Security

Built to read your broker, not your data.

Qarote connects to RabbitMQ over TLS, reads only management and metrics data, and never stores your message payloads. Here's exactly what that means.

Encryption in transit

Connections to your RabbitMQ broker use TLS by default. Qarote talks to the Management HTTP API over an encrypted channel — no plaintext broker traffic.

What we read — and don't store

Qarote reads only metrics and management data from the Management HTTP API. We do not store:

  • Message payloads — never read or stored
  • Broker credentials — not persisted
  • Application data — out of scope

Only configuration and alert/notification preferences are persisted.

AI & data residency

You choose where AI Explain runs.

Root-cause analysis can run three ways. The choice determines whether any data leaves your network — and self-hosters can keep everything in-network.

Managed cloud · Qarote key

The incident plus surrounding broker state is sent to Qarote's managed LLM provider using our key. Simplest to run — zero configuration.

leaves network
BYOK · your Anthropic / OpenAI key

Analysis runs on your own model provider account with your API key. Data goes to your chosen provider under your terms — not through Qarote's account.

your provider
Local Ollama · self-hosted

Analysis runs on a local Ollama model on your own hardware. Nothing leaves your network — broker state never crosses your perimeter.

stays in-network

Self-host & data control

Run Qarote entirely inside your own infrastructure. All data stays within your network, and licenses validate offline — there is no phone-home, no telemetry beacon, and no dependency on our uptime for yours.

  • Offline JWT license validation
  • Local Ollama for fully in-network AI
  • MIT open-source detection core

Compliance

SOC 2 is available on the Enterprise plan. If your procurement process needs a report, security review, or DPA, our team can walk you through it.

Request SOC 2 details

Responsible disclosure

Found a vulnerability? We want to hear from you. Email security@qarote.io with details and steps to reproduce. We'll acknowledge your report, keep you updated, and credit you once it's resolved. Please give us a reasonable window to fix issues before public disclosure.

Report a vulnerability

Questions about security?

Our team is happy to walk through data handling, residency, and compliance for your environment.