Skip to content

Built so you can prove it.

Agencies hold the most sensitive parts of an author's life: SSNs, bank details, contracts, earnings. Quillaris treats that as the default, not a premium add-on: access is scoped at the server, every change is logged, sensitive fields are encrypted, and GDPR responses are two clicks.


Roles scoped at the server, not hidden in the UI.

Five roles map to how an agency actually runs. Agents see their own roster; power users see the whole roster without touching the controls; bookkeepers run the money; principals see everything. Scoping is enforced on the server, so manipulating the interface can't widen what a role returns.

  • Admin, Power User, Agent, Bookkeeper, Read-only. Each with a precise, documented set of capabilities.
  • Power User sees the business, not the controls. The full client roster and every deal, but no team and settings, and no other client's money. Viewing all submissions is a per-user switch.
  • Tier-aware sidebar. Features a subscription doesn't include are hidden entirely, not just disabled.
Access control
Capability Admin Power Agent Bkpr R-O
Client rosterAllAllOwnAllAll
DealsAllAllOwnAllAll
SubmissionsAllOptionalOwnAllAll
Process money✓Own·✓·
Manage Payees✓✓·✓·
Reports✓✓·✓·
Team & settings✓····
Audit log✓····

A field-level record of who changed what.

Every create, edit, payment, deletion, sensitive-field view, and login is captured with the actor, timestamp, and IP. Expand any entry to see exactly which fields changed.

  • Color-coded diffs. Old values in red strike-through, new values in green; unchanged fields stay hidden behind a toggle.
  • Filter & export. By date, action, entity, or actor, then export the entire filtered log to CSV for compliance handover.
  • Article 30 ready. The trail satisfies GDPR record-keeping out of the box.
Audit trail
Updated Deal · 7f3a9c2e M. Reyes 198.51.100.24
advance $25,000 → $30,000
status Negotiating → Signed
agency_commission 15% → 20%
client_ssn[redacted]
+ Show 14 unchanged fields

Tax identifiers, encrypted and accounted for.

SSNs and foreign TINs are stored encrypted and visible only to Admins and Bookkeepers. Revealing one is a deliberate, logged act, and the plaintext never lands in the audit trail.

  • AES-256-GCM authenticated encryption. All traffic runs over TLS, and SSNs, TINs, bank routing and account numbers, OAuth tokens, and document share tokens are stored encrypted.
  • Reveal is recorded. Clicking the eye writes a Viewed Sensitive Field event tied to a specific user.
  • Redacted everywhere else. Diffs and exports replace the value with [redacted], recording that it happened, not what it was.
Sensitive data
SSN •••–••–•••• Reveal · logged
Foreign TIN ••••••••• Encrypted
Bank account •••••••••••• AES-256-GCM
Routing no. ••••••••• AES-256-GCM
Viewed Sensitive Field · J. Doe · 2:14 PM · 198.51.100.24Logged

Data-subject requests, handled in two buttons.

Quillaris ships the building blocks for Articles 15, 17, and 20, not as a consulting project but as buttons on the client and contact pages. And nothing is lost to a misclick: deletions are recoverable.

  • Export & portability. A ZIP of every linked record and file with a manifest, for Article 15 / 20 requests.
  • Scrub-not-delete erasure. Personal fields are anonymized while tax source records keep their links, per Article 17(3)(b).
  • A recycle bin & verified email. Deleted records are recoverable, and outbound mail sends from your own DKIM-verified domain.
GDPR & recovery
Export Data ZIP + manifest.json · Art. 15 / 20
Erase (GDPR) Scrub-not-delete · Art. 17
Article 15 · Access Article 17 · Erasure Article 20 · Portability Article 30 · Records Audit logged Recycle bin

Defense in depth, from the edge to the row.

Before a request ever reaches agency data it clears an AWS Web Application Firewall (WAF), a server-side session check, role and scope checks, and tenant isolation enforced by the database itself. No single layer is the security model.

  • AWS WAF at the edge. Managed rules block known-bad IPs, anonymous proxies, SQL injection, XSS, and emerging attack patterns, with bot control and per-IP rate limiting.
  • Sessions live on the server. Sign in with email and password or Google SSO; the browser holds only an opaque secure cookie. One active session per user, revocable instantly.
  • Isolation enforced by the database. Row-Level Security scopes every query to your agency before application code runs.
Infrastructure
EdgeAWS Web Application Firewall (WAF)
TransportTLS + strict security headers
IdentityServer-side session · Google SSO
AuthzRole & per-agent scope checks
DatabaseRow-Level Security · tenant isolation
At restAES-256-GCM encrypted fields

AI that never learns from your clients.

Quillaris runs every AI feature on Amazon Bedrock. Prompts and documents are processed inside our own AWS region and are never used to train any foundation model: not ours, and not the model providers'.

  • No training on your data, ever. Bedrock doesn't store prompts or completions, and doesn't use them to improve any base model or share them with third-party providers.
  • Bedrock Guardrails on every request. Sensitive-information filters redact PII, content filters and denied topics block unsafe output, and contextual grounding checks catch hallucinations.
  • Private and encrypted end to end. Traffic stays inside AWS over PrivateLink, encrypted in transit and at rest with KMS. Nothing crosses the public internet.
AI & LLM privacy
Never TrainedPrompts & completions · not retained
Sensitive info filter · PII redactionOn
Content filtersOn
Denied topicsOn
Contextual grounding checkOn
AWS PrivateLink KMS encryption In-region SOC 2

Built to stay up, and to come back.

Quillaris runs in AWS's us-east-1 (Northern Virginia) region with high availability across multiple Availability Zones: EC2 application servers span zones, and Amazon RDS keeps a synchronized standby that takes over automatically if a data center fails.

  • Multi-AZ across the stack. EC2 application servers run in separate Availability Zones, and the database replicates synchronously to a standby in another zone, so a zone outage doesn't take the agency down.
  • Multiple backups per day. EBS snapshots run several times daily, with air-gapped copies kept isolated from the production environment so even a compromised account can't reach them.
  • Encrypted everywhere it rests. Every drive and volume, every database, every snapshot, and every machine image is encrypted, not just the sensitive fields.
Architecture & resilience
us-east-1 · Northern Virginia
Availability Zone A EC2 app servers RDS primary
Availability Zone B EC2 app servers RDS standby
EBS snapshots · multiple per dayEncrypted
Air-gapped backup copiesIsolated
Machine images (AMIs)Encrypted
All drives & volumesEncrypted
Server-enforced
Access can't be talked around.
Every scope check runs on the server. Hiding a button isn't the security model. The data simply isn't returned to a role that shouldn't see it.
Accountable
Every disclosure has a name on it.
From an edited advance to a revealed SSN, the audit log ties each action to a user, a time, and an IP, without ever storing the secret itself.
Compliance-ready tooling
The hard parts are already built.
GDPR export and erasure, 1099-MISC, 1099-NEC, and 1042-S generation, and a full change history are part of the platform, not a quarter-long project. Tools that support your compliance work; your agency remains responsible for its own compliance.