency calendar, and a customizable dashboard that surfaces every deadline that matters.
See project management One platformEvery department, one system.
Clients, deals, royalties, money, rights, and reports in one place, with fewer touchpoints and no re-keying between tools.
See the platform