Security by design

Security and Data Protection

Last updated: 10 August 2026

QuoteGuardian minimises risk by keeping original quotation documents on your device, collecting only what the service needs and separating public, account and administrator functions.

Document protection

PDFs and photographs are processed in browser memory and are not uploaded to QuoteGuardian storage. Files are limited to PDF, JPEG, PNG or WebP, a maximum of five files and 10 MB per file. Their signatures are checked and PDFs containing common active or embedded-content indicators are rejected before parsing.

Accounts and access

Home Vault access requires ChatGPT sign-in and every record query is restricted to the authenticated owner. Administration additionally requires an explicit server-side email allowlist. Original source documents are not available in the administration area.

Requests, monitoring and incidents

Assessment and contact requests are size-limited and rate-limited. Failed analyses, rate-limit events, support failures and administrator actions enter a private operational log. The incident procedure covers triage, containment, evidence preservation, risk assessment, notification, recovery and review.

Retention and recovery

Browser documents end when deleted, refreshed or closed. Home Vault reports can be permanently deleted by their owner. Purpose-based schedules apply to support and security records. Remote document storage and payments remain blocked until encrypted backup, restoration and security tests are completed.

Data-protection governance

A DPIA has been completed for the present beta scope and will be reviewed before any material change. The operator must separately complete the ICO’s official fee self-assessment, because the result depends on legal entity, turnover and processing circumstances.

Report a concern

Use the technical-fault or privacy category, or email info@quoteguardian.co.uk. Do not attach passwords, payment information or sensitive documents.