Read-only by design
Each statement is parsed before it leaves Quarrow; only SELECT and WITH queries are sent. The BI Publisher report executes under the Fusion data source you choose.
Security
Quarrow is designed for production Fusion pods holding financial and personal data.
Each statement is parsed before it leaves Quarrow; only SELECT and WITH queries are sent. The BI Publisher report executes under the Fusion data source you choose.
TLS for every connection. Fusion credentials, API secrets and snapshots are encrypted at rest with AES-256-GCM using a per-organization key.
Password policies with lockout, TOTP multi-factor authentication, passkeys (WebAuthn), and single sign-on with OIDC, Google or Microsoft. Organizations can require MFA.
Roles (owner, admin, developer, analyst, viewer), per-pod role lists, production flags, temporary elevated access and API keys limited to the public API.
Column masking by pattern, PII discovery across the data dictionary, row-level rules, and share links that always apply masking and expire.
Business justification and four-eyes approval for sensitive pods, a complete audit trail of sign-ins, queries and admin changes, and streaming to your SIEM.
The hosted service runs on Oracle Cloud Infrastructure. Enterprise customers can run Quarrow in their own OCI tenancy so no data leaves their cloud.
Query results are streamed to your browser and not stored, unless you explicitly save a snapshot, notebook result or extract - which you can delete at any time.
Need a security questionnaire answered or a review call? Email hello@159-13-40-49.sslip.io. To report a vulnerability, write to the same address with "security" in the subject.