Control who can access customer data, what Brain can use and where QualiBot runs
QualiBot combines authentication, role-based authorization, account isolation, guarded outbound requests, audit capabilities and self-hosted deployment options.
QualiBot does not use customer conversation data to train a shared QualiBot model.
When an external model provider is configured, its processing and retention terms apply and must be reviewed separately.
Available controls
Microsoft OAuth authenticates mailbox connections.
What administrators manage
External system credentials and permissions provide the enforcement boundary for least privilege.
The safe-fetch layer
Self-hosted deployments can enable private-network requests through an installation setting when the architecture requires it.
Enterprise capabilities may include
Retention, data-subject request and incident-response procedures are defined at the contract and operational level, alongside these technical controls.
QualiBot provides technical and deployment controls that can support an organization’s security and compliance program. Compliance depends on configuration, contracts, operations, hosting, data flows and applicable law.
Answers for the security review
Can QualiBot be self-hosted?
Yes, through the supported Docker and Docker Compose deployment model.
Does QualiBot support SAML?
Yes, as an Enterprise feature.
Are MCP tools read-only by default?
MCP tools carry a read or write label administrators set; the connected system's own permissions provide the actual enforcement boundary.
Are tool outputs stored?
V2 Brain sessions can retain tool-call arguments and results in run context, visible to your team for review.
Are uploaded and relayed files malware-scanned?
Every relayed file is size-limited before delivery. Connect only trusted, approved file sources, and add your own file-inspection layer if your organization requires broader scanning.
