Qubit Docs العربية

How Qubit protects your data

This section describes the security controls in Qubit and how the AI features use your data. It covers what you can configure in the product. For Qubit's legal commitments, read the Privacy Policy and Terms of Service on qubit.sa.

Accounts and sign-in

  • Passwords are stored as one-way hashes, never in readable form.
  • Each person can turn on two-factor authentication with an authenticator app. See Security & Privacy.
  • People can sign in with a linked Google or Microsoft account.
  • Each person can see the devices where they are signed in and sign any of them out.

Workspace controls

Owners and admins can set rules for everyone in a workspace. See Workspace security.

  • Require two-factor authentication for all members.
  • Enforce a password policy.
  • Limit how long sessions last.
  • Allow access only from approved IP addresses or ranges.

Who can see which data

  • Data and content belong to a workspace. Only members of that workspace can open them.
  • Workspace roles decide what each person can do. See Members and roles.
  • Data permissions decide which connections, schemas, and tables members can query, and row restrictions decide which records they see. Qubit applies both to every query, including the queries the Assistant runs. See Access Control.

Stored secrets

Credentials for connected data sources are encrypted at rest. Other secrets, such as the Slack bot token, embed API key secrets, and the signing secret for audit log forwarding, are also stored encrypted. An embed API key secret is shown only once, when you create it.

Audit log

Qubit records workspace activity, data access, and AI runs in a tamper-evident audit log. Owners and admins can search it, export it, check its integrity, and forward it to their own security monitoring system. See Audit Logs.

More in this section