Security you can take to diligence
ACGRAM Quotrova™ runs on enterprise-trusted platforms and adds quoting-specific controls — an auditable record, screening signals for your own review, and role-based access — designed to support your compliance program. Here's how, in plain terms.
Built on certified platforms
Quotrova is built on an enterprise-grade build-and-runtime platform and a leading third-party AI provider, and is distributed and billed through a major commerce platform, with card payments processed by PCI DSS Level 1-certified payment processors. The build-and-runtime platform is independently certified to SOC 2 Type II and ISO 27001; the AI provider maintains SOC 2 Type II, ISO 27001, ISO/IEC 42001 (AI management), CSA STAR, and NIST 800-171; the commerce platform is certified PCI DSS Level 1 and holds SOC 2 Type II and SOC 3. Our platform providers also maintain GDPR-aligned data protection programs. These certifications are held by our platform providers, not by Quotrova.
How your data is protected
Data is encrypted in transit (TLS 1.2+) and at rest at the platform level. Access is role-based, with row-level separation designed to scope each merchant's data to their own workspace. Security hardening is ongoing (see Diligence below).
Payments handled by PCI-certified processors
Quotrova does not collect, process, or store cardholder data. Subscription billing and any card payments run through PCI DSS Level 1-certified payment processors — so card data never touches Quotrova's servers, and your own PCI scope stays narrow.
Auditable by design
Quote actions are recorded to a tamper-evident, hash-chained audit trail, and acceptance is captured with e-signature — so you can show what happened, when, and by whom.
Buyer-risk support signals
Buyer Risk Support (part of Shield™) screens the buyer company and buyer name on your quotes against an ingested copy of the U.S. Treasury OFAC Specially Designated Nationals (SDN) List, and routes potential matches to human-in-the-loop review with the decision recorded to a tamper-evident audit trail. This supports your own sanctions-screening program operations. It is NOT a legal determination, a regulatory certification, an audit attestation, or sanctions clearance, and it does not make you or ACGRAM compliant with any sanctions program. Coverage is limited: name-based matching on two fields, against the SDN list only. It does not screen non-SDN or consolidated lists, does not derive ownership under the 50 Percent Rule, and does not screen addresses, email addresses, beneficial owners, or your buyer’s own customers. Confirming that a customer is not a sanctioned party, and determining what any sanctions program requires of you, remains your responsibility and your counsel’s. Search OFAC directly at https://sanctionssearch.ofac.treas.gov and review the active programs at https://ofac.treasury.gov/sanctions-programs-and-country-information. Separately, Quotrova is a quoting platform and not a payment or card processor: payment-security and card-fraud screening are performed by the payment provider you connect, not by Quotrova.
Private by default
Quotrova's AI features run on a leading third-party AI provider that does not train on our customers' data.
Diligence under NDA
Verified U.S. buyers can request the data room — architecture, data-flow, RBAC matrix, and audit-moat exhibits. Quotrova is in Beta and under active security hardening; we share current status openly under NDA.
SOC 2, ISO, and similar certifications referenced are held by our platform providers, not by ACGRAM Quotrova™. ACGRAM Quotrova™ is software that supports B2B quoting and compliance-program operations; it is not legal advice, a compliance program, or a guarantee of compliance with any law, regulation, or standard. Quotrova is in Beta and under active security hardening; current diligence status is available to verified buyers under NDA.